Loading prices…
🩸BEARISH

Raydium exploit drains $1.34M via fake LP tokens on legacy AMM

The funds came from a legacy AMM V3 program Raydium phased out in 2021 — no current UI users were exposed, but the exploit shows aged on-chain program surfaces remain a live attack surface.

Raydium confirmed an exploit drained roughly $1.34 million from its legacy AMM V3 program, with the attacker using fabricated LP tokens to pull liquidity from pools the protocol had already phased out in 2021.

In a statement via its @0xINFRA account, the team said no current Raydium users were affected and that the deprecated pools could not have been reached through the protocol's UI. The exposure sits in residual on-chain program permissions tied to the old AMM version — surfaces that remain callable by anyone who knows the program ID, even after the front-end routes are pulled.

Why it matters

Exploits against deprecated but still-live program code have become a recurring Solana pattern: the front-end gets sunset, the on-chain program does not, and any unclaimed authority over LP token minting or pool liquidity stays exercisable. Raydium's incident is small in dollar terms relative to the multi-hundred-million Solana-era drains of 2022-2024, but the mechanism is the same one adversaries probe for whenever a major protocol retires a version.

Market impact

$RAY traded lower on the news, with the token decoupling from the broader Solana complex intraday. The dollar value limits contagion risk to other Solana DEXes, though the incident is likely to reignite scrutiny of governance hygiene around legacy program keys — and may push other AMM teams to publish explicit program-revocation attestations for retired pools.

Related tokens
$RAY $SOL

Frequently asked questions

  1. How was Raydium exploited?

    An attacker used fabricated LP tokens to pull liquidity from Raydium's legacy AMM V3 program, a version the protocol phased out in 2021. The on-chain program remained live even after the front-end routes were retired.

  2. Were current Raydium users affected?

    No. Per the team's @0xINFRA statement, no current users were impacted and the affected pools were never reachable through the Raydium UI.

  3. How much was stolen in the Raydium exploit?

    Roughly $1.34 million was drained from the deprecated AMM V3 pools. The dollar size is small relative to major Solana-era exploits of 2022-2024.

  4. Why are deprecated Solana programs still exploitable?

    Front-ends get sunset but on-chain programs do not — any unclaimed authority over LP token minting or pool liquidity remains exercisable by anyone with the right program keys, even years after retirement.

  5. What was the market impact on RAY token?

    $RAY traded lower on the news and briefly decoupled from the broader Solana complex intraday. Contagion risk to other Solana DEXes looked limited by the dollar size of the exploit.

Source attribution
Aggregated from Crypto News · Verified · Last refreshed 45d ago
Open original →