3-year-old bug triggers $1.3 million drain and forces 10-day blockchain halt
A routine Radix code refactor created a vault flaw that enabled a roughly $1.3 million theft and later compelled validators to halt the blockchain.
The Radix Foundation said Sept. 17 that an RDX Works growth staff launched the defect throughout a June 2023 cleanup of the Radix Engine, the software program layer that executes transactions and enforces asset possession throughout the community. The vulnerability remained undetected for greater than three years earlier than an attacker exploited it on Aug. 31.
A neighborhood reconstruction of the ledger shows the attacker withdrew about 458,915 USDC, 72,420 USDT, 61.08 ETH, 6.35 wrapped Bitcoin, 536.16 SOL and 32.91 BNB throughout 26 transactions. The property have been price roughly $1.26 million utilizing Aug. 31 market costs, and the attackers took one other 13,000 XRD from a vault to pay transaction charges. The two stablecoins alone accounted for about $531,335.
The stolen property have been despatched by way of Hyperlane to Ethereum, BNB Chain, and Solana, then bought for ETH, Radix stated. Hyperlane itself operated as designed: the attacker had already obtained the property by way of the Radix Engine earlier than utilizing the bridge to maneuver them elsewhere. No personal keys have been compromised.
However, the quick loss understated the potential publicity. Radix investigators concluded the flaw might have been used in opposition to any vault on the community, placing tokens and different property past the bridged holdings focused by the attacker in danger.
As a end result, community validators intentionally took sufficient stake offline to stop it from reaching consensus and stopping further transactions whereas builders labored on a repair.
Radix audit miss turns upkeep bug into systemic failure
The vulnerability had already survived an impartial safety overview earlier than the attacker discovered it.
Zellic audited the Radix protocol in 2024, together with the engine kernel containing the defect. The review didn’t detect the authorization flaw, although the weak code had been launched throughout the earlier 12 months’s refactor.
The bug modified how the engine dealt with vault references. A transaction might establish one other consumer’s vault by its inner deal with and move that reference into purpose-built smart-contract code. The engine then allowed bizarre withdrawal capabilities to be known as with out correctly implementing the possession boundary that ought to have rejected the request.
That gave the attacker entry to property held by consumer accounts, functions and liquidity swimming pools with out acquiring the homeowners’ signatures.
The Foundation stated the attacker accomplished 26 exploit transactions between 16:02 and 16:57 UTC on Aug. 31. Once investigators decided the vulnerability existed within the execution layer reasonably than a single utility, validators coordinated to cease transaction finalization.

The halt lasted greater than 10 days. A protocol repair added checks stopping a restricted vault reference from getting used for an bizarre withdrawal, and consumer transactions resumed Sept. 11, in response to the neighborhood ledger reconstruction.
The incident additionally produced secondary losses in liquidity swimming pools after the attacker eliminated bridged property from one aspect of buying and selling pairs. The distorted costs allowed one other account to extract tens of millions of XRD from affected swimming pools, displaying how an execution-layer failure can maintain inflicting financial harm even after the preliminary property have left the community.
Radix stated it’s including regression exams, strengthening its safety overview course of, and formalizing the emergency process validators used to interrupt community liveness.
The Foundation additionally stated future safety work should account for more and more succesful AI-assisted code-analysis tools, which it believes could have helped the attacker establish the years-old defect.
For builders and validators, the subsequent problem is stopping equally routine upkeep work from silently altering safety assumptions that exterior audits could miss.
That process extends past repairing the exploited code. Radix now has to strengthen the overview course of round adjustments to authorization logic whereas restoring confidence amongst customers and liquidity suppliers whose property in the end rely on the engine implementing these boundaries accurately.
The publish 3-year-old bug triggers $1.3 million drain and forces 10-day blockchain halt appeared first on CryptoSlate.
