Security

Raydium: $1.34M Exploit in Retired Legacy Pools — Treasury Covers Losses in Full

An attacker drained five pools of Raydium's AMM V3 program, retired in 2021, for about $1.34 million. Active programs are unaffected; Raydium covers the losses in full from its treasury.

SOLANA·HUB Editorial ·

What Happened

On June 10, 2026, an attacker drained liquidity from five legacy pools of Raydium — total damage around $1.34 million. Affected was the old AMM V3 program, which was already retired in 2021. Raydium confirmed the incident and announced it will cover the losses in full from its own treasury.

The Facts

  • Affected pools: five Serum-era pools (including Sollet-USDT-RAY, Sollet-ETH-RAY, SRM-RAY, USDC-RAY, RAY-SOL) on the retired AMM V3 program
  • Drained: roughly 150,177 RAY, 5,603 SOL, and 893,700 USDC
  • Method: the attacker exploited a validation weakness in the dormant pools, bypassing checks with a fake mint address
  • Not affected: Raydium’s current programs (AMM V4, CLMM) and thus active trading volume and TVL — the old pools had no active user participation anymore
  • Fund trail: per reports, most of the loot was bridged to Ethereum and laundered through Tornado Cash

Context

The case shows a recurring DeFi risk: retired code remains attackable onchain as long as it stays deployed and still holds residual value. On the positive side, the response follows the pattern of responsible protocols — confirmation, full protocol-level reimbursement, and an announced security review, without users bearing the loss.

Basics for protecting your own wallet: Solana wallet security. What Raydium is today: Raydium explained.

What to Watch

  • The execution of the reimbursement and the announced security review
  • Whether other legacy programs in the ecosystem carry similar residual risks

Sources

#raydium #exploit #security #defi #legacy-code