The protocol said its closed mySwap CL interface had not accepted new liquidity for more than six months, with residual LP positions across over 100,000 positions bearing most of the losses.
Starknet automated market maker (AMM, a protocol for token trading) mySwap said its mySwap CL protocol was exploited, leading to withdrawals of about $300,000 from liquidity pools. The team said the interface had been shut for more than six months and was no longer taking new liquidity, so the losses mainly hit residual LP (liquidity provider) positions spread across more than 100,000 positions. mySwap added that the attacker used bridge-stolen funds and Railgun (a privacy tool that obscures transfers) to mask asset flows, nearly depleting all remaining liquidity. The incident points to persistent risks around dormant DeFi infrastructure, where even products no longer open to new deposits can remain exposed if liquidity is still onchain.