logo

Raydium Protocol Exploit Incident Analysis

ID: 45360fcc-d38d-5aae-bf53-0ccf5dffe8b6

STIX ID: report--45360fcc-d38d-5aae-bf53-0ccf5dffe8b6

Feed Name: CertiK Blog

Threat Score
72/100

Date Published: 2023-01-19

Date Updated: 2026-06-11

...
...

On 16 December 2022 Raydium, a Solana-based AMM, suffered a private-key compromise caused by a trojan that exposed an owner (privileged) wallet; the attacker used the compromised signer to invoke withdraw_pnl() and drain multiple liquidity pools, stealing approximately $5.5M (including ~$1.6M SOL) and bridging funds to Ethereum and Tornado Cash. The report documents exploit transactions and attacker addresses, describes the broader context of private-key compromises on Solana, and outlines Raydium's immediate mitigation and recovery actions (contract upgrades, bounty offer, DAO compensation proposal).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.