Raydium, the largest decentralized exchange on Solana, suffered an exploit targeting its deprecated AMM V3, resulting in the loss of approximately $1.34 million in liquidity across five pools. Core contributor InfraRAY confirmed that the affected pools had been inactive since 2021 and that no new price discovery had occurred on them. The attack did not spread to the live protocol.
How the Attack Worked: Fake LP Tokens
The five compromised pools were Sollet USDT-RAY, Sollet ETH-RAY, SRM-RAY, USDC-RAY, and RAY-SOL. The attacker exploited a logic flaw in the old contract: the AMM V3 did not properly verify the minting address of LP tokens. By creating a new set of LP tokens and passing them off as legitimate ones, the attacker bypassed the protocol's ratio-checking mechanism and drained assets. Stolen assets include 150,177 RAY, 5,603 SOL, and 893,700 USDC.
Root Cause: Insufficient LP Token Address Check
Investigators traced the vulnerability to a missing validation of the LP token's mint authority. InfraRAY stated this was an isolated logic bug, not a private key leak or permission breach, and there is no risk of contagion. All current Raydium mainnet programs remain unaffected.
Raydium's Role in Solana DeFi
Raydium is Solana's leading AMM protocol, having surpassed Uniswap in monthly trading volume for two consecutive months in 2024. While the exploit targeted a depreciated contract from 2021, it underscores that even well-maintained protocols can have legacy code vulnerabilities that on-chain sleuths may uncover. On June 10, on-chain investigator Specter issued the first warning; within 12 hours, Raydium's core team confirmed the incident.

