Raydium has promised to reimburse liquidity providers after an attack on the outdated AMM V3 program. The attacker withdrew about $1.34 million from five old pools that had not been used since 2021 and were no longer accessible through the main exchange interface.
The team stated that current users and active pools were not affected. According to them, the bug was isolated in the old code and was not related to key compromise or admin rights.
A Vulnerability Was Found in the Old Program
The incident affected not the active Raydium infrastructure, but an outdated part of the protocol. It concerns the AMM V3 program, which the decentralized exchange on Solana phased out of active use several years ago.
A team member under the nickname Infra stated that the cause was a separate logical error. It does not affect other programs and does not create risk for current pools.
This is an important distinction from attacks via stolen private keys. In this case, the attacker did not use admin access but exploited a weakness in the old smart contract mechanics. This scenario shows that even inactive code can remain dangerous if it still holds funds.
Fake LP Tokens Gave Access to Liquidity
According to security researcher Param, the attacker found five abandoned pools where assets remained. Then, they created fake proofs of ownership in the pool.
The old program accepted these fake LP tokens as real liquidity provider rights. After that, the contract allowed the attacker to withdraw assets as if they truly owned a share of the pool.
The company F12 also tracked the attack on-chain. According to them, the exploit used a fabricated LP token with an offer of just one unit. When a withdrawal request was sent, the old contract released the entire pool balance.
Funds Withdrawn Through Cross-Chain Route
After the attack, the stolen assets quickly started leaving Solana. According to on-chain analysts, the original wallet was funded via KuCoin, and then the funds were transferred to Ethereum via deBridge.
On the Ethereum side, the attacker received about 810 ETH. Most of this amount was sent to Tornado Cash to make further tracking more difficult. A small portion, about 7 ETH, went through FixedFloat.
Publishing the attacker’s address should help exchanges and analytics services monitor further movement of the funds. The faster such addresses are added to monitoring lists, the harder it is to withdraw assets through centralized platforms.
Losses Will Be Covered From the Treasury
The team stated that it will fully compensate liquidity providers for their losses. The funds for payouts will come from the project’s treasury.
It has not yet been disclosed when exactly the payouts will begin or how the process will be organized. There is also no detailed breakdown for each of the five affected pools.
For users, the fact of compensation is not the only important thing. The market will expect a clear report: which funds were withdrawn, which addresses were affected, and why liquidity still remained in the outdated program.
Active Pools Continue to Operate
Raydium remains one of the major DeFi protocols in the Solana ecosystem. According to DefiLlama, the project’s total value locked is about $796.6 million, and trading volume over the past seven days exceeded $1.1 billion.
The team emphasizes that the exploit did not affect active programs. According to them, current pools and users were not put at risk by this particular bug.
Nevertheless, the incident is important for the entire industry. Protocols often develop over years, change contract versions, and leave old components on the network. If assets remain in such components, they can become an easy target for attackers.
This Is Not Raydium’s First Incident
The project has already faced security problems. In December 2022, the protocol lost $4.4 million after a private key compromise.
The new attack was structured differently. Then, the risk was related to key access; now, it is due to the logic of the old contract. But for users, the result is similar: funds were withdrawn, and the team is forced to compensate losses and conduct an audit.
After the recent exploit, the core developers began reviewing all mainnet programs. This is the right step, because vulnerabilities in outdated contracts often go unnoticed precisely because the team no longer considers them an active part of the product.
Old Contracts Have Become a Separate Risk
Raydium emphasizes that current pools and users were not affected. But the incident highlighted another problem: smart contracts do not disappear from the network after the project stops displaying them in the interface.
If assets remain in such code, it continues to be a target for attackers. At the same time, old programs often receive less attention because the team has long considered them inactive.
That is why reviewing mainnet programs became a mandatory step after the attack. The market needs to be sure that other outdated infrastructure elements do not contain similar bugs and leftover funds.
Hacks Are Hitting Old Code Again
The incident fits into the overall picture of 2026. According to CertiK, there were 60 attacks and security incidents confirmed in May, with total losses of $68.3 million. This is the highest monthly figure for the number of episodes this year.
Code errors are especially notable. They accounted for more than $45 million of May’s losses. Recent attacks on Gnosis Pay and TesseraDAO, as well as the transfer of the Flooring Protocol vulnerability to its fork Asterisk, show the same problem: if code is reused or not checked for a long time, the risk spreads quickly.
According to PeckShield, by the end of May, losses from crypto exploits in 2026 approached $1.3 billion. Of this amount, about $340.7 million came from bridge-related attacks. Against this backdrop, the Raydium case looks smaller in size but clearly shows the market’s weak spot: forgotten contracts and cross-chain routes remain an easy target.
What Happens Next?
Raydium needs to complete its program review and publish a clear compensation procedure. Users need to see not only the promise of payouts but also an explanation of why the vulnerable program had been holding funds since 2021.
If payouts are made quickly and the audit does not reveal new problems, reputational damage may remain limited. If the review finds other forgotten contracts with liquidity, the market will have to wait for additional measures.
The main takeaway is simple. The attack did not affect Raydium’s current pools but highlighted the risk of old infrastructure. Even if a contract has long been removed from the interface, it continues to operate on the network and can become a hacker’s target.
Read More: CFTC Commission Takes First Steps Toward Prediction Market Oversight