Radiant Capital was founded in 2022 as a cross-chain money market protocol whose TVL stood at $386.8 million in December 2023. But everything changed in October 2024 after the firm experienced a massive cyberattack, resulting in its TVL falling from $386.8 million to $75 million. It has now dropped to a mere $5 million since then. Prior to the recent hack, the platform had already lost another $4.5 million worth of 1,900 ETH through a flash loan attack.
The process of development, updates, and expansion will come to an end when DAO developers quit working, but Radiant will shift to maintenance mode forever. Its frontend and smart contracts will stay active indefinitely, ensuring that users can still withdraw their money, pay off their debts, and close their positions. Moreover, the DAO clarified that its remediation portal will be available permanently so that all recovered funds will eventually return to their owners.
Sophisticated North Korean Cyber Espionage Group Behind the October 2024 Attack
The crypto cyber attack committed in October 2024 turned out to be a part of an intricate cyber espionage campaign carried out in December 2024 by the hacker who pretended to be a former contractor and circulated a malicious ZIP archive on the Telegram channel of Radiant as part of the feedback process.
According to Mandiant’s analysis, the exploit was executed by a member of the AppleJeus hacking group, which is part of the broader cyber espionage ecosystem supported by the North Korean government. The attackers managed to compromise three of Radiant’s eleven multisig permissions and replace its lending pool implementation contract, extracting up to $51 million-$53 million worth of tokens.
The retrieval of these funds proved to be almost impossible as well. In October 2025, the blockchain analytics company CertiK reported that hackers managed to launder some $10.8 million (2,834 ETH) through the use of Tornado Cash mixing service by using unique wallets and decentralized exchanges in between.
A Blueprint Threat for DeFi
The tactics employed by the hackers in the Radiant Capital case have now been used to attack another DeFi protocol. In April 2026, Drift Protocol announced “medium-high confidence” that it was the same North Korean actors responsible for the attack on its system. According to the results of the investigation, the attackers spent several months gaining the trust of protocol members through professional networks and events before delivering the malware.