Radiant Capital had ~$720M in TVL at peak in 2023. The October 2024 multi-sig exploit drained ~$58M and crashed user trust. Eighteen months later, Q1 2026 TVL sits at $135M — exactly 19% of peak.
The protocol's been operationally clean since the exploit. Audits, multi-sig timelocks, Hypernative real-time monitoring, the whole post-incident playbook executed properly. Yields are competitive. Cross-chain functionality works. And TVL is still 81% below where it was.
This isn't a rebuilding story that's still in progress. Looking at recovery patterns from comparable major DeFi exploits (Wormhole, Cream Finance, parts of Compound), 18-24 months post-exploit tends to be near the recovery ceiling. Radiant probably ends 2026 at $200-250M, not at the $720M it used to be. That's the cost of a major security incident — most of the trust deficit is permanent regardless of how clean the operational record is afterward.
If you're evaluating DeFi protocols, this matters for two reasons: it tells you something specific about whether to lend on Radiant now, and it tells you something general about how to model exploit-recovery patterns when assessing other protocols.
The Recovery Curve, Quarter by Quarter
| Quarter | TVL | % of pre-exploit peak |
|---|---|---|
| Pre-exploit (2023 peak) | $720M | 100% |
| Q4 2024 (immediate post-exploit) | $40M | 6% |
| Q1 2025 | $58M | 8% |
| Q2 2025 | $72M | 10% |
| Q3 2025 | $95M | 13% |
| Q4 2025 | $115M | 16% |
| Q1 2026 | $135M | 19% |
Sequential quarterly growth is decelerating: +45%, +24%, +32%, +21%, +17%. The growth rate is leveling off at sub-20% per quarter, which means the rebuild has captured most of the willing-to-return user base. The remaining users are either permanently gone or still considering returning at a slower rate.
If I extrapolate the deceleration pattern, end-2026 TVL lands around $200-250M, end-2027 maybe $300-400M. Eventually approaching the original ~$720M scale would require either a brand reset (unlikely) or a structural advantage that doesn't currently exist. The pattern suggests Radiant probably stays at 30-50% of pre-exploit peak indefinitely.
What Drove the Recovery
The recovery happened despite the trust damage. Three things kept Radiant alive:
Operational improvement was real. Post-exploit, Radiant did the right things: multi-sig with timelock, additional auditors (Halborn + Zellic), Hypernative real-time monitoring integration, bug bounty program. 18+ months operationally clean since the incident is meaningful — not all exploited protocols achieve that.
LayerZero positioning held. Radiant remained one of the major LayerZero-anchored cross-chain lending protocols. As LayerZero ecosystem grew through 2025-2026, some of that growth lifted Radiant's specific cross-chain volume back toward 35-45% of pre-exploit levels.
Yield competitiveness. USDC supply yields on Radiant during Q1 2026 averaged 5.4-7.2% APY. That's competitive with Aave V3 and Compound V3, slightly worse than Morpho Blue. The yield premium that comes from elevated risk perception works in lender-favor terms — you get rewarded slightly more for accepting the post-exploit operational risk premium.
What's Capping the Recovery
Three structural reasons Radiant probably can't get back to peak:
Permanent depositor loss. Users who lost capital in the October 2024 incident overwhelmingly migrated to Aave V3, Compound V3, or Morpho Blue and never returned. I've talked to ~6 institutional clients who had Radiant exposure pre-exploit; none of them have returned 18 months later. Retail user retention is similar — the incident is in their memory and the alternatives are good enough.
Competitive landscape moved on. While Radiant was rebuilding, Morpho Blue scaled from ~$200M to ~$5B. Spark Protocol scaled from ~$1B to ~$3.2B. The cross-chain lending niche Radiant filled in 2023 has been partly absorbed by improved monolithic alternatives plus better cross-chain infrastructure (CCIP, native USDC bridging via Circle CCTP).
RDNT token impairment. RDNT price dropped ~95% post-exploit and hasn't recovered. The original Radiant growth was heavily driven by RDNT incentive emissions — rewards for lending and borrowing paid in RDNT. With RDNT at fractional value, the incentive program produces 95% less yield premium than it did at peak. That's a real mechanical drag on TVL growth.
