Starknet AMM project mySwap issued a security update stating that its CL protocol was exploited at 7:15am UTC today. According to the update, the incident resulted in approximately $300,000 being drained from liquidity pools. The statement was posted by the official mySwap - Starknet AMM account, @mySwapxyz, and the post timestamp shown in the source was 12:05 on June 19, 2026. The post page also displayed 7542 Views and a “Read 3 replies” prompt.
About $300,000 Drained From Liquidity Pools
In its update, mySwap described the incident as an exploit of the mySwap CL protocol. The project said the exploit resulted in “~$300K” being drained from liquidity pools, and added that the attack had drained nearly all remaining liquidity from the protocol. The scope of the statement was limited to the mySwap CL protocol and its liquidity pools, with no additional categories of affected systems named in the post.
The timeline in the official update is direct: the exploit took place at 7:15am UTC, and the public statement was posted later at 12:05. The key confirmed details are the affected protocol, the approximate value removed from the pools, and the fact that nearly all remaining protocol liquidity was drained. The post did not provide additional technical details about the exploit mechanism.
Interface Had Been Closed to New Liquidity for More Than Six Months
mySwap also stated that its interface had been closed to new liquidity for the past 6+ months. This was part of the team’s explanation of the state of the protocol before the exploit. The remaining balances, according to mySwap, were mostly residual LP positions rather than newly supplied liquidity through the interface.
The team said those residual LP positions were spread across over 100K positions. That figure was used in the official post to describe how the remaining balances were distributed. At the same time, mySwap said the exploit drained nearly all remaining liquidity from the protocol, indicating that the incident affected the liquidity still left in the CL protocol despite the interface being closed to new liquidity for more than half a year.
Attacker Bridged Funds and Used Railgun
On the movement of funds, mySwap said the attacker had bridged the stolen funds and used Railgun to obfuscate the flow of assets. The statement identifies two actions after the exploit: the stolen funds were moved through a bridge, and Railgun was used in an attempt to obscure the asset flow.
The official update did not include more information on addresses, transaction hashes, asset types, recovery steps, or further handling measures. Based on the post, the confirmed post-exploit fund movement is limited to the attacker bridging the stolen funds and using Railgun to obfuscate their flow. The source material does not add a separate explanation of how the exploit was executed.
Key Points From the Official Update
The confirmed facts from the mySwap update are as follows: the exploit occurred at 7:15am UTC; the affected target was the mySwap CL protocol on Starknet; approximately $300,000 was drained from liquidity pools; the interface had been closed to new liquidity for more than 6 months; remaining balances were mostly residual LP positions spread across more than 100,000 positions; nearly all remaining protocol liquidity was drained; and the attacker bridged the stolen funds and used Railgun to obfuscate the flow of assets.
Foresight categorized the item under market analysis, with the source being the official mySwap post on X. The post functions as a security update from the project team, focusing on the exploit result, the pre-existing state of protocol liquidity, and the movement of stolen funds after the attack. No further official details were included in the provided source beyond these points.

