Incident case file
Sign in to watchRadix Vault Authorization Vulnerability — $1.3M, Addresses Referred to Law Enforcement Only
0 views
Estimated loss
Affected users
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatOn August 31, 2026, between 16:02 and 16:57 UTC, an attacker exploited a bug in the core Radix Engine that had existed since June 2023 and had gone undetected through a prior Zellic security audit conducted in August 2024. The bug allowed unauthorized withdrawal from vaults belonging to third parties. Across 26 transactions, the attacker extracted a combined total of $1,249,946 in assets (458,915 USDC, 72,420 USDT, 61.08 ETH, 6.35 WBTC and 536.16 SOL). Network consensus was halted for more than 10 days, resuming around September 11, with a full public incident report (v1.4) published September 17. The attacker's addresses have been turned over exclusively to law enforcement authorities in Jersey and the UK and have never been made public.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)