Raydium, a decentralized exchange on Solana, has confirmed a security exploit that drained approximately $1.3 million from five inactive liquidity pools. The protocol announced it will fully compensate affected users using treasury funds, ensuring no user bears the loss.
Exploit Details: Outdated Code Vulnerability
According to blockchain security firm PeckShield and on-chain investigator Specter, the attacker exploited a validation weakness in Raydium's deprecated automated market maker (AMM) infrastructure. By using a fake mint address, the attacker bypassed checks and withdrew assets from legacy pools. Stolen tokens include approximately 150,177 RAY, 5,603 SOL, and 893,700 USDC. Raydium emphasized that active pools and current users are not impacted, as the exploit only affected retired contracts.
Fund Flow and Tracing
Specter reported that the attacker initially received funding via KuCoin before moving stolen assets across chains to Ethereum. PeckShield's tracking data shows about 810 ETH was deposited into Tornado Cash, a privacy mixer, while another 7 ETH was transferred to FixedFloat. The use of Tornado Cash may complicate recovery efforts, although the mixer was removed from the U.S. Treasury's sanctions list in March 2025. Investigations are ongoing.
Compensation Promise and Market Reaction
This is not Raydium's first security incident. In December 2022, an admin key compromise led to losses from active pools, which were later reimbursed via buyback fees and vested tokens. This time, the team again commits to making users whole from treasury funds. Market response has been muted: RAY is trading near $0.57, down less than 1% in 24 hours, while SOL slipped nearly 2% to around $63.88. The incident highlights risks from legacy code in DeFi; similar exploits have hit other protocols like Token of Power recently. Raydium's swift compensation move may help maintain user confidence.

