Raydium confirms that the old version of AMM V3 was attacked, approximately $1.34 million in assets were stolen, and full compensation will be provided.

Golden Finance reports that on June 11th, Raydium core contributor InfraRAY announced that the team confirmed an attack on the old version of the AMM V3 program, which was discontinued in 2021.
The attacker unauthorizedly removed some liquidity, but this incident does not affect current Raydium users, and the related liquidity pools have been inaccessible via the Raydium official UI since deactivation.
Raydium SDK and DApp also do not support operations on mainnet old version AMM V3 liquidity pools.
The five affected pools include: Sollet USDT-RAY, Sollet ETH-RAY, SRM-RAY, USDC-RAY, and RAY-SOL.
Preliminary statistics show that the stolen assets include approximately 150,177 RAY, 5,603 SOL, and 893,700 USDC, with a total value of about $1.34 million.
The related losses will be fully compensated by the treasury.
The investigation indicates that the vulnerability stemmed from insufficient validation of LP token minting addresses.
The attacker created new LP tokens and impersonated legitimate LP tokens, bypassing the protocol’s ratio verification mechanism to extract funds.
However, this incident is an isolated logical vulnerability and not due to private key leaks or permission breaches, so there is no risk of further spread.
Currently, all active Raydium mainnet programs remain unaffected.
RAY2.34%
ETH2.42%
USDC0.04%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned