Uncategorized

Radiant Capital Hacker Doubles $53 Million Fortune with ETH Trading

The individual behind last year’s $53 million Radiant Capital exploit has managed to nearly double the amount of misappropriated funds through shrewd Ethereum trading strategies.

Summary

  • The hacker increased stolen assets from $53M to $94M via trading ETH and DAI.
  • The attack took place in October 2024, targeting Radiant’s multisig wallet with macOS malware.
  • Investigations link the breach to the North Korea-associated AppleJeus group, with slim chances of recovery.

As reported by the on-chain analyst EmberCN on Aug. 19, the hacker previously sold 9,631 Ethereum (ETH) at an average price of $4,562, converting that to 43.9 million Dai (DAI), and later repurchased 2,109.5 ETH for $8.64 million DAI when prices dropped to $4,096.

The wallet now contains 14,436 ETH and 35.29 million DAI, which amounts to a total value of $94.63 million. This signifies an increase of over $41 million from the initial value of the stolen funds. Blockchain analytics firm Lookonchain pointed out that maintaining most assets in ETH during its price surge greatly contributed to this increase.

From $53 million heist to $94 million stash

The October 2024 intrusion of Radiant Capital, a multi-chain decentralized finance protocol, is recognized as one of the year’s major attacks. The intruder breached the core team’s multisignature wallet using macOS malware named INLETDRIFT, draining tokens from lending pools on both Arbitrum (ARB) and BNB (BNB) Chain.

At that time, the stolen assets were quickly converted into 21,957 ETH, valued at roughly $53 million when Ethereum was trading around $2,500. Rather than liquidating the assets, the hacker retained the ETH as its value rose. In recent weeks, they executed several trades to further increase their holdings.

Radiant Capital hack attribution and ongoing risks

Blockchain security experts have traced this attack back to North Korea’s AppleJeus group, known for its assaults on exchanges and DeFi protocols. Following the breach, Radiant Capital engaged with the FBI, Chainalysis, and Web3 security entities like SEAL911 and ZeroShadow. Nevertheless, the chances of recovery appear grim as the stolen funds continue to circulate through Ethereum-based trading activities.

This incident marked Radiant’s second breach in 2024, following an earlier, smaller $4.5 million flash loan exploit that year. It underscores the persistent security vulnerabilities in DeFi, which has already seen significant losses in 2025.

With over $94 million currently under their control, analysts and security teams will be keeping a close watch on the hacker’s next move.

Leave a Reply

Your email address will not be published. Required fields are marked *