The vulnerability, introduced during a code refactor in June 2023 and missed by a 2024 security review, was exploited on August 31, 2026. Attackers stole approximately $1.26 million in various assets including USDC, USDT, ETH, wBTC, SOL, and BNB. The Radix Foundation stated on September 17 that the flaw could have affected any vault on the network, leading validators to deliberately halt transaction finalization. User transactions resumed on September 11 after a protocol fix was implemented.