Raydium suffers $1,34 million attack and promises full reimbursement.
- Raydium DEX covers losses after attacks on old pools.
- Failure in legacy AMM allowed for the drain of US$1,34 million.
- Solana's current programs were not affected.
Raydium, one of the leading decentralized exchanges (DEXs) on the Solana network, reported that a vulnerability in an old automated market maker (AMM) program resulted in the improper withdrawal of approximately US$1,34 million in digital assets from liquidity pools that were no longer in operation.
According to the protocol team, the incident exclusively affected the AMM V3 program, which has been deactivated since 2021. According to the company, these pools were no longer accessible through the platform's official interface and were not compatible with the tools currently used by users.
Raydium is aware of an exploit involving unauthorized removal of liquidity from its legacy AMM V3 program which was previously phased out in 2021.
No current users of Raydium are affected by this exploit or would have been able to interact with these pools through the UI since…
— Infra | Raydium (@0xINFRA) June 10, 2026
Initial estimates indicate that the attacker managed to withdraw approximately 150 RAY tokens, about 5.600 SOL tokens, and nearly 900 USDC tokens. Among the liquidity pairs impacted were RAY-SOL, USDC-RAY, and SRM-RAY.
Despite the financial loss, Raydium stated that active users of the platform were not directly impacted. The team highlighted that its "SDK and DAPP do not support mainnet interactions with legacy AMM V3 pools."
The company also reported that the lost funds will be fully covered by the protocol's treasury. This measure aims to avoid any financial impact on participants linked to the pools affected by the attack.
In its preliminary analysis, Raydium explained that the vulnerability was related to inadequate validation of liquidity coins within the legacy program. This flaw would have allowed the attacker to bypass mechanisms designed to ensure the correct ratio of assets deposited in the pools.
The team described the breach as stemming from insufficient validation of liquidity currencies, creating an opportunity to circumvent the "expected ratio checks."
The incident occurs at a time when decentralized finance protocols continue to strengthen audits and security processes to reduce risks in legacy smart contracts that remain active on the blockchain, even after being removed from core interfaces.
Raydium emphasized that its programs currently running on Solana's main network were not compromised. Furthermore, the company reported that active systems undergo independent security reviews to identify potential vulnerabilities before they can be exploited.
Although the attack targeted a component that was discontinued several years ago, the case highlights how legacy code can still pose risks within the cryptocurrency ecosystem, especially when it remains directly accessible on the blockchain.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Crypto Futures Liquidations Top $141M in 24 Hours as Bitcoin and Ethereum Lead
Whale Address Acquires $3.7M in ENA and Stakes on Ethena
Top-Performing Cryptos to Watch in 2026: ZKP, Dogecoin, Tron & XRP Deliver Strong Network Utility

INSPIRE MEDICAL SYSTEMS INC <INSP.N>: JEFFERIES RAISES TARGET PRICE TO $55 FROM $50
