Solana-based DEX Raydium Hacked for Nearly $4.4M due to Private Key Compromised

Solana-based DEX Raydium released an initial report about the incident it was hacked, saying the the exploit appears to stem from a trojan attack and compromised private key for the pool owner's account. The total loss is around $4.395m. Raydium has released a patch to prevent further exploits from the attacker.

According to Raydium, the attacker accessed the pool owner account and was then able to call the withdrawalPNL function, which is used to collect trading fees earned by swaps in pools. The attacker was also able to set the SyncNeedTake parameters to change the out_put.need_take_pnl for quote and base tokens in the affected pools in order to modify expected fees and then withdraw those amounts. Nine pools were affected, including SOL-USDC, SOL-USDT, RAY-USDC, and RAY-USDT, and the total loss is around $4.395m.

The previous owner authority has been revoked by Raydium, and all program accounts have been updated to new hard wallet accounts, so that the attacker no longer has access authority. Raydium said that if the attacker returns the funds, 10% of the total amount will be offered and considered as a white-hat bug bounty.

Source

DeFi

DEX

Solana

Security Incidents

In This Article

Related News
Solana's key SIMD-228 proposal fails to pass validator vote, token emissions unchanged Solana's key SIMD-228 proposal fails to pass validator vote, token emissions unchanged
Transaction fees generated on Solana network fall to lowest weekly amount since September Transaction fees generated on Solana network fall to lowest weekly amount since September
Bybit hackers move over half the stolen ETH onto Bitcoin, largely using ThorChain Bybit hackers move over half the stolen ETH onto Bitcoin, largely using ThorChain
Stablecoin neobank Infini exploited for $49 million: security analysts Stablecoin neobank Infini exploited for $49 million: security analysts
Wildcat, the decentralized credit platform built by Crypto Twitter mainstay Laurence Day, launches new version on Ethereum Wildcat, the decentralized credit platform built by Crypto Twitter mainstay Laurence Day, launches new version on Ethereum
Latest News More More
ZKsync sunsets ‘Ignite’ token rewards for DeFi ecosystem, cites market conditions and focus on Elastic Network
20 Hours Ago GnosisDAO votes to invest further $4.8 million to fund HOPR's in-house development of private, uncensorable VPN
20 Hours Ago Bankrbot ends Grok's unintentional token creation spree by disabling interactions on X
1 Day Ago Taproot Wizards to hold first public auction of 'Wizards' Bitcoin Ordinals project
1 Day Ago Paradigm leads $82 million Series B round for crypto payments network Mesh
delate
Use TokenInsight App All Crypto Insights Are In Your Hands
Open