
Three-year-old Radix bug led to $1.3M theft and 10-day network halt
- —Stolen assets included about 458,915 USDC, 72,420 USDT, 61.08 ETH, 6.35 WBTC, 536.16 SOL and 32.91 BNB
- —USDC and USDT stablecoins accounted for about $531,335 of the total
- —A 2024 Zellic audit did not detect the vulnerability in the Radix Engine core
- —The network was halted for more than 10 days, with transactions resuming on September 11
Why it matters: The incident showed that routine code refactoring can silently break ownership boundaries and evade external audits, putting all network vaults at risk.
Source: CryptoSlate