Raydium's Legacy AMM V3 Exploited for $1.34M via LP Mint Flaw
A hacker exploited a validation flaw in Raydium's legacy AMM V3 program on 10 June 2026, draining approximately $1.34 million from five deprecated Solana liquidity pools. Raydium confirmed its treasury will cover all losses and that no active users or current programs were affected.

Raydium's deprecated AMM V3 pools were drained for 1.34 million dollars
A hacker exploited a validation flaw in Raydium's legacy AMM V3 program on 10 June 2026, draining approximately $1.34 million from five deprecated Solana liquidity pools. The program had been retired from Raydium's user interface since 2021 following the shutdown of the Serum order book it was built for, but the smart contracts remained active on-chain with real assets locked inside. According to DefiLlama data cited by The Defiant, Raydium holds approximately $797 million in total value locked, meaning the drained amount represents less than 0.2% of its on-chain liquidity base.
Attacker used a fraudulent LP mint to bypass proportion checks
The vulnerability resided in the legacy program's LP mint address validation logic. The attacker created a fraudulent LP token mint and submitted it to the deprecated contract, bypassing the proportion checks that should have blocked the withdrawal. Because the program failed to cross-reference the mint against actual LP token supply, it treated the attacker as a legitimate liquidity provider with a claim over the entire pool balance. The five affected pools — Sollet USDT-RAY, Sollet ETH-RAY, SRM-RAY, USDC-RAY, and RAY-SOL — yielded approximately 150,177 RAY, 5,603 SOL, and 893,700 USDC. Multiple security researchers independently confirmed the exploiter's on-chain wallet address as the sole entry point for all five pool drains.
PeckShield traced 810 ETH from the exploit to Tornado Cash
According to security firm PeckShield, the attacker funded the initial transaction through KuCoin and then bridged the stolen assets from Solana to Ethereum, yielding approximately 810 ETH. The attacker deposited the bulk of that amount into Tornado Cash to obscure the transaction trail. A further 7 ETH was routed through instant-swap service FixedFloat, per PeckShield's analysis. Blockchain watcher Specter first flagged the incident on-chain before PeckShield confirmed the laundering path.
Raydium treasury will fully compensate all five affected pool holders
Raydium confirmed that its treasury will cover the full $1.34 million in losses for liquidity providers who held positions in the five deprecated pools at the time of the exploit. The protocol described the LP mint flaw as a self-contained logic error specific to the legacy program — not a key compromise or authority-level issue — and stated that it carries no propagation risk to current programs. Raydium announced a comprehensive security review of all its mainnet programs following the incident.
"Full compensation will be handled by Raydium's treasury." — Infra, Core Contributor, Raydium, 10 June 2026
Cryptocurrencies are highly volatile and involve significant risk. You may lose part or all of your investment.
All information on Coinpaprika is provided for informational purposes only and does not constitute financial or investment advice. Always conduct your own research (DYOR) and consult a qualified financial advisor before making investment decisions.
Coinpaprika is not liable for any losses resulting from the use of this information.