Radiant Post-Mortem
2024-10-18 • Radiant Capital •
https://medium.com/@RadiantCapital/radiant-post-mortem-fecd6cd38081
This breach occurred during a routine multi-signature emissions adjustment process, which takes place periodically to adapt to market conditions and utilization rates. The malicious actors exploited this normalcy, using the process to collect multiple compromised signatures over several attempts, all while mimicking the appearance of routine transaction failures. The attackers used malware to manipulate transaction data at the device level, bypassing manual checks and simulations in Tenderly, which returned normal results. The attackers exploited this by presenting normal-looking transactions in Gnosis Safe, with no visible anomalies, aside from routine transaction failures — a common occurrence, making detection difficult.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | help.safe.global | 2024-10-18 | 2025-02-26 |
| DOMAIN | chainlist.org | 2024-10-18 | 2024-10-18 |