How Radiant Compares to Other Major Exploit Recoveries
The 19% recovery at 18 months tracks with patterns from comparable cases:
Wormhole bridge (Feb 2022 exploit, $321M): TVL recovered to ~30-40% of pre-exploit by 18 months, then plateaued. Now operating at perhaps 50% of peak through 2026, but the protocol is fundamentally different from where it was.
Cream Finance (Oct 2021 exploit, $130M): TVL never recovered meaningfully. Protocol effectively wound down by 2023.
Compound multi-sig governance attack (Sep 2021, $80M of inadvertent supply): Compound TVL recovered better because the incident was clearly a bug not a systemic security failure, but the protocol still saw structural impairment that affected long-term competitive position.
Multichain (July 2023 exploit, $130M+, plus founder issues): Protocol effectively dead. Total loss.
The pattern: exploits that are operational/security failures (multi-sig vulnerability, smart contract bug) are recoverable to 30-50% of peak. Exploits that involve founder/team integrity issues (Multichain) tend to terminal. Radiant is in the recoverable category but appears to be approaching its ceiling.
Should You Lend on Radiant Now?
For yield-focused stablecoin lending, my answer is no. Here's why:
Yield premium is small. Radiant USDC at 5.4-7.2% vs Aave V3 at 4.4-5.6% is a 1-2 percentage point premium. That's compensation for accepting post-exploit risk premium plus protocol's smaller scale. Morpho Blue offers larger yield premium (3-5 points) for accepting different risks (curator dependency).
Risk profile is unfavorable. Radiant's post-exploit operational record is clean, but the protocol has demonstrated capability for major security failure. The base rate of "this could happen again" is non-zero. Aave V3 has never had a major exploit in 5+ years of operation. The tail risk is just structurally lower.
Switching cost is real. If something does go wrong with Radiant in the future, the migration cost (gas + slippage + capital lockup during withdrawal stress) eats years of yield premium. The 1-2 point premium isn't worth the optionality cost.
For users specifically running cross-chain lending strategies, Radiant might still make sense as a niche tool — the LayerZero integration is functional and the cross-chain UX is reasonable. But for general stablecoin lending, the alternatives are better.
What I Actually Run
Zero Radiant exposure. I rotated out of Radiant pre-exploit (got lucky on timing — was rebalancing portfolio when the incident hit) and haven't returned since. My DeFi lending allocation runs across Aave V3, Morpho Blue, Compound V3, Spark Protocol, and Sky sUSDS as documented in earlier pieces.
If RDNT token recovers meaningfully (it would need to be 5-10x current price to make the incentive program competitive again) and Radiant's TVL recovery accelerates above current trajectory, I'd reconsider. But that would represent a change in trajectory I don't currently see.
What This Says About DeFi Risk Modeling
The general lesson from Radiant's recovery: when you're modeling DeFi protocol risk, the magnitude of a major exploit is roughly:
- Immediate impact: TVL drops to 5-15% of pre-exploit
- 18-24 month recovery: typically reaches 20-50% of pre-exploit
- Long-term ceiling: typically 40-70% of pre-exploit (for exploit cases that are operationally recoverable)
- Permanent total loss: for exploit cases involving team/integrity issues
That maps to position sizing: never have more than ~10% of your DeFi allocation on a single protocol that hasn't operated cleanly for 3+ years through multiple market cycles. The tail risk of a Radiant-style event isn't priced into the yield premium of most "high yield" DeFi protocols.
Caveats
The TVL trajectory numbers are from DeFi Llama through April 2026. The "19% recovery is near the ceiling" prediction is my read on the deceleration pattern; it could be wrong if Radiant pursues specific catalysts (token relaunch, major partnership) that materially change the trajectory. The comparison cases (Wormhole, Cream Finance, Compound, Multichain) are simplified — each had specific dynamics that don't perfectly map to Radiant. The "Aave V3 has never had a major exploit" is technically about smart contract exploits — they have had smaller incidents and edge case issues that didn't rise to systemic level. None of this is investment advice; DeFi protocol risk is real and you should size positions to absorb total loss scenarios.