logo

Radiant links $50 million crypto heist to North Korean hackers

ID: de4fe231-effc-5a59-9ecf-550efb732b00

STIX ID: report--de4fe231-effc-5a59-9ecf-550efb732b00

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2024-12-09

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Radiant Capital disclosed a $50M DeFi breach (Oct 16, 2024) attributed to North Korean-linked UNC4736 (aka Citrine Sleet / AppleJeus). Attackers used social engineering (Telegram message) to deliver a malicious ZIP containing a decoy PDF and macOS backdoor 'InletDrift', compromising developer devices, bypassing multisig and hardware-wallet protections, and signing unauthorized transactions on Arbitrum and Binance Smart Chain; Mandiant aided attribution and Radiant is working with U.S. law enforcement to recover funds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.