Friday, September 18, 2026

Latest Posts

3-year-old bug triggers $1.3 million drain and forces 10-day blockchain halt

A routine Radix code refactor created a vault flaw that enabled a roughly $1.3 million theft and later forced validators to halt the blockchain.

The Radix Foundation said Sept. 17 that an RDX Works development team introduced the defect during a June 2023 cleanup of the Radix Engine, the software layer that executes transactions and enforces asset ownership across the network. The vulnerability remained undetected for more than three years before an attacker exploited it on Aug. 31.

A community reconstruction of the ledger shows the attacker withdrew about 458,915 USDC, 72,420 USDT, 61.08 ETH, 6.35 wrapped Bitcoin, 536.16 SOL and 32.91 BNB across 26 transactions. The assets were worth roughly $1.26 million using Aug. 31 market prices, and the attackers took another 13,000 XRD from a vault to pay transaction fees. The two stablecoins alone accounted for about $531,335.

The stolen assets were sent through Hyperlane to Ethereum, BNB Chain, and Solana, then sold for ETH, Radix said. Hyperlane itself operated as designed: the attacker had already obtained the assets through the Radix Engine before using the bridge to move them elsewhere. No private keys were compromised.

Read More:  Strive adds $12 million to its dividend tab after issuing nearly one million new preferred shares to buy Bitcoin

Related Reading

Hacker turned 55 days of failed transactions into a $3 million master key that drained GalaChain wallets

However, the immediate loss understated the potential exposure. Radix investigators concluded the flaw could have been used against any vault on the network, putting tokens and other assets beyond the bridged holdings targeted by the attacker at risk.

As a result, network validators deliberately took enough stake offline to prevent it from reaching consensus and stopping additional transactions while developers worked on a fix.

Radix audit miss turns maintenance bug into systemic failure

The vulnerability had already survived an independent security review before the attacker found it.

Zellic audited the Radix protocol in 2024, including the engine kernel containing the defect. The review did not detect the authorization flaw, even though the vulnerable code had been introduced during the previous year’s refactor.