Radix Suffers a Cross-Chain Attack! A Vault Authorization Flaw Was Exploited, and Multiple Assets Were Stolen
The Radix Foundation disclosed that on August 31 an incident occurred in the ecosystem. The attacker exploited a vault authorization vulnerability in the Radix Engine to extract assets from certain third-party vaults without obtaining proper authorization. The assets were then transferred to external networks via the Hyperlane cross-chain bridge and sold.
The affected assets are fairly extensive, including ETH, WBTC, USDT, USDC, BNB, SOL, and a small amount of XRD fee assets. They involve parts of ecosystem contracts and liquidity-pool vaults.
More notably, this vulnerability was not something that appeared recently—it traces back to a code refactor in June 2023. Even in an independent security audit conducted in August 2024, the issue was not identified.
After the incident, the team quickly launched emergency measures. Hyperlane paused the related operations, and validators also voluntarily went offline with sufficient staked amounts to break the exploit chain first, preventing the attack from further expanding.
At present, the Radix Foundation says the vulnerability has been fully patched, has passed independent review and testing, and is working to restore the network. This incident also once again serves as a reminder to the market: what DeFi fears most is often not a sudden crash in market prices, but vulnerabilities in underlying authorizations and cross-chain components. Code security is always the first line of defense for funds safety.$龙虾 $STAR $COTI
The Radix Foundation disclosed that on August 31 an incident occurred in the ecosystem. The attacker exploited a vault authorization vulnerability in the Radix Engine to extract assets from certain third-party vaults without obtaining proper authorization. The assets were then transferred to external networks via the Hyperlane cross-chain bridge and sold.
The affected assets are fairly extensive, including ETH, WBTC, USDT, USDC, BNB, SOL, and a small amount of XRD fee assets. They involve parts of ecosystem contracts and liquidity-pool vaults.
More notably, this vulnerability was not something that appeared recently—it traces back to a code refactor in June 2023. Even in an independent security audit conducted in August 2024, the issue was not identified.
After the incident, the team quickly launched emergency measures. Hyperlane paused the related operations, and validators also voluntarily went offline with sufficient staked amounts to break the exploit chain first, preventing the attack from further expanding.
At present, the Radix Foundation says the vulnerability has been fully patched, has passed independent review and testing, and is working to restore the network. This incident also once again serves as a reminder to the market: what DeFi fears most is often not a sudden crash in market prices, but vulnerabilities in underlying authorizations and cross-chain components. Code security is always the first line of defense for funds safety.$龙虾 $STAR $COTI
