Solana-based exchange Raydium suffers $4.4 million exploit

Quick Take

  • Solana-based decentralized exchange Raydium reported an exploit. 
  • The team estimated that assets worth $4.4 million were stolen.

Update: In a latest post-mortem report, the Raydium team noted that $4.4 million in crypto assets were taken during the exploit.

Raydium, a decentralized exchange built on the Solana blockchain, was hacked.

The attacker was able to able to withdraw liquidity pool (LP) tokens into their control. Raydium acknowledged the incident and said it believed that an attacker took control over the exchange's admin address.

In a post-mortem report, the team estimated that crypto assets worth $4.4 million were stolen during the incident. "The attacker compromised eight constant product liquidity pools on Raydium, totaling approximately ~4.4m USD in funds stolen," it wrote. 

Security firm Otter offered an analysis of the event and said a compromised private key may have been responsible for the exploit.

THE SCOOP

Keep up with the latest news, trends, charts and views on crypto and DeFi with a new biweekly newsletter from The Block's Frank Chaparro

By signing-up you agree to our Terms of Service and Privacy Policy
By signing-up you agree to our Terms of Service and Privacy Policy

Meanwhile, Raydium said it was still investigating the matter to determine the nature and root cause of the compromise. It postulated the attacker may have targeted an internal server with "trojan" malware in order to compromise Raydium's underlying code. 

"Initial suspicions are that the attacker may have gained remote access to the virtual machine or internal server where the account was deployed. The exact intrusion vector has yet to be identified, but a trojan attack may be one possibility," the team said. Raydium is offering the hacker a 10% bounty in exchange for returning funds.

Raydium still holds more than $30 million in crypto assets, according to data from DeFiLlama.

The article was updated with the final estimate of the total value of assets stolen during the exploit.


© 2023 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

About Author

Vishal Chawla is The Block’s crypto ecosystems editor and has spent over six years covering tech protocols, cybersecurity, artificial intelligence and cloud computing. Vishal likes to delve deep into blockchain intricacies to ensure readers are well-informed about the continuously evolving crypto landscape. He is also a staunch advocate for rigorous security practices in the space. Before joining The Block, Vishal held positions at IDG ComputerWorld, CIO, and Crypto Briefing. He can be reached on Twitter at @vishal4c and via email at [email protected]

Editor

To contact the editor of this story:
Tim Copeland at
[email protected]