Solana-based exchange Raydium suffered a $1.34 million exploit targeting five deprecated AMM V3 liquidity pools from 2021. The attacker exploited a logic flaw, creating a fake LP mint to bypass validation and drain assets. No current users were affected as the pools were inaccessible via the official UI. Raydium has committed to compensating all losses from its treasury and is conducting a full security review.
Exploit Details and Financial Impact
- ▪Solana-based decentralized exchange Raydium was exploited for approximately $1.34 million
- ▪Stolen assets included approximately 150,177 RAY, 5,603 SOL, and 893,700 USDC
- ▪The exploit drained funds from five deprecated AMM V3 liquidity pools that were phased out in 2021
Vulnerability and Technical Cause
- ▪The attacker created a fake LP mint to bypass security checks and withdraw liquidity
- ▪The vulnerability was a logic flaw stemming from insufficient validation of the LP mint address in the legacy program
- ▪The issue was a self-contained logic flaw and not a key compromise or authority-level issue
Scope and User Impact
- ▪No current users, active pools, or modern Raydium protocols were affected by the exploit
- ▪The affected pools had not been accessible through Raydium's official UI, SDK, or DApp for several years
- ▪The liquidity in the deprecated pools was previously used to place orders on the Serum protocol before its shutdown
Raydium's Response and Mitigation
- ▪Raydium stated that its treasury will provide full compensation for the drained funds
- ▪Raydium is conducting a comprehensive security review of all its mainnet programs following the incident
Attacker Actions and Broader Context
- ▪After the exploit, the attacker funneled approximately 810 ETH through the privacy mixer Tornado Cash
- ▪The attacker's wallet was reportedly funded initially from the KuCoin centralized exchange
Story comments
Loading comments…