VIP Signals · Elixir

Smarter Trading Starts Here

Get structured trading signals, weekly test sessions, and a transparent referral-based VIP access model.

Join Telegram

Hacker Withdraws $1.3M From Old Raydium Pools

0 Reading time: 9 min. abelcopy_editor

Raydium has promised to reimburse liquidity providers after an attack on the outdated AMM V3 program. The attacker withdrew about $1.34 million from five old pools that had not been used since 2021 and were no longer accessible through the main exchange interface.

The team stated that current users and active pools were not affected. According to them, the bug was isolated in the old code and was not related to key compromise or admin rights.

Ranking
of the best traders
according to the opinion of the REAL USERS
“Trades Closed From +40% Profit”
“+1,300$/Month in Profit”
“Stable 500$–600$ Withdrawals”

A Vulnerability Was Found in the Old Program

The incident affected not the active Raydium infrastructure, but an outdated part of the protocol. It concerns the AMM V3 program, which the decentralized exchange on Solana phased out of active use several years ago.

A team member under the nickname Infra stated that the cause was a separate logical error. It does not affect other programs and does not create risk for current pools.

This is an important distinction from attacks via stolen private keys. In this case, the attacker did not use admin access but exploited a weakness in the old smart contract mechanics. This scenario shows that even inactive code can remain dangerous if it still holds funds.

Fake LP Tokens Gave Access to Liquidity

According to security researcher Param, the attacker found five abandoned pools where assets remained. Then, they created fake proofs of ownership in the pool.

The old program accepted these fake LP tokens as real liquidity provider rights. After that, the contract allowed the attacker to withdraw assets as if they truly owned a share of the pool.

The company F12 also tracked the attack on-chain. According to them, the exploit used a fabricated LP token with an offer of just one unit. When a withdrawal request was sent, the old contract released the entire pool balance.

Funds Withdrawn Through Cross-Chain Route

After the attack, the stolen assets quickly started leaving Solana. According to on-chain analysts, the original wallet was funded via KuCoin, and then the funds were transferred to Ethereum via deBridge.

On the Ethereum side, the attacker received about 810 ETH. Most of this amount was sent to Tornado Cash to make further tracking more difficult. A small portion, about 7 ETH, went through FixedFloat.

Publishing the attacker’s address should help exchanges and analytics services monitor further movement of the funds. The faster such addresses are added to monitoring lists, the harder it is to withdraw assets through centralized platforms.

Losses Will Be Covered From the Treasury

The team stated that it will fully compensate liquidity providers for their losses. The funds for payouts will come from the project’s treasury.

It has not yet been disclosed when exactly the payouts will begin or how the process will be organized. There is also no detailed breakdown for each of the five affected pools.

For users, the fact of compensation is not the only important thing. The market will expect a clear report: which funds were withdrawn, which addresses were affected, and why liquidity still remained in the outdated program.

Active Pools Continue to Operate

Raydium remains one of the major DeFi protocols in the Solana ecosystem. According to DefiLlama, the project’s total value locked is about $796.6 million, and trading volume over the past seven days exceeded $1.1 billion.

The team emphasizes that the exploit did not affect active programs. According to them, current pools and users were not put at risk by this particular bug.

Nevertheless, the incident is important for the entire industry. Protocols often develop over years, change contract versions, and leave old components on the network. If assets remain in such components, they can become an easy target for attackers.

This Is Not Raydium’s First Incident

The project has already faced security problems. In December 2022, the protocol lost $4.4 million after a private key compromise.

The new attack was structured differently. Then, the risk was related to key access; now, it is due to the logic of the old contract. But for users, the result is similar: funds were withdrawn, and the team is forced to compensate losses and conduct an audit.

After the recent exploit, the core developers began reviewing all mainnet programs. This is the right step, because vulnerabilities in outdated contracts often go unnoticed precisely because the team no longer considers them an active part of the product.

Old Contracts Have Become a Separate Risk

Raydium emphasizes that current pools and users were not affected. But the incident highlighted another problem: smart contracts do not disappear from the network after the project stops displaying them in the interface.

If assets remain in such code, it continues to be a target for attackers. At the same time, old programs often receive less attention because the team has long considered them inactive.

That is why reviewing mainnet programs became a mandatory step after the attack. The market needs to be sure that other outdated infrastructure elements do not contain similar bugs and leftover funds.

Hacks Are Hitting Old Code Again

The incident fits into the overall picture of 2026. According to CertiK, there were 60 attacks and security incidents confirmed in May, with total losses of $68.3 million. This is the highest monthly figure for the number of episodes this year.

Code errors are especially notable. They accounted for more than $45 million of May’s losses. Recent attacks on Gnosis Pay and TesseraDAO, as well as the transfer of the Flooring Protocol vulnerability to its fork Asterisk, show the same problem: if code is reused or not checked for a long time, the risk spreads quickly.

According to PeckShield, by the end of May, losses from crypto exploits in 2026 approached $1.3 billion. Of this amount, about $340.7 million came from bridge-related attacks. Against this backdrop, the Raydium case looks smaller in size but clearly shows the market’s weak spot: forgotten contracts and cross-chain routes remain an easy target.

What Happens Next?

Raydium needs to complete its program review and publish a clear compensation procedure. Users need to see not only the promise of payouts but also an explanation of why the vulnerable program had been holding funds since 2021.

If payouts are made quickly and the audit does not reveal new problems, reputational damage may remain limited. If the review finds other forgotten contracts with liquidity, the market will have to wait for additional measures.

The main takeaway is simple. The attack did not affect Raydium’s current pools but highlighted the risk of old infrastructure. Even if a contract has long been removed from the interface, it continues to operate on the network and can become a hacker’s target.

Read More: CFTC Commission Takes First Steps Toward Prediction Market Oversight

Top Verified Traders 🔥
Discover Our Best Trader Picks
elixir telegram review 1
falconai private club 2
Comments (0)

News about digital currencies, fintech trends and financial innovations

CoinSpot.io - the largest Runet resource about digital currencies, fintech trends and financial innovations. We talk about technologies, startups and entrepreneurs shaping the face of the financial world. Venture investments, p2p and digital technologies, cryptocurrencies, analytics and reviews - everything you need to know to stay in trend and earn.

Full or partial use of site materials is allowed only with the written permission of the editorial office, and a link to the source is mandatory!

Subscribe to email updates about new articles and important news from Coinspot.io