$1.3M Theft Triggers 10-Day Blockchain Halt After Three-Year-Old Vulnerability Exploited
A $1.3 million theft on the Radix blockchain prompted a 10-day halt to prevent further exploitation of a three-year-old vulnerability. The bug, introduced in June 2023 during a code refactor, allowed an attacker to withdraw funds from any vault on the network without proper authorization.
The flaw was not detected by Zellic's 2024 security review, which audited the Radix protocol, including the engine kernel containing the defect. The bug changed how the engine handled vault references, enabling ordinary withdrawal functions to be called without enforcing ownership boundaries.
The attacker exploited the vulnerability on August 31, withdrawing $1.26 million worth of assets across 26 transactions. The stolen funds were sent through Hyperlane to Ethereum, BNB Chain, and Solana before being sold for Ether.
Raadix investigators concluded that the flaw could have been used against any vault on the network, putting tokens and other assets at risk. In response, network validators took enough stake offline to prevent further transactions while developers worked on a fix.