The Radix Treasury Exploit: A Breakdown of the Attack and Response

The Radix Foundation, supporting the full-stack DeFi project, has released a detailed report on a security incident that impacted its network. The report confirms that an attacker leveraged a vulnerability within the Radix Engine's treasury authorization system.

How the Attack Unfolded

On August 31, the exploiter used this flaw to withdraw assets from third-party managed treasuries without proper authorization from the owners. The siphoned assets were then bridged out via the Hyperlane cross-chain bridge and sold on external blockchains.

The scope of stolen assets was diverse, including:

  • Major Cross-Chain Assets: ETH, WBTC, USDT, USDC.
  • Other Ecosystem Assets: BNB, SOL.
  • Native Network Token: A small amount of XRD used for transaction fees.

The impact extended beyond individual smart contracts to include vaults belonging to several liquidity pools, indicating a systemic issue.

Root Cause and Missed Detection

Investigators traced the vulnerability's origin back to a code refactoring effort in June 2023. The authorization flaw was inadvertently introduced during this routine update. Notably, the bug remained undetected even during an independent security audit conducted by Zellic in August 2024, highlighting the challenges of securing complex DeFi protocols.

Emergency Response and Path to Resolution

Following the incident, the Radix team activated its emergency response protocol.

Immediate Containment Actions

To prevent further loss, the team executed swift containment measures:

  • Hyperlane, the bridge operator, promptly suspended all cross-chain operations involving Radix.
  • Network validators voluntarily took enough stake offline to halt block production, effectively freezing the network and stopping any further exploitation.

Patch Deployment and Recovery

The Foundation states that a code fix for the treasury authorization vulnerability has been completed. This patch underwent rigorous independent review and testing to ensure a comprehensive solution. The current focus is on safely restoring full network operations and reactivating bridge functionality.