Radiant's cross-chain lending design was ambitious: borrow on one chain against collateral on another, using LayerZero messaging. What ended it was not the ambition but basic key security.
The October 2024 compromise
Attackers compromised the devices of several multisig signers and presented them with transactions that appeared routine while executing a malicious contract upgrade. Multiple signers approved. Roughly $50m was drained. It is the same class of attack that hit Bybit months later: valid signatures authorising a transaction the signers did not understand.
The earlier exploit
In January 2024 a flash-loan attack exploited a rounding issue in a newly deployed market, costing around $4.5m. Two significant incidents in one year, from different causes, is a pattern rather than bad luck.
What it means for depositors
A protocol whose upgrade keys were compromised can be upgraded again. Recovery has been partial, the DAO's capacity to compensate is limited, and there is no version of this risk assessment where depositing here is sensible while comparable protocols with clean records exist on the same chains.
Who should use it
Nobody, on our assessment. The functionality Radiant offers is available at Aave, Morpho or Fluid without the incident history.