Loading prices…
🩸BEARISH

Radix Bug Drains $1.3M and Halts Chain for 10 Days

The loss exposed a protocol-level authorization flaw, while a 10-day halt and missed 2024 audit raise questions about maintenance code and emergency controls.

A Radix Engine flaw enabled an attacker to withdraw about $1.26 million across 26 transactions on Aug. 31, including 458,915 USDC, 72,420 USDT, 61.08 ETH, 6.35 wrapped Bitcoin, 536.16 SOL and 32.91 BNB. The attacker also took 13,000 XRD to pay transaction fees. Validators later halted the Radix blockchain for more than 10 days after investigators determined the defect could affect any vault, not just the accounts targeted in the exploit.

Why it matters

RDX Works introduced the defect during a June 2023 cleanup of the Radix Engine, the execution layer responsible for processing transactions and enforcing asset ownership. The bug changed how the engine handled vault references, allowing purpose-built smart-contract code to pass another user's vault into ordinary withdrawal functions without properly checking the ownership boundary.

That created a protocol-level failure rather than a flaw in one application. The attacker moved the stolen assets through Hyperlane to Ethereum, BNB Chain and Solana, then sold them for ETH. Hyperlane operated as designed because the assets had already been withdrawn from Radix before the bridge was used.

Market impact

The direct theft understated the potential exposure. Radix investigators concluded that user accounts, applications and liquidity pools could have been vulnerable. Secondary losses followed when bridged assets were removed from liquidity pools, distorting prices and allowing another account to extract millions of XRD.

The flaw had also survived Zellic's 2024 independent audit of the Radix protocol, including the engine kernel containing the defect. Validators took enough stake offline to block consensus while developers added checks against unauthorized vault references. User transactions resumed on Sept. 11. Radix said it is adding regression tests, strengthening security reviews and formalizing the emergency process used to restore network safety.

Related tokens
$XRD $USDC $USDT $ETH $SOL

Frequently asked questions

  1. How much did the Radix exploit remove from targeted vaults?

    The attacker withdrew assets worth about $1.26 million across 26 transactions, plus 13,000 XRD used to pay transaction fees.

  2. What caused the Radix Engine authorization failure?

    A June 2023 refactor changed how the engine handled vault references. Smart-contract code could pass another user's vault into withdrawal functions without a proper ownership check.

  3. Why did Radix validators halt the blockchain?

    Investigators determined the flaw could affect any vault on the network. Validators took enough stake offline to stop consensus and prevent further transactions while developers prepared a fix.

  4. Did the attacker compromise users' private keys?

    No. The assets were withdrawn through the Radix Engine's authorization flaw, and no private keys were compromised.

  5. What secondary damage followed the initial Radix theft?

    Removing bridged assets from liquidity pools distorted prices and allowed another account to extract millions of XRD from affected pools.

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 1h ago
Open original →