Raydium, one of Solana's largest decentralized exchanges, lost about $1.34 million on June 10 after an attacker exploited a flaw in its legacy AMM V3 program, draining five liquidity pools that had been inactive since 2021.
"The exploit was limited to a retired program that was no longer accessible through Raydium's interface," pseudonymous contributor 0xInfra posted on X. "No current users of Raydium are affected by this exploit."
The attack targeted five dormant pools — Sollet USDT-RAY, Sollet ETH-RAY, SRM-RAY, USDC-RAY and RAY-SOL — all tied to the Serum era on Solana. The attacker removed about 150,177 RAY, 5,603 SOL and 893,700 USDC, worth roughly $900,000, $357,000 and $86,000 respectively, according to 0xInfra. The exploiter's Solana address ends in Bq33QVk.
The old program failed to validate whether the LP token mint was legitimate, allowing the attacker to create a fake mint and bypass the proportion checks governing withdrawals. Raydium said its current mainnet programs avoid the bug through a virtual supply mechanism and stricter LP mint verification. The exchange added that its live programs are undergoing a separate security review.
PeckShield and on-chain investigator Specter traced the attacker's initial funding to KuCoin. The stolen funds were bridged from Solana to Ethereum and deposited into Tornado Cash, a crypto mixer that obscures the on-chain trail.
RAY traded up more than 2% on the day at $0.578, though it remained down about 7% on the week and 96.6% below its all-time high of $16.83. Raydium's concentrated liquidity pools and newer AMM versions held no exposure, limiting the total loss to $1.34 million.
The incident highlights a structural risk unique to public blockchains: deprecated smart contracts remain live on-chain even after being removed from a protocol's interface, leaving dormant funds exposed to vulnerabilities in retired code. Raydium said it will compensate impacted users from its treasury.
This article is for informational purposes only and does not constitute investment advice.