Raydium Confirms $1.34 Million Exploit in Retired AMM Program, Says Live Systems Are Safe

Raydium Confirms $1.34 Million Exploit in Retired AMM Program, Says Live Systems Are Safe

N
News Editor 01
2026-07-22 14:15:13
Raydium said a retired Legacy AMM V3 program was exploited for about $1.34 million across five old liquidity pools. The team said losses will be covered by treasury funds and that the current app, SDK, and mainnet programs were not affected.
RaydiumSolanaDeFiexploitonchain-security

Raydium has confirmed that its retired Legacy AMM V3 program was exploited, with about $1.34 million drained from five old liquidity pools. The Solana-based decentralized exchange said the affected code had been retired from its app since 2021, and that its current app, SDK, and mainnet programs were not compromised. The protocol added that all losses will be covered from its treasury.

The flaw came from LP mint verification in old code

According to the disclosed details, the attacker abused a weakness in how the legacy program checked liquidity token mint addresses, or LP Token Mint addresses. The old program did not validate those addresses correctly. By creating a fake mint address, the attacker was able to bypass internal safety checks and drain funds within minutes.

Raydium said its active programs use a virtual supply method for proportion checks and also verify the LP mint correctly. The retired code lacked that protection. The issue was not tied to the live user-facing product; it was tied to an old contract that still held funds onchain.

Five legacy pools were hit, then funds were bridged to Ethereum

The affected pools were RAY-SOL, USDC-RAY, SRM-RAY, Sollet ETH-RAY, and Sollet USDT-RAY. The stolen assets included about 150,177 RAY, 5,603 SOL, and 893,700 USDC.

Blockchain security firms PeckShield and Specter were the first to flag the attack. PeckShield said the attacker later bridged the assets to Ethereum, with 810 ETH traced into Tornado Cash and another 7 ETH sent to FixedFloat. Once funds moved through those channels, the prospect of recovery became much harder.

Raydium says users will not absorb the loss

Raydium said every dollar lost in the incident will be covered by its treasury, leaving users without direct losses from the exploit. The team also stressed that this was not a breach of its live systems. The flaw existed only in the retired Legacy AMM V3 codebase.

The protocol said it is now reviewing all mainnet programs for similar issues. The episode also highlights a long-running DeFi risk: retiring a contract from the interface does not remove it from the chain. If funds remain in old pools, any weakness in that legacy code can still be exploited.

RAY showed limited price impact after the disclosure

Market reaction was relatively muted. According to the source material, RAY fell less than 1% after the news, then added 0.55% and traded near $0.5718. Its 24-hour trading volume rose 67% to $22 million, while market capitalization stood at about $153.82 million and TVL held near $770 million.

Based on the disclosed facts, the damage was confined to inactive pools tied to retired code. The incident did not reach Raydium’s current production systems, but it did expose the risk of leaving value inside old smart contracts long after a program is no longer in use.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.