3-Year-Old Radix Bug Triggers $1.3M Theft and 10-Day Network Halt

iconNS3
Share
AI summary iconSummary
A critical vulnerability in Radix’s engine triggered a $1.3M theft and a 10-day network halt. The flaw, introduced in June 2023, allowed unauthorized withdrawals from accounts, apps, and liquidity pools. The attacker drained 458,915 USDC, 72,420 USDT, 61.08 ETH, 6.35 wBTC, 536.16 SOL, and 32.91 BNB via Hyperlane. Validators paused the network to block restricted vault references in ordinary withdrawals. The incident impacted liquidity pools and distorted prices. Radix is improving security reviews and adding regression tests. The fear and greed index for the network activity remains under scrutiny.

A Radix Engine flaw enabled a roughly $1.3 million theft and forced validators to halt the blockchain. The Radix Foundation said an RDX Works development team introduced the defect during a June 2023 cleanup of the Radix Engine. The vulnerability remained undetected for more than three years. An attacker exploited it on Aug. 31. A community ledger reconstruction recorded 26 exploit transactions. The attacker withdrew about 458,915 USDC. The attacker withdrew 72,420 USDT. The attacker withdrew 61.08 ETH. The attacker withdrew 6.35 wrapped Bitcoin. The attacker withdrew 536.16 SOL. The attacker withdrew 32.91 BNB. The assets were worth roughly $1.26 million using Aug. 31 market prices. The attacker took another 13,000 XRD to pay transaction fees. The two stablecoins accounted for about $531,335. The attacker sent the assets through Hyperlane to Ethereum, BNB Chain, and Solana. Radix said the attacker then sold the assets for ETH. Hyperlane operated as designed. No private keys were compromised. Investigators concluded that the flaw could have been used against any vault on the network. The potential exposure included tokens and other assets beyond the bridged holdings targeted by the attacker. Validators took enough stake offline to prevent the network from reaching consensus. This action stopped additional transactions while developers worked on a fix. The halt lasted more than 10 days. A protocol fix blocked restricted vault references from being used for ordinary withdrawals. User transactions resumed on Sept. 11, according to the community ledger reconstruction. Zellic had audited the Radix protocol in 2024. The review included the engine kernel containing the defect. The review did not detect the authorization flaw. The bug allowed a transaction to identify another user's vault through its internal address. Smart-contract code could then receive that reference. The engine allowed ordinary withdrawal functions without properly enforcing the ownership boundary. The attacker accessed assets held by user accounts, applications, and liquidity pools without obtaining the owners' signatures. The incident caused secondary losses in liquidity pools after bridged assets were removed from one side of trading pairs. Distorted prices allowed another account to extract millions of XRD from affected pools. Radix said it is adding regression tests. Radix is strengthening its security review process. Radix is formalizing the emergency procedure validators used to break network liveness. The Foundation said future security work must account for increasingly capable AI-assisted code-analysis tools. The Foundation believes those tools may have helped the attacker identify the years-old defect.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.