
Radiant Capital, a cross-chain lending protocol built on the Arbitrum layer-2 network, was hacked for 1,900 ETH (~$4.5 million). The exploit relied on a flaw in the underlying code, which was forked from Compound and Aave. The original code has a known rounding issue, which makes new projects vulnerable to attack shortly after they are deployed if they are not specifically configured to avoid the issue. In this case, the attacker had observed the contract being deployed and performed the exploit only six seconds after the project was activated.
Radiant Capital sent an on-chain message to the attacker, offering to negotiate a bounty.
-
Tweet thread by Radiant Capital
-
Tweet thread by PeckShield
-
On-chain message
from Radiant Capital to the exploiter