Raydium hack — June 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | June 10, 2026 |
| Target type | Decentralised exchange |
| Loss | $1,340,000Price at time of incident |
| Method | Contract logic errorThe remove-liquidity instruction in Raydium's deprecated legacy AMM V3 program did not verify that the LP token account presented belonged to the pool's canonical LP mint. The attacker created a fresh attacker-controlled SPL mint with zero decimals and minted exactly one token, then passed it in as the LP token. The proportional-withdrawal calculation used that attacker-controlled supply of one as its denominator, releasing full vault balances in exchange for burning a single worthless token. |
| Chains | Solana |
| Outcome | Users reimbursed |
What happened
On 10 June 2026 an attacker drained five long-deprecated Raydium liquidity pools on Solana, taking about $1.34 million. Raydium put the losses at 893,700 USDC, 5,603 SOL and 150,177 RAY, from the Sollet USDT-RAY, Sollet ETH-RAY, SRM-RAY, USDC-RAY and RAY-SOL pools, all running on the legacy AMM V3 program that Raydium phased out in 2021.
The remove-liquidity instruction in that program never verified that the LP token account passed in belonged to the pool's canonical LP mint. Raydium described it as the program not properly verifying the LP mint address, letting an attacker create a new mint and use it as the LP token. DARKNAVY's reconstruction adds detail: the attacker created a fresh SPL mint with zero decimals and a supply of one, so the proportional-withdrawal check used that supply as its denominator and released full vault balances against a single worthless token. It counts 17 successful transactions between 12:09:21 and 12:22:04 UTC, about 13 minutes, with later attempts failing as the pools ran dry.
Raydium said no current users were affected and that the pools had not been reachable through its interface since deprecation. It committed to reimbursing the drained funds from its treasury, and said current programs use a virtual supply mechanism for proportion checks and correctly verify the LP mint, so they are not vulnerable to the same substitution.
The crypto investigator Specter reported the proceeds were bridged from Solana to Ethereum and laundered through Tornado Cash; DARKNAVY attributes the same tracing to PeckShield and specifies 810 ETH sent to Tornado Cash and 7 ETH to FixedFloat. The $1.34 million figure is Raydium's own accounting; several outlets round it to $1.3 million.
Sources
- The Crypto Times (carrying Raydium's official statement)Secondary · retrieved 2026-08-01
- ProtosSecondary · retrieved 2026-08-01
- DARKNAVYSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Raydium hack — June 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/raydium-2026https://itokenly.com/hacks/raydium-2026Permalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.