Raydium suffers $1.3M exploit, promises full compensation
Raydium lost $1.3M in an exploit of five deprecated Solana pools. The attacker bypassed old validation, but current users were unaffected. Raydium will fully compensate losses and enhance security.
Raydium, a decentralized exchange on Solana, suffered an exploit in its legacy AMM V3 program, resulting in losses of approximately $1.3–$1.34 million. The attack targeted five deprecated liquidity pools: RAY-SOL, USDC-RAY, SRM-RAY, Sollet USDT-RAY, and Sollet ETH-RAY. The attacker exploited a validation flaw in the outdated liquidity provider mint process, using a fake mint address to bypass security checks and withdraw around 150,177 RAY, 5,603 SOL, and 893,700 USDC. These pools had been phased out since 2021 and were not accessible via Raydium’s current interface or SDK, so current users and active pools were unaffected. The attacker’s wallet was reportedly funded through KuCoin, with the stolen assets later bridged to Ethereum and laundered via Tornado Cash. Raydium has pledged to fully compensate all affected users from its treasury and is conducting additional security audits to prevent similar incidents. This exploit highlights the ongoing risks associated with legacy DeFi infrastructure.