T
iTokenly

Raydium hack — December 2022

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedDecember 16, 2022
Target typeDecentralised exchange
Loss$4,400,000Published estimates range $4,400,000 to $5,500,000Price at time of incident
MethodPrivate key compromiseCompromise of the account holding the pool-owner (admin) authority over Raydium's constant-product AMM pools on Solana. The attacker abused SetParams and SyncNeedTake to inflate the need_take_pc and need_take_coin fee counters without any trading volume, then repeatedly called the withdrawPNL instruction — normally used to sweep protocol fees for RAY buybacks — to withdraw the inflated 'fees' from eight pools. Raydium said there was no evidence the key had ever left the virtual machine holding it and raised a trojan on that machine as one possibility; the intrusion vector was never established.
ChainsSolana
OutcomeUsers reimbursed

What happened

On 16 December 2022 at 10:12 UTC an attacker gained control of the account holding the pool-owner authority over Raydium's constant-product liquidity pools on Solana. Raydium's post-mortem said there was no evidence the private key had ever been passed, shared, transferred or stored outside the virtual machine that held it, and offered a trojan on that machine as one possibility. The intrusion vector was never established.

With the authority key the attacker did not simply move pool balances. Raydium's withdrawPNL instruction exists to collect accrued protocol fees for RAY buybacks, and the amount it releases is governed by the need_take_pc and need_take_coin parameters. The attacker used SetParams and SyncNeedTake to inflate those two values without any trading having occurred, then called withdrawPNL repeatedly, draining eight pools of what the program believed were fees owed to the protocol.

Raydium's own accounting put the loss at approximately $4.4 million, the figure The Block used. CertiK's analysis put it higher, at about $5.5 million, and traced roughly $2 million bridged to Ethereum and routed through Tornado Cash. Raydium offered a 10% bounty plus the exploited RAY balance for the return of the assets; it was not taken up.

Raydium compensated liquidity providers from its treasury and from vested team token reserves. Providers in RAY pairs could claim 100% of principal lost; providers in the other affected pairs, including SOL-USDC, SOL-USDT, stSOL-USDC and whETH-USDC, could claim 90% in kind, with the remaining 10% paid in RAY at a 1.2x rate. Claims opened 5 January 2023 and closed 14 May 2023.

Sources

  1. RaydiumPrimary · retrieved 2026-08-01
  2. RaydiumPrimary · retrieved 2026-08-01
  3. The BlockSecondary · retrieved 2026-08-01
  4. CertiKSecondary · retrieved 2026-08-01

Official post-mortem: https://raydium.medium.com/detailed-post-mortem-and-next-steps-d6d6dd461c3e

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Raydium hack — December 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/raydium
https://itokenly.com/hacks/raydium

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.