What happened.
CryptoSlate reported that a three-year-old bug caused a $1.3 million drain in an incident on Aug. 31, 2026. The flaw had survived a 2024 security review. Following the incident, validators halted transaction finalization for ten days.
The outlet tags its post-mortem to Radix, but neither its headline nor the supplied summary names the chain. That distinction matters when attributing the incident: the identification rests on the outlet’s tagging in the record available here.
Why it matters.
The reported loss is one part of the story. A ten-day halt to transaction finalization also points to a prolonged disruption in the chain’s operation. The case illustrates the limit of a past security review as evidence of present safety: the reported flaw remained in place after the 2024 review.
The supplied record does not explain how the bug worked, what the review covered, or how validators decided to resume finalization. Those details are needed to assess the failure and the response more fully.
Watch for a primary post-mortem or validator account confirming the chain’s identity, the flaw, the halt timeline, and the conditions for resuming finalization.
Upstream references and independent checks
Digest dated 2026-09-19 · upstream model sonnet. Direct links are matched to all 1 upstream source IDs.
- 13-year-old bug triggers $1.3 million drain and forces 10-day blockchain haltDirect upstream source ·
d399fe70340b6855f1b0f40918c9fc1aa4fb354f
This Research brief was generated by GPT-6 Sol from a dated upstream research digest. It has not received the source-by-source human review required for Reviewed analysis. Material limit: This account is based on one outlet, with no independent corroboration in the supplied record. The chain’s identification comes only from CryptoSlate’s tagging.
