Radix: Attacker Exploits Engine Vulnerability to Steal Assets, Network Briefly Lost Liveness
Odaily reports that the Radix Foundation has released an incident report stating that an attacker exploited a previously undiscovered vulnerability in the Radix Engine to withdraw assets from third-party vaults without owner authorization, then bridged them via Hyperlane to Ethereum, BNB Chain, Solana, and other networks to sell. The vulnerability originated from a code cleanup in June 2023, and was not identified during an independent security audit conducted by Zellic in August 2024. Approximately 3 hours after the incident, Radix validators proactively took enough staked share offline to prevent the network from reaching consensus, thereby preventing further exploitation of the vulnerability. Affected assets include ETH, WBTC, USDT, USDC, BNB, and SOL, among others. Radix stated that the vulnerability fix has been completed and has undergone independent review and testing, and network recovery is currently underway.
