Raydium Protocol Exploit Incident Analysis
ID: 45360fcc-d38d-5aae-bf53-0ccf5dffe8b6
STIX ID: report--45360fcc-d38d-5aae-bf53-0ccf5dffe8b6
Feed Name: CertiK Blog
On 16 December 2022 Raydium, a Solana-based AMM, suffered a private-key compromise caused by a trojan that exposed an owner (privileged) wallet; the attacker used the compromised signer to invoke withdraw_pnl() and drain multiple liquidity pools, stealing approximately $5.5M (including ~$1.6M SOL) and bridging funds to Ethereum and Tornado Cash. The report documents exploit transactions and attacker addresses, describes the broader context of private-key compromises on Solana, and outlines Raydium's immediate mitigation and recovery actions (contract upgrades, bounty offer, DAO compensation proposal).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
