Radiant Post-Mortem

2024-10-18 Radiant Capital

https://medium.com/@RadiantCapital/radiant-post-mortem-fecd6cd38081

This breach occurred during a routine multi-signature emissions adjustment process, which takes place periodically to adapt to market conditions and utilization rates. The malicious actors exploited this normalcy, using the process to collect multiple compromised signatures over several attempts, all while mimicking the appearance of routine transaction failures. The attackers used malware to manipulate transaction data at the device level, bypassing manual checks and simulations in Tenderly, which returned normal results. The attackers exploited this by presenting normal-looking transactions in Gnosis Safe, with no visible anomalies, aside from routine transaction failures — a common occurrence, making detection difficult.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN help.safe.global 2024-10-18 2025-02-26
DOMAIN chainlist.org 2024-10-18 2024-10-18

Related Reports

« Back