
Radix Patches Vault Flaw After Cross-Chain Asset Theft

Radix Patches Vault Flaw After Cross-Chain Asset Theft
WEEX View
- The next key signal is Radix’s recovery process: whether network restoration proceeds smoothly and whether exchanges, custodians, and ecosystem applications resume normal operations without added restrictions.
- Markets should also watch for any follow-up disclosure on user or protocol exposure. The foundation identified affected ecosystem contracts, accounts, and liquidity pool vaults, but loss totals and any remediation or compensation framework were not disclosed in the available information.
- The incident also puts focus on cross-chain risk separation. Radix said the flaw was in the Radix Engine, not Hyperlane, which may matter for how infrastructure providers, validators, and users reassess operational dependencies across bridged assets.
Radix Foundation said it has fixed the vault authorization vulnerability behind the August 31 attack that let an attacker withdraw assets from third-party vaults without owner consent and route them to external chains through Hyperlane for sale.
According to the foundation’s incident report, the attacker exploited a previously undetected authorization flaw in the Radix Engine, the network’s execution layer, to remove assets from vaults owned by third-party packages and accounts. The stolen assets included ETH, WBTC, USDT, USDC, BNB, SOL, and a small amount of XRD used for transaction fees.
Radix said the assets were then transferred through the Hyperlane cross-chain bridge to an external chain and sold for ETH. The foundation said Hyperlane itself, its validators, and its message verification process operated correctly, and that the theft happened on Radix before the bridge was used. It also said no admin, recall, or clawback permissions were abused.
The foundation traced the vulnerability to a code cleanup in June 2023. It added that an independent security audit conducted by Zellic in August 2024 did not identify the issue. Radix said the first signs of the exploit were spotted by community members running validator nodes, who saw bridged assets being drained and escalated the matter to the team.
In response, Hyperlane suspended operations related to Radix, while validators voluntarily took enough staked shares offline to interrupt network activity and stop further exploitation. Radix said the fix has since gone through independent review and testing, and that network restoration is now in progress. The available information does not include a total value of stolen assets or a reimbursement plan.
Why It Matters
The incident highlights how execution-layer authorization bugs can cascade into cross-chain losses even when bridge infrastructure is functioning as designed. For projects relying on bridged asset liquidity, the event underscores that security assumptions extend beyond the bridge itself to the source chain’s core application and vault logic.
It also raises fresh questions about audit coverage and incident response design. Radix’s disclosure that the bug originated in 2023 and was missed by a later independent audit is likely to sharpen scrutiny on how protocol teams review execution-layer changes, monitor validator-side anomalies, and coordinate emergency shutdown measures when multiple ecosystem assets are at risk.
Milestones
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
About WEEX View
WEEX View is a crypto analysis and intelligence hub, covering the latest in Web3, AI, and global markets. Get independent research and in-depth insights to stay ahead of market trends and trading opportunities.
Latest articles
MoreVietnam Targets 2026 Crypto Licenses Under Pilot Framework
Vietnam said it expects to license its first crypto asset service providers in 2026 under a pilot framework, while officials discussed regulatory cooperation with Austria's FMA on investor protection, anti-money laundering, and market supervision.
SlowMist Warns FomoPeek iOS App Versions Carried Malicious Code
SlowMist said FomoPeek App versions 1.1 to 1.2 carried malicious code that could expose private keys and other sensitive data on affected iPhones, after users reported stolen assets linked to private key leaks.
Switchboard Says It Will Wind Down Oracle Operations
Switchboard said it is ceasing operations, with maintenance for its oracle implementations ending immediately and remaining support scheduled to end on September 25, prompting protocols to migrate to alternatives including Pyth and RedStone.
Bastion Seeks OCC Trust Charter as Stablecoin Regulation Tightens
Bastion is pursuing an OCC national trust bank charter after earlier reports framed the matter as conditional approval, highlighting growing efforts by crypto infrastructure firms to move stablecoin and custody businesses into a federal oversight framework.


