HomeUncategorizedNorth Korean Hacker Behind $50 Million DeFi Platform Attack

North Korean Hacker Behind $50 Million DeFi Platform Attack

-

Cybersecurity firm Mandiant has concluded with “high confidence” that the hacker responsible for draining $50 million from Radiant Capital’s decentralized finance (DeFi) platform is linked to North Korea. The hack, which occurred earlier this year, was revealed in a report on December 6, where Mandiant traced the attack to a North Korea-affiliated threat actor, with ties to the Democratic People’s Republic of Korea (DPRK).

The breach began on September 11, when a Radiant developer received a Telegram message seemingly from a trusted former contractor. The message contained a zip file requesting feedback on a new project, which, unbeknownst to the developer, carried malware designed to compromise the platform’s security.

Radiant Capital disclosed that the zip file, believed to have been sent by a DPRK-linked hacker impersonating the contractor, contained malware that went undetected at first. Once the file was shared among the development team, it triggered a chain of events that ultimately led to the attack. The malware infected multiple developer devices, allowing the attackers to manipulate data and control several private keys and smart contracts. This breach prompted Radiant to halt its lending markets on October 16.

Despite the initial confusion, Radiant confirmed that the zip file, which appeared to contain PDF documents, did not raise immediate suspicions. Reviewing PDFs in professional environments is a standard practice, and the file’s domain name was designed to closely resemble the contractor’s legitimate website, adding another layer of deception.

Radiant’s security measures, such as using simulations through Tenderly and verifying payload data, failed to detect the intrusion. The attack was so seamlessly carried out that the usual security checks revealed no obvious discrepancies. Radiant explained that the hackers were able to manipulate transaction data in the background, while the front-end interfaces appeared benign.

“The threat was virtually invisible during normal review stages,” Radiant stated. “Even with our standard best practices and industry-standard procedures, the attackers successfully compromised multiple developer devices.”

The attackers, identified as “UNC4736” or “Citrine Sleet,” are believed to be affiliated with North Korea’s Reconnaissance General Bureau (RGB), and may also be connected to the infamous Lazarus Group. The Lazarus Group has been implicated in several major cyberattacks, including the theft of an estimated $3 billion in cryptocurrency between 2017 and 2023.

After the breach in October, around $52 million worth of cryptocurrency was moved by the hackers on October 24. Radiant Capital emphasized that the attack is a stark reminder of the evolving threats facing the DeFi sector and the limitations of current security measures in detecting sophisticated cyberattacks.

Previous Attacks on Radiant and North Korean Cyberattacks

This isn’t the first time Radiant has been targeted. In January, the platform was hit with a $4.5 million flash loan exploit, which similarly resulted in the suspension of its lending markets.

Additionally, North Korea has been implicated in previous high-profile cryptocurrency heists. In 2019, the country was accused of orchestrating a hack on South Korea’s Upbit exchange, resulting in the theft of 342,000 ETH, then valued at $41.5 million. The stolen funds are now worth over $1 billion, marking one of the largest cryptocurrency thefts tied to North Korea, according to the South Korean National Police Agency.

The Radiant Capital hack and similar incidents highlight the ongoing challenges in securing decentralized finance platforms, with experts warning that the threat of state-sponsored cyberattacks will continue to grow.

Martin joseph
Martin josephhttps://reportscoin.com
Hey, I’m Joseph! I’m a 22-year-old tech enthusiast who’s all about the future of finance. I got into crypto during my college years, and since then, it’s been a wild ride. I’m passionate about blockchain technology, NFTs, and how decentralized finance (DeFi) can empower everyday people. When I’m not reading the latest crypto news, I’m gaming, exploring new tech gadgets, or discussing the next big trends in Web3.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

LATEST POSTS

Trump Nominates Stephen Miran to Lead Council of Economic Advisers

President-elect Donald Trump has tapped Stephen Miran, a former Treasury official from his first administration, to lead the Council of Economic Advisers (CEA). By selecting...

Japanese Investment Firm Metaplanet Makes Largest Bitcoin Purchase to Date

Tokyo-based investment firm Metaplanet has made its largest Bitcoin acquisition to date, purchasing nearly 620 BTC as the cryptocurrency trades below $100,000. On December 23,...

Survey: 7%-35% of Brazilians’ Portfolios in Crypto

A recent survey by Brazil's Securities and Exchange Commission (CVM) reveals that more Brazilians are investing in, trading, or holding Bitcoin and other altcoins than...

Dogecoin: Short-Term Dip, Long-Term Potential for 2025

Dogecoin (DOGE) faced a tough day on Wednesday, dropping 9% as risk assets took a hit following the US Federal Reserve’s latest policy announcement. While...

Most Popular