Raydium has confirmed that its retired Legacy AMM V3 program was exploited, with about $1.34 million drained from five old liquidity pools. The Solana-based decentralized exchange said the affected code had been retired from its app since 2021, and that its current app, SDK, and mainnet programs were not compromised. The protocol added that all losses will be covered from its treasury.
The flaw came from LP mint verification in old code
According to the disclosed details, the attacker abused a weakness in how the legacy program checked liquidity token mint addresses, or LP Token Mint addresses. The old program did not validate those addresses correctly. By creating a fake mint address, the attacker was able to bypass internal safety checks and drain funds within minutes.
Raydium said its active programs use a virtual supply method for proportion checks and also verify the LP mint correctly. The retired code lacked that protection. The issue was not tied to the live user-facing product; it was tied to an old contract that still held funds onchain.
Five legacy pools were hit, then funds were bridged to Ethereum
The affected pools were RAY-SOL, USDC-RAY, SRM-RAY, Sollet ETH-RAY, and Sollet USDT-RAY. The stolen assets included about 150,177 RAY, 5,603 SOL, and 893,700 USDC.
Blockchain security firms PeckShield and Specter were the first to flag the attack. PeckShield said the attacker later bridged the assets to Ethereum, with 810 ETH traced into Tornado Cash and another 7 ETH sent to FixedFloat. Once funds moved through those channels, the prospect of recovery became much harder.
Raydium says users will not absorb the loss
Raydium said every dollar lost in the incident will be covered by its treasury, leaving users without direct losses from the exploit. The team also stressed that this was not a breach of its live systems. The flaw existed only in the retired Legacy AMM V3 codebase.
The protocol said it is now reviewing all mainnet programs for similar issues. The episode also highlights a long-running DeFi risk: retiring a contract from the interface does not remove it from the chain. If funds remain in old pools, any weakness in that legacy code can still be exploited.
RAY showed limited price impact after the disclosure
Market reaction was relatively muted. According to the source material, RAY fell less than 1% after the news, then added 0.55% and traded near $0.5718. Its 24-hour trading volume rose 67% to $22 million, while market capitalization stood at about $153.82 million and TVL held near $770 million.
Based on the disclosed facts, the damage was confined to inactive pools tied to retired code. The incident did not reach Raydium’s current production systems, but it did expose the risk of leaving value inside old smart contracts long after a program is no longer in use.

