Radix Blockchain Halted for 10 Days After $1.26 Million Bug Exploit
A routine code refactor on the Radix blockchain in June 2023 introduced a vault flaw that remained undetected for over three years. An attacker exploited this vulnerability on August 31, withdrawing approximately $1.26 million worth of assets across 26 transactions.
The stolen funds included USDC, USDT, ETH, wrapped Bitcoin, SOL, and BNB, which were sent through the Hyperlane bridge to Ethereum, BNB Chain, and Solana. No private keys were compromised in the process.
The immediate loss was around $1.26 million, but investigators concluded that the flaw could have been used against any vault on the network, putting other tokens and assets at risk.
As a result, validators took enough stake offline to prevent further transactions, halting the blockchain for over 10 days while developers worked on a fix.
The vulnerability had survived an independent security review in 2024, which did not detect the authorization flaw. The Radix Foundation is now strengthening its security review process and formalizing emergency procedures to prevent similar incidents in the future.