Solana-based DEX Raydium Hacked for Nearly $4.4M due to Private Key Compromised

Solana-based DEX Raydium released an initial report about the incident it was hacked, saying the the exploit appears to stem from a trojan attack and compromised private key for the pool owner's account. The total loss is around $4.395m. Raydium has released a patch to prevent further exploits from the attacker.

According to Raydium, the attacker accessed the pool owner account and was then able to call the withdrawalPNL function, which is used to collect trading fees earned by swaps in pools. The attacker was also able to set the SyncNeedTake parameters to change the out_put.need_take_pnl for quote and base tokens in the affected pools in order to modify expected fees and then withdraw those amounts. Nine pools were affected, including SOL-USDC, SOL-USDT, RAY-USDC, and RAY-USDT, and the total loss is around $4.395m.

The previous owner authority has been revoked by Raydium, and all program accounts have been updated to new hard wallet accounts, so that the attacker no longer has access authority. Raydium said that if the attacker returns the funds, 10% of the total amount will be offered and considered as a white-hat bug bounty.

Source

DeFi

DEX

Solana

Security Incidents

In This Article

Related News
Canada to launch spot Solana ETFs this week: report Canada to launch spot Solana ETFs this week: report
Pump.fun launches DEX called PumpSwap to instantly migrate graduated token Pump.fun launches DEX called PumpSwap to instantly migrate graduated token
OKX suspends DEX aggregator following Lazarus 'misuse' and heightened EU scrutiny OKX suspends DEX aggregator following Lazarus 'misuse' and heightened EU scrutiny
Solana's key SIMD-228 proposal fails to pass validator vote, token emissions unchanged Solana's key SIMD-228 proposal fails to pass validator vote, token emissions unchanged
Transaction fees generated on Solana network fall to lowest weekly amount since September Transaction fees generated on Solana network fall to lowest weekly amount since September
Latest News More More
13 Hours Ago Kraken launches forex perpetual futures with up to 20x leverage
13 Hours Ago Bybit CEO says nearly 28% of $1.4 billion hacked crypto 'gone dark,' moved to P2P and OTC
3 Days Ago Eliza Labs unveils auto.fun, a no-code AI agent launchpad with 'fairer than fair' token model
3 Days Ago Non-KYC exchange eXch to close down under money laundering scrutiny tied to Lazarus Group
4 Days Ago Base scrutinized over promotion of token that briefly crashed 95%; says part of 'contentcoin' vision
delate
Use TokenInsight App All Crypto Insights Are In Your Hands
Open