{"id":24132,"date":"2026-06-11T15:51:31","date_gmt":"2026-06-11T15:51:31","guid":{"rendered":"https:\/\/nft.runfyers.com\/index.php\/2026\/06\/11\/solana-exchange-raydium-hit-with-1-34-million-exploit-as-defi-attacks-grow-nft-plazas\/"},"modified":"2026-06-11T15:51:31","modified_gmt":"2026-06-11T15:51:31","slug":"solana-exchange-raydium-hit-with-1-34-million-exploit-as-defi-attacks-grow-nft-plazas","status":"publish","type":"post","link":"https:\/\/nft.runfyers.com\/index.php\/2026\/06\/11\/solana-exchange-raydium-hit-with-1-34-million-exploit-as-defi-attacks-grow-nft-plazas\/","title":{"rendered":"Solana Exchange Raydium Hit With $1.34 Million Exploit as DeFi Attacks Grow &#8211; NFT Plazas"},"content":{"rendered":"<p><\/p>\n<div>\n<p><span style=\"font-weight: 400;\">One of Solana\u2019s flagship decentralized exchanges became the latest victim of a crypto exploit on Wednesday, when an attacker drained more than $1.34 million from five dormant liquidity pools on Raydium, adding fresh urgency to an already bruising year for decentralized finance security.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The exploit targeted Raydium\u2019s legacy AMM V3 program and drained roughly $1.34 million from five inactive liquidity pools. The affected pools \u2014 Sollet USDT-RAY, Sollet ETH-RAY, SRM-RAY, USDC-RAY, and RAY-SOL \u2014 had been phased out following the deprecation of the Serum protocol in 2021.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The attacker bypassed validation checks in the old AMM V3 program, minted new liquidity provider tokens without depositing corresponding assets, then withdrew and converted the positions. The exploiter\u2019s Solana address ends in \u201cBq33QVk.\u201d In dollar terms, the attacker made off with nearly $900,000 in USDC, approximately $357,000 in SOL, and $86,000 worth of RAY.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The vulnerability originated from insufficient validation of the LP mint address within the Legacy AMM V3 program. Because the program failed to properly verify the LP mint, the attacker created a new mint and used it as the LP token, effectively bypassing the proportion checks that were meant to govern liquidity removal.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Raydium moved quickly to contain the fallout. Pseudonymous Raydium contributor 0xInfra confirmed the incident via X, stating that no current users were affected and could not have interacted with the deprecated pools through the platform\u2019s UI since their phase-out. The project confirmed full compensation for all affected users will be handled directly through its treasury, covering the entire $1.34 million across all five impacted pools. Raydium\u2019s core contributors also announced a comprehensive security review of all mainnet programs to verify that no similar logic flaws exist across any active code.<\/span><\/p>\n<p><noscript><\/noscript><img loading=\"lazy\" decoding=\"async\" class=\"lazyload aligncenter size-large wp-image-97811\" src=\"https:\/\/nftplazas.com\/wp-content\/uploads\/2026\/06\/2-9-4-1024x576.jpg\" alt=\"Solana Exchange Raydium Hit With $1.34 Million Exploit as DeFi Attacks Grow\" width=\"1024\" height=\"576\"\/><\/p>\n<p><noscript><img loading=\"lazy\" decoding=\"async\" class=\"size-large wp-image-97814\" src=\"https:\/\/nftplazas.com\/wp-content\/uploads\/2026\/06\/2-9-5-1024x576.jpg\" alt=\"Solana Exchange Raydium Hit With $1.34 Million Exploit as DeFi Attacks Grow\" width=\"1024\" height=\"576\"\/><\/noscript><img loading=\"lazy\" decoding=\"async\" class=\"lazyload size-large wp-image-97814\" src=\"https:\/\/nftplazas.com\/wp-content\/uploads\/2026\/06\/2-9-5-1024x576.jpg\" alt=\"Solana Exchange Raydium Hit With $1.34 Million Exploit as DeFi Attacks Grow\" width=\"1024\" height=\"576\"\/><\/p>\n<p style=\"text-align: center;\"><em>Solana Exchange Raydium Hit With $1.34 Million Exploit as DeFi Attacks Grow<\/em><\/p>\n<h2><span class=\"ez-toc-section\" id=\"A_Ghost_in_the_Machine\"\/><span style=\"font-weight: 400;\">A Ghost in the Machine<\/span><span class=\"ez-toc-section-end\"\/><\/h2>\n<p><span style=\"font-weight: 400;\">The incident raises a question that has become increasingly uncomfortable across DeFi: what happens to code that is officially retired but never fully removed from the blockchain?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The loss shows how old liquidity pools can remain financially dangerous long after a protocol\u2019s user interface, SDKs, and main product routes move elsewhere. The affected contracts still held live assets on-chain despite being phased out of Raydium\u2019s current application interface and active liquidity stack.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Because smart contracts are immutable, fully removing old code that still holds funds is never straightforward. This incident shows a real weakness in DeFi: old contracts can still become targets for attackers looking for edge cases. Raydium had transitioned to newer AMM versions, including V4 and V5, which utilize virtual supply mechanisms alongside stricter account verification protocols \u2014 but the deprecation of the legacy program did not wipe its on-chain footprint.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">After stealing the assets on Solana, the funds were bridged to Ethereum and are now being laundered via Tornado Cash, according to blockchain investigator Specter. That exit path \u2014 bridge to Ethereum, deposit into the sanctioned mixer \u2014 has become a familiar playbook for DeFi exploiters seeking to complicate recovery efforts. US authorities sanctioned Tornado Cash in 2022, and its continued use in exploit laundering gives regulators ammunition to argue for stricter oversight of DeFi protocols.