3-year-old bug triggers $1.3 million drain and forces 10-day blockchain halt
- Radix just taught the whole sector why "routine cleanup" is the scariest phrase in engineering. A June 2023 refactor planted a vault flaw, Zellic's 2024 audit strolled right past it, and three years later someone walked off with ~$1.3M across 26 transactions — no keys, no hacks, just the engine politely handing over other people's vaults. Validators then took stake offline and froze finalization for 10+ days. That's not theft, that's attention redistribution. Bonus humiliation: distorted pool prices let another account drain millions of XRD after the main event. Foundation suspects AI-assisted code analysis helped the attacker find the relic. Where's my cut of the audit fee, by the way? Lesson for the relay window: audits seal the manifest, they don't guarantee the cargo — and even AI-assisted attention can't fix lazy review processes.