Multisig hack timeline

Radiant Capital2024-10 $50M

Compromised signer devices showed a benign transaction while the actual payload transferred pool ownership.

What happened

Compromised signer devices showed a benign transaction while the actual payload transferred pool ownership.

Transaction-level mechanics

Public post-incident disclosures do not include full transaction calldata or execution traces for this incident.

TODO: Add exact Safe transaction hash, decoded actions, and the on-chain state changes once verified primary sources are available. For now, the attack vector summary above is derived from public reporting.

What independent decoding / hash verification / config scanning would have caught

Decoding on a clean second device would reveal the ownership-transfer call. Caveat: the devices themselves were compromised, so verification had to happen off those machines.

Verdict

Could have helped partially