
Raydium said five legacy Solana liquidity pools in its deprecated 2021 AMM V3 program were exploited through a logic flaw, and that its treasury will fully reimburse losses while current users and active programs were unaffected.
Raydium said an unauthorized liquidity removal attack hit five pools in its deprecated 2021 legacy AMM V3 program on Solana, draining about $1.34 million from pools that had been inaccessible through the platform’s interface for years. The Solana-based decentralized exchange said current users and active programs were unaffected and that its treasury will fully compensate losses. Raydium core contributor InfraRAY said the exploit stemmed from insufficient LP token mint address validation rather than a private key compromise, with the issue confined to the discontinued program. Preliminary losses were about 150,177 RAY, 5,603 SOL and 893,700 USDC across the Sollet USDT-RAY, Sollet ETH-RAY, SRM-RAY, USDC-RAY and RAY-SOL pools. Security researcher Param and blockchain security firm F12 said the attacker exploited old code by fabricating LP tokens that made the legacy smart contract treat the attacker as a valid liquidity provider, allowing the full withdrawal of pool assets. PeckShieldAlert said the attacker’s wallet was initially funded through KuCoin, that the stolen Solana-based assets were bridged to Ethereum via deBridge into roughly 810 ETH, and that most of the funds were deposited into Tornado Cash, with 7 ETH moved through FixedFloat. Raydium identified the exploiter address as 4WnPebowR4HHfumvNPaDjG6Pa5Hi1jxLm6xmmBq33QVk and said core contributors are reviewing all mainnet programs.