Home > DeFi > Body

Radiant Capital Says DPRK Actor Posed as Ex-Contractor to Pull Off $50 Million Hack

clock
2024-12-09 13:52:23

Hackers from the Democratic People’s Republic of Korea (DPRK)—commonly known as North Korea—are responsible for the recent Radiant Capital hack, the firm claims.

In mid-October, decentralized finance (DeFi) protocol Radiant Capital lost about $50 million to what the team described as “one of the most sophisticated hacks ever recorded in DeFi.”

Now, in a more recent update, Radiant Capital’s contracted cybersecurity firm Mandiant “assesses with high confidence that this attack is attributable to a Democratic People’s Republic of Korea (DPRK)-nexus threat actor.”

Recounting the events, the post explains that when a developer was contacted by a “trusted former contractor” in early September, it was a DPRK actor in disguise. The impersonator shared a zip file under the guise of asking for feedback on a new project they were working on.

“This ZIP file, when shared for feedback among other developers, ultimately delivered malware that facilitated the subsequent intrusion,” reads the reconstruction of the events. The malware in question was reportedly sophisticated. It established a permanent macOS backdoor while still displaying a legitimate PDF to the user to avoid detection.

The payload was a malicious AppleScript that led the system to communicate with an innocent-sounding domain name, the team said. The hackers were also able to leverage the malware to bypass the security measures put in place by web3 infrastructure provider Tenderly.

“This deception was carried out so seamlessly that even with Radiant’s standard best practices, such as simulating transactions in Tenderly, verifying payload data, and following industry-standard SOPs at every step, the attackers also compromised multiple developer devices,” the post explains.

Explaining how Tenderly acted on the hacked devices, the post explains that “the front-end interfaces displayed benign transaction data while malicious transactions were signed in the background. Traditional checks and simulations showed no obvious discrepancies, making the threat virtually invisible during normal review stages.”

Edited by Stacy Elliott.

Web3 Desktop Trading Tool
Stay ahead of the game in the cryptocurrency space.

7x24 Newsflash

23:48 2025-03-30
Goldman Sachs: The Federal Reserve is now expected to cut interest rates in July, September, and November
Goldman Sachs: The Federal Reserve is now expected to cut interest rates in July, September and November.
23:45 2025-03-30
California Congressman Juan Carrillo Valencia Proposes "Bitcoin Bill of Rights" AB-1052
Bitcoin.com News said in a social media post that California Congressman Juan Carrillo Valencia introduced Bill 1052 (AB-1052), the "Bitcoin Bill of Rights," which aims to lock in financial freedom for 40 million in the United States, protect users' rights to hold bitcoin, enable payment without penalty, and establish true custody rules for lost assets.
23:36 2025-03-30
Goldman Sachs increases U.S. recession probability and tariff rate expectations
Goldman Sachs sharply raised its forecast for US tariffs in 2025 in a research report early this morning, warning that escalating trade tensions could severely impact economic growth, inflation and jobs. The bank now expects average US tariff rates to rise by 15 percentage points in 2025, up from 10 percentage points previously.
23:33 2025-03-30
WSJ: The Trump team is weighing broader, higher tariffs
On March 31st, according to the Wall Street Journal, the Trump team is discussing the implementation of broader and higher tariffs before the deadline, including possible across-the-board tariffs of up to 20% on all trading partners.
22:57 2025-03-30
The current bitcoin holdings in El Salvador are 6132.18
According to Mempool data, El Salvador currently holds 6,132.18 BTC, which is about $606 million.
21:02 2025-03-30
US congressman: Trump intends to "completely destroy" Iran's economy
US President Donald Trump plans to continue applying maximum pressure on Iran aimed at "totally destroying" its economy, according to Alice Stephanick, a US congressman. "President Trump intends to ensure that the maximum pressure campaign against Iran continues to completely destroy the Iranian economy and put peace in the Middle East first," Alice Stephanick said in an interview. Stephanick said the US leader was "firmly committed" that Iran would never acquire a nuclear weapon.
20:22 2025-03-30
Ethereum Gas Fee Now 0.37Gwei
According to Etherscan data, the Ethereum Gas Fee is now reported at 0.37Gwe.
18:45 2025-03-30
BTC falls below $82,600
The market shows that BTC fell below $82,600, and is now reported at $8 2598.76, with a 24-hour increase of 0.04%. The market fluctuates greatly. Please do a good job in risk control.
17:53 2025-03-30
Analysis: Cryptocurrency market cap has evaporated by $610 billion so far this year, and the current key support level of BTC may be $81,600
According to Bitcoin.com, in the 89 days since entering 2025, the total value of the cryptocurrency space has shrunk by $610 billion, from about $32,700 to $2.66 trillion. Bitcoin is trading between $82,856 and $83,032, with a market cap of around $1.65 trillion and a 24-hour global trading volume of close to $14 billion. Currently Bitcoin is showing signs of a short-term consolidation. Despite the temporary upward momentum, the volume pattern indicates weaker buyer participation. Lower highs an...
17:20 2025-03-30
ETH falls below $1,800
The market shows that ETH has fallen below $1,800 and is now quoted at $1,799.38, a 24-hour decline of 0.32%. The market is volatile, so please do a good job in risk control.
16:56 2025-03-30
BNB fell below $600
The market shows that BNB has fallen below $600 and is now quoted at $599.9, a 24-hour decline of 0.26%. The market is volatile, so please do a good job in risk control.
16:47 2025-03-30
BTC breaks through $82,500
The market shows that BTC broke through $82,500, and is now reported at $8 2503.4, with a 24-hour increase of 0.19%. The market fluctuates greatly. Please do a good job in risk control.