Radix Engine Vulnerability Exploited in Asset Theft... Network Disrupted

A security breach exploiting a vulnerability in the Radix engine resulted in unauthorized withdrawals from a third-party vault and a temporary halt in network transaction processing. The Radix Foundation disclosed in an incident report released on September 17 that attackers leveraged a flaw in the vault ownership verification mechanism to withdraw assets including Ethereum (ETH), WBTC, USDT, USDC, BNB, SOL, and a small amount of XRD via bridges. The stolen assets were transferred externally through the Hyperlane bridge. To prevent further exploitation, the foundation blocked the Hyperlane routing path and offline-converted part of the validators' stakes to ensure consensus could not be achieved with insufficient stake.
The Foundation clarified that the vulnerability stemmed from a flaw in the Radix engine's vault authentication logic, not from bridge issues or private key breaches.
Korean Source
This article is an English localization of a Korean-language crypto news report. Original headline: 래딕스 엔진 취약점 악용돼 자산 도난…네트워크 중단