Radiant: North Korea hacker fake before the contractor will implement 50 million US dollars attack

Author: Stephen Katte, Cointelegraph; Compilation: Tao Zhu, Bitchain Vision Realm

Radiant Capital said,In October, its decentralized finance (DEFI) platform was attacked by hackers with a loss of 50 million US dollars. Hackers sent malware through Telegram. The malware was implemented by a hacker who alliance with North Korea.

Radiant stated in the survey update on December 6 that Mandiant, a network security company signed, has evaluated “highly convinced that this attack is done by threat actors connected with North Korea.”

The platform stated that on September 11, a developer of Radiant received a Telegram message containing a ZIP file from a “trusted former contractor” and asked to provide feedback to the new projects they were planned.

“After review, the news was suspected of coming from a threat actor who alliance with North Korea, posing as a former contractor,” said it.”When this ZIP file is shared between other developers to solicit feedback, malicious software finally spreads, which has led to subsequent invasion.”

On October 16, a hacker controlled the private key and smart contracts of many signatures, causing the DEFI platform to be forced to suspend the loan market.North Korea hackers have long aimed at cryptocurrency platforms for a long time, and stole a $ 3 billion cryptocurrency worth $ 3 billion from 2017 to 2023.

Source: Radiant Capital

Radiant said that the document did not cause any other doubts, because “in a professional environment, the request for reviewing PDF is a conventional practice”, and developers “often share documents in this format.”

The domain associated with the ZIP file also deceived the legal website of the contractor.

Many Radiant developer equipment is attacked during the attack, the front -end interface shows benign transaction data, and malicious transactions are signed in the background.

“Traditional inspection and simulation did not show obvious differences, making threats almost invisible during the normal review stage,” it added.

“This kind of deception is performed so seamlessly, even if the best practice of Radiant standards, such as simulation transactions in Tenderly, verifying effective load data, and following industry standards SOP, attackers can still invade multiple developer equipment equipment”Radiant wrote.

Fishing PDF examples that may be used by malicious hackers.Source: Radiant Capital

Radiant Capital believes that the threat actor in charge of the case is called “UNC4736”, also known as “CITRINE SLEET” -The believes that it is in contact with the General Administration of Investigation (RGB) of the main Intelligence Institution of North Korea, and it is speculated that the hacker Lazarus GroupA branch.

Hackers transferred about $ 52 million in stolen funds on October 24.

“This incident shows that even strict SOP, hardware wallets, Tenderly and other simulated tools and careful artificial review may be bypassed by very advanced threat actors,” Radiant Capital wrote in its update.

“The dependence requirements for blind signs and front -end verification requirements that may be deceived developed more powerful hardware -level solutions to decod and verify the effective load of transactions,” it added.

This is not the first time that Radiant has been attacked this year.The platform suspended the lending market due to the $ 4.5 million Lightning loan vulnerability in January.

According to DEFILLAMA data, after the use of vulnerabilities this year, Radiant’s total lock value dropped sharply, from more than $ 300 million at the end of last year to about $ 5.81 million on December 9.

  • Related Posts

    Viewpoint: Ethereum Killer narrative is broken, ETH and SOL are over

    Author: Haotian; Source: X, @tmel0211 I found an interesting phenomenon when I visited the English blogger circle: ETH Maxi and SOL Maxi are always tit-for-tat. ETH side mocked SOL for…

    A brief discussion on RWA and Defi system: Financial 3.0 revolution

    Since the global financial crisis created by Wall Street in 2008, criticism and controversy over the traditional financial system have never stopped in all sectors of society.As we all know,…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    How to plan to welcome the Bitcoin boom period (2025 edition)

    • By jakiro
    • September 4, 2025
    • 2 views
    How to plan to welcome the Bitcoin boom period (2025 edition)

    Coin stock hidden story: halved method of slashing the slashing method hidden in equity dilution and mNAV algorithm

    • By jakiro
    • September 4, 2025
    • 1 views
    Coin stock hidden story: halved method of slashing the slashing method hidden in equity dilution and mNAV algorithm

    Will seasonal “curse” become a nightmare for Bitcoin?

    • By jakiro
    • September 4, 2025
    • 1 views
    Will seasonal “curse” become a nightmare for Bitcoin?

    Shelf life of digital assets

    • By jakiro
    • September 4, 2025
    • 1 views
    Shelf life of digital assets

    The symbolic significance of Zhao Changpeng’s return to China: the shift in global cryptocurrency regulation

    • By jakiro
    • September 4, 2025
    • 4 views
    The symbolic significance of Zhao Changpeng’s return to China: the shift in global cryptocurrency regulation

    Investment strategies for the next decade: Holding scarce assets such as gold and Bitcoin

    • By jakiro
    • September 4, 2025
    • 2 views
    Investment strategies for the next decade: Holding scarce assets such as gold and Bitcoin
    Home
    News
    School
    Search