Raydium disclosed that its deprecated Legacy AMM V3 program was exploited for roughly $1.34 million after a flaw in LP token mint validation let an attacker bypass proportion checks on liquidity deposits. Only inactive Legacy V3 pools were reachable through the bug path; current mainnet programs, the SDK, and the Raydium DApp were not affected.
The protocol said affected users will be fully compensated and that a security review of all mainnet programs is underway. The exploit lands on a Solana DeFi segment that has shrunk sharply since the post-FTX rotation toward perps and the launch of Raydium's own V4 / CLMM engine — a context that makes a legacy-program drain small in dollar terms but awkward in optics.
Why it matters
Deprecated Solana program IDs rarely get shut down cleanly. As long as a program account remains executable on-chain, any validation gap in its instruction handlers is fair game — the attacker only needs the account's address, which is public. The Raydium case is a textbook version of that: V3 was superseded, but the program itself was still live.
Market impact
The $1.34M figure is small relative to cross-chain bridge exploits, and Raydium's pre-committed reimbursement caps contagion. What to watch: whether the security review surfaces similar validation gaps in other legacy Solana program IDs, and how the protocol's RAY token and TVL hold up in the 24-48 hours after the disclosure.
Frequently asked questions
-
What exactly was exploited in the Raydium hack?
An LP token mint validation flaw in Raydium's deprecated Legacy AMM V3 program let an attacker bypass proportion checks on liquidity deposits, draining roughly $1.34 million from inactive V3 pools.
-
Were Raydium's mainnet programs and user funds on the live DApp affected?
No. Raydium said only inactive Legacy AMM V3 pools were reachable through the bug path. Current mainnet programs, the SDK, and the Raydium DApp were not affected.
-
Will Raydium reimburse users who lost funds?
Raydium committed to fully compensating affected users and announced a security review of all mainnet programs. The protocol has not yet published a payout timeline or mechanism.
-
Why is a deprecated AMM program still exploitable?
As long as a Solana program account remains executable on-chain, its instruction handlers can be called by anyone who knows the program ID. Deprecation does not remove that surface; only closing or replacing the program account does.
-
How does the $1.34M Raydium exploit compare to other DeFi hacks?
The figure is small relative to major cross-chain bridge exploits. Raydium's pre-committed reimbursement and the limited scope — deprecated pools only — also cap direct contagion, though the optics pressure RAY and Raydium TVL in the short term.
WuBlockchain