← Radar

Incident case file

Sign in to watch

Radix Vault Authorization Vulnerability — $1.3M, Addresses Referred to Law Enforcement Only

Incident date Aug 30, 2026Last updated Sep 24, 2026

0 views

ContainedRadixEngine-level vault authorization bugCluster: RADIX-2026-08

Estimated loss

$1.3M

Affected users

Number of affected users is not confirmed
Group joining is coming soon.

Investigation

70%

Facts and investigation

Ledger

Attacker

TODO

Funds moved to

TODO — addresses were turned over exclusively to law enforcement (Jersey/UK) and have never been made public.

Linked

The Radix Engine bug had been present since June 2023 and was not detected by a prior Zellic audit conducted in August 2024. Total precise sum of assets withdrawn: $1,249,946 (458,915 USDC + 72,420 USDT + 61.08 ETH + 6.35 WBTC + 536.16 SOL), commonly rounded to $1.3M in media coverage.

Chronology

1 beat
  1. On August 31, 2026, between 16:02 and 16:57 UTC, an attacker exploited a bug in the core Radix Engine that had existed since June 2023 and had gone undetected through a prior Zellic security audit conducted in August 2024. The bug allowed unauthorized withdrawal from vaults belonging to third parties. Across 26 transactions, the attacker extracted a combined total of $1,249,946 in assets (458,915 USDC, 72,420 USDT, 61.08 ETH, 6.35 WBTC and 536.16 SOL). Network consensus was halted for more than 10 days, resuming around September 11, with a full public incident report (v1.4) published September 17. The attacker's addresses have been turned over exclusively to law enforcement authorities in Jersey and the UK and have never been made public.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)