Skip to content
NetarxImpact Database
Vendor / Supply Chain ImpersonationNo AI reportedReported

DPRK actor posing as a former contractor took $50M from Radiant Capital

Radiant Capital · Cryptocurrency · Unknown · October 2024

Funds lost
$50,000,000
Money actually taken from, or wired out by, the victim.
Approximately $50 million, with stolen funds moved on October 24, 2024. Radiant Capital later wound down operations.

What happened

Radiant Capital lost about $50 million in October 2024. On September 11, a threat actor impersonating a trusted former contractor messaged a Radiant developer on Telegram from a spoofed version of the contractor's real domain and shared a ZIP file framed as a request for feedback. The file was passed among other developers, spreading malware. Mandiant attributed the attack with high confidence to a DPRK-nexus actor tracked as UNC4736.

How the deception worked

The pretext worked because the sender was someone the team already knew and the ask, review this document, was ordinary. The ZIP contained a decoy PDF that opened normally while a macOS backdoor installed behind it, and because the developer forwarded the file to colleagues for their input, the compromise multiplied across the signer group. With malware on multiple developer machines, the attackers manipulated what those machines displayed: front-end interfaces and simulation tools such as Tenderly showed benign transaction data while malicious transactions were being signed underneath. Radiant noted that traditional checks and simulations showed no obvious discrepancies, so the review process that should have caught the theft confirmed it instead.

AI involvement · No AI reported

No AI-generated media was reported; the impersonation relied on a spoofed contractor domain and an existing working relationship.

The control that would have caught it· our reading, not a claim from the sources

Signing must happen on dedicated, hardened devices that do nothing else, with the transaction independently verified on separate hardware, because once the reviewer's endpoint is compromised, on-screen verification is worthless.

Sources (2)

  1. Radiant Capital says North Korea posed as ex-contractor to carry out $50M hack
    Cointelegraph·cointelegraph.comOpen ↗
  2. Radiant Capital Says DPRK Actor Posed as Ex-Contractor to Pull Off $50 Million Hack
    Decrypt·decrypt.coOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.