Radix Foundation Says Radix Engine Bug Exploited; Network Taken Offline to Halt Attack

AI Market Summary
Radix reported an exploit of a previously undiscovered Radix Engine vulnerability that enabled unauthorized withdrawals from third-party vaults, with stolen funds bridged via Hyperlane to Ethereum, BNB Chain, and Solana for liquidation. Validators halted further damage by intentionally disabling consensus, leaving the network temporarily inactive. While the bug is patched and reviewed, the episode raises near-term cross-chain and DeFi counterparty risk, pressuring bridged assets and related liquidity.
Impact level
● Medium
Affected assets
ETH/USDT+5.79%
AI Insight · ETH/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Radix Foundation has published an incident report detailing an attack that leveraged a previously unknown vulnerability in the Radix Engine. The attacker was able to withdraw assets from third-party vaults without owner authorization, then used Hyperlane to move funds cross-chain to networks including Ethereum, BNB Chain and Solana for liquidation. The foundation said the flaw stemmed from a code refactor in June 2023 and was not identified in an independent security audit performed by Zellic in August 2024. About three hours after the incident, Radix validators mitigated further exploitation by proactively removing enough staked shares to prevent the network from reaching consensus, effectively making the network temporarily inactive. Assets impacted included ETH, WBTC, USDT, USDC, BNB and SOL. Radix said the vulnerability has been patched, independently reviewed and tested, and work is underway to restore the network.