Solana-based DEX Raydium Hacked for Nearly $4.4M due to Private Key Compromised

Solana-based DEX Raydium released an initial report about the incident it was hacked, saying the the exploit appears to stem from a trojan attack and compromised private key for the pool owner's account. The total loss is around $4.395m. Raydium has released a patch to prevent further exploits from the attacker.

According to Raydium, the attacker accessed the pool owner account and was then able to call the withdrawalPNL function, which is used to collect trading fees earned by swaps in pools. The attacker was also able to set the SyncNeedTake parameters to change the out_put.need_take_pnl for quote and base tokens in the affected pools in order to modify expected fees and then withdraw those amounts. Nine pools were affected, including SOL-USDC, SOL-USDT, RAY-USDC, and RAY-USDT, and the total loss is around $4.395m.

The previous owner authority has been revoked by Raydium, and all program accounts have been updated to new hard wallet accounts, so that the attacker no longer has access authority. Raydium said that if the attacker returns the funds, 10% of the total amount will be offered and considered as a white-hat bug bounty.

Source

DeFi

DEX

Solana

Security Incidents

In This Article

Related News
Hyperliquid hits record $248 billion perp volume in May, capturing over 10% of Binance flow Hyperliquid hits record $248 billion perp volume in May, capturing over 10% of Binance flow
Sui DEX Cetus Protocol restarts platform after recovering from $223 million exploit Sui DEX Cetus Protocol restarts platform after recovering from $223 million exploit
Sui DEX Cetus says overlooked flaw in open-source library used by smart contract led to $223 million exploit Sui DEX Cetus says overlooked flaw in open-source library used by smart contract led to $223 million exploit
Solana validators patch zero-day bug that could have led to unlimited minting of certain tokens Solana validators patch zero-day bug that could have led to unlimited minting of certain tokens
Term Finance recovers $1 million of $1.6 million loss to oracle configuration error Term Finance recovers $1 million of $1.6 million loss to oracle configuration error
Latest News More More
3 Hours Ago Ethereum community plans onchain ‘time capsule’ to mark 10th anniversary of network’s genesis block
5 Days Ago Circle's post-IPO stock surge pushes market cap near Coinbase and USDC
June 20 Kraken offers bitcoin ‘staking’ yield via Babylon without wrapping or lending
June 17 Trump makes over $57 million from WLFI sales, Truth Social files for Bitcoin and Ethereum combo ETF, and more
June 13 XRP Ledger adopts USDC one week after Circle goes public
delate
Use TokenInsight App All Crypto Insights Are In Your Hands
Open