<\/span><\/p>\n<p><noscript><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-97813 size-large\" src=\"https:\/\/nftplazas.com\/wp-content\/uploads\/2026\/06\/3-12-e1781193064525-1024x521.jpg\" alt=\"Raydium (RAY) Price Chart\" width=\"1024\" height=\"521\"\/><\/noscript><img loading=\"lazy\" decoding=\"async\" class=\"lazyload aligncenter wp-image-97813 size-large\" src=\"https:\/\/nftplazas.com\/wp-content\/uploads\/2026\/06\/3-12-e1781193064525-1024x521.jpg\" alt=\"Raydium (RAY) Price Chart\" width=\"1024\" height=\"521\"\/><\/p>\n<p style=\"text-align: center;\"><em>Raydium (RAY) Price Chart<\/em><\/p>\n<h2><span class=\"ez-toc-section\" id=\"A_Deteriorating_Security_Landscape\"\/><span style=\"font-weight: 400;\">A Deteriorating Security Landscape<\/span><span class=\"ez-toc-section-end\"\/><\/h2>\n<p><a href=\"https:\/\/nftevening.com\/drift-protocol-hacked-270m-solana-exploit\/\" target=\"_blank\" rel=\"noopener nofollow external noreferrer\" data-wpel-link=\"external\"><span style=\"font-weight: 400;\">The Raydium hack<\/span><\/a><span style=\"font-weight: 400;\"> arrives at a moment when DeFi\u2019s security track record is under acute scrutiny. The sector has already lost over $750 million to hacks and exploits in 2026, driven largely by the approximately $292 million <\/span><a href=\"https:\/\/nftplazas.com\/kelp-dao-bridge-exploit-292-million-layerzero\/\" target=\"_blank\" rel=\"noopener\" data-wpel-link=\"internal\"><span style=\"font-weight: 400;\">KelpDAO exploit<\/span><\/a><span style=\"font-weight: 400;\"> and the $285 million Drift Protocol breach.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Drift Protocol lost $285 million on April 1 after a North Korean hacking group spent six months socially engineering its way into the Solana-based DEX, while KelpDAO\u2019s LayerZero bridge was drained of $292 million in rsETH on April 19. Those two incidents alone caused 95% of April\u2019s total DeFi damage, triggering a mass exit from DeFi and ranking among the top ten hacks since 2021.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">What makes the current environment particularly alarming is the widening attack surface. Neither of the two biggest exploits of 2026 involved a smart contract vulnerability \u2014 code audits, formal verification, and bug bounty programs would not have prevented Drift or KelpDAO. Instead, social engineering, compromised infrastructure, and governance weaknesses have emerged as the dominant vectors.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Adding a new dimension to the threat landscape, AI is now playing a documented role in vulnerability discovery. Security researcher Taylor Hornby identified a critical four-year-old vulnerability in Zcash\u2019s Orchard shielded pool on May 29 by running a custom auditing agent framework paired with Anthropic\u2019s Claude Opus 4.8 model, then wrote a complete working exploit in a local test environment. The bug would have allowed an attacker to mint unlimited ZEC tokens inside the Orchard pool without detection, and its disclosure sent ZEC crashing more than 38% in a single day. While the <\/span><a href=\"https:\/\/nftplazas.com\/zcash-plunges-four-year-bug-unlimited-token-minting\/\" target=\"_blank\" rel=\"noopener\" data-wpel-link=\"internal\"><span style=\"font-weight: 400;\">Zcash<\/span><\/a><span style=\"font-weight: 400;\"> disclosure was a white-hat find \u2014 and there is no evidence AI tools were used in the Raydium attack \u2014 it underscores the accelerating capability of AI-assisted auditing on both sides of the security equation.<\/span><\/p>\n<h2><span class=\"ez-toc-section\" id=\"Market_Reaction_and_Outlook\"\/><span style=\"font-weight: 400;\">Market Reaction and Outlook<\/span><span class=\"ez-toc-section-end\"\/><\/h2>\n<p><span style=\"font-weight: 400;\">Market reaction to the Raydium exploit was limited. RAY fell about 2% in the 24 hours after the disclosure and roughly 13% over the prior week, with the token remaining far below its all-time high.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For the broader DeFi ecosystem, the incident carries implications beyond the dollar figure. Legacy contracts, abandoned pools, and residual permission settings represent a class of risk that traditional code audits do not systematically address. As protocols evolve and migrate to newer architectures, the operational burden of cleanly decommissioning old infrastructure \u2014 not just removing UI access, but auditing and safely winding down on-chain contracts that still hold value \u2014 has become a pressing security obligation.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The Raydium incident is a clear reminder that \u201cdeprecated\u201d does not always mean safe in the blockchain world.<\/span><\/p>\n<\/div>\n<p><a href=\"https:\/\/nftplazas.com\/raydium-exploit-solana-defi-security\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>One of Solana\u2019s flagship decentralized exchanges became the latest victim of a crypto exploit on Wednesday, when an attacker drained more than $1.34 million from five dormant liquidity pools on Raydium, adding fresh urgency to an already bruising year for decentralized finance security. The exploit targeted Raydium\u2019s legacy AMM V3 program and drained roughly $1.34 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":24133,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_publicize_message":"","jetpack_is_tweetstorm":false,"jetpack_publicize_feature_enabled":true},"categories":[16],"tags":[],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/nftplazas.com\/wp-content\/uploads\/2026\/06\/1-1-20.jpg","jetpack_sharing_enabled":true,"jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/24132"}],"collection":[{"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=24132"}],"version-history":[{"count":0,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/24132\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/24133"}],"wp:attachment":[{"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=24132"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=24132"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=24132"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}