HomeSecurityRadiant Capital: North Korean hackers stole $50 million worth of crypto

Radiant Capital: North Korean hackers stole $50 million worth of crypto.

Radiant Capital says North Korean hackers are behind its recent breach, which led to the theft of $50 million worth of crypto. The cyberattack took place on October 16.

Radiant Capital North Korean crypto hackers

The company investigated the incident with the help of cybersecurity experts from Mandiant, who say the attack was carried out by North Korean state hackers known as Citrine Sleet (or “UNC4736” and “AppleJeus”).

The US warned that North Korean hackers are targeting crypto companies, exchanges and gaming companies to steal and launder illicit funds. The goal of these malicious operations is to support their country's activities.

See also: Man pleads guilty to cryptojacking operation

Cyberattack on Radiant Capital

Radiant is a decentralized finance (DeFi) platform that allows users to deposit, borrow, and manage crypto across multiple blockchain networks.

The platform uses Ethereum blockchain security through the Arbitrum Layer 2 scaling system and operates under a community-based system.

On October 16, 2024, Radiant Capital announced that it had suffered a breach that resulted in the theft of $50 million worth of crypto. The breach was caused by “advanced malwarethat targeted three trusted developers. Their devices were compromised to execute the unauthorized transactions.

The (North Korean) hackers likely exploited the common multi-signature process, collecting valid signatures under the guise of transaction errors, and stealing funds from the Arbitrum and Binance Smart Chain (BSC) exchanges.

The attack bypassed the hardware wallet's security and multiple layers of verification , and transactions appeared normal during manual and simulation checks.

North Korean hackers responsible for Radiant Capital hack

After an internal investigation, Radiant explained that the attack began on September 11, 2024, when one of its developers received a Telegram message from an alleged former contractor. The developer was tricked into downloading a malicious ZIP file.

See also: Losses from crypto hacks and scams continue to decrease!

The file contained a PDF that was used as bait and a macOS malware payload named "InletDrift", which created a backdoor on the infected device.

Radiant says the attack was so well-planned that it bypassed all security measures in place.

This breach was so flawlessly executed that even with Radiant’s standard best practices, such as simulating transactions in Tenderly, verifying payload data, and following industry standard SOPs at every step, the attackers were able to compromise multiple developer devices,” Radiant Capital explained.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Radiant Capital: North Korean hackers stole $50 million worth of crypto.

Front-end interfaces displayed benign transaction data while malicious transactions were being signed in the background. Traditional audits and simulations showed no obvious deviations, making the threat virtually invisible during normal audit stages.“.

Mandiant, which assisted Radiant Capital in the investigation, believes the attack was carried out by North Korean hackers UNC4736.

Given the successful circumvention of its security measures, Radiant highlights the need for more robust device-level solutions to enhance transaction security.

See also: November 2024: Hackers have stolen $71 million worth of crypto.

Regarding the stolen funds, the platform says it is working with US law enforcement and zeroShadow to recover some amounts.

The North Korean crypto theft has significant implications for the global economy. First, the theft creates uncertainty and loss of confidence in the cryptocurrency market. Investors and users are concerned about the safety of their funds and the possibility of becoming victims of cyberattacks.

Additionally, the theft of crypto by North Korean hackers could have a negative impact on the development and security of cryptocurrencies in general. cyberattacks expose weaknesses in security systems and can cause market turmoil. The loss of public trust can negatively affect the value of cryptocurrencies.

Finally, these attacks could have geopolitical implications. North Korea is using stolen cryptocurrencies to fund its nuclear weapons and missile programs. This could threaten regional security and provoke reactions from other countries.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS