On June 10, 2026, a hacker exploited 5 deprecated liquidity swimming pools on Raydium, Solana largest decentralized alternate, draining roughly $1.34 million in crypto belongings by a solid LP token assault on the protocol’s legacy AMM V3 program.
The stolen funds included ~$900,000 in USDC, ~$357,000 in SOL, and ~$86,000 in RAY tokens. The RAY token up 2% within the 24 hours following the incident, just lately altering arms at $0.578, already down ~7% on the week and sitting 96.6% beneath its all-time excessive of $16.83.
Raydium confirms $1.34M exploit on legacy AMM V3 swimming pools. No present customers affected; full compensation from treasury. pic.twitter.com/tqmKATA2tH
— Solana Hub (@SolanaHub_) June 10, 2026
EXCLUSIVE: Earn $10 USDC Via Binance Sign-Up
Solana Raydium Exploit Defined: How a Faux Token Fooled a Retired Sensible Contract
Consider it like a decommissioned financial institution department that closed its doorways to clients years in the past, however administration forgot to maneuver the money out of the vault. The tellers are gone, the ATM is switched off, the department doesn’t seem on the financial institution’s web site anymore. But when somebody discovered a aspect door nonetheless unlocked, the cash inside could be simply as actual as ever.
That’s nearly precisely what occurred right here. Raydium operates as an AMM, an automatic market maker, which suggests it makes use of good contract-managed liquidity swimming pools as an alternative of conventional order books to facilitate trades on Solana. In 2021, Raydium phased out its legacy AMM V3 program after Serum’s order e-book was deprecated, changing it with up to date structure. The previous program was faraway from the UI, however the underlying good contract and the funds locked inside it remained reside on-chain.

The attacker discovered a sensible contract vulnerability in that legacy code: the AMM V3 program didn’t correctly validate the LP mint deal with, the token that represents a liquidity supplier’s share of a pool. By making a pretend LP token mint and presenting it to the contract, the hacker satisfied this system’s inner accounting that their counterfeit tokens represented professional pool possession. The contract then allowed them to withdraw the swimming pools’ actual belongings as if they have been a real LP redeeming a place.
Throughout 5 swimming pools, Sollet USDT–RAY, Sollet ETH–RAY, SRM–RAY, USDC–RAY, and RAY–SOL, the attacker withdrew ~150,177 RAY, ~5,603 SOL, and ~893,700 USDC. After the liquidity pool hack, the funds have been bridged from Solana to Ethereum and deposited into Twister Money, a crypto mixer that breaks the on-chain transaction path, a laundering sample more and more widespread in 2026 DeFi exploits. The attacker’s Solana deal with (ending in Bq33QVk) was initially funded by KuCoin.
EXCLUSIVE: Earn $10 USDC Via Binance Sign-Up
The Structural Story: Why Retired Code Nonetheless Held Stay Funds
A very powerful factor to grasp about this DeFi exploit is what “deprecated” truly means on a public blockchain, and what it doesn’t imply. When a protocol deprecates a program, it usually stops directing customers to it by way of the interface and focuses growth consideration elsewhere.
What it nearly by no means does mechanically is freeze the contract’s state or migrate funds out of the previous swimming pools.
On Solana, and on Ethereum and just about each different good contract platform, a deployed program stays callable by anybody who is aware of its deal with, no matter whether or not it seems on a entrance finish. Except a protocol explicitly pauses the contract, burns its improve authority, or migrates all liquidity out, the code retains working.
Raydium’s legacy AMM V3 had been invisible to on a regular basis customers for 4 years, but it surely was by no means immobilized. That’s the structural hole this exploit walked by.
Raydium is conscious of an exploit involving unauthorized elimination of liquidity from its legacy AMM V3 program which was beforehand phased out in 2021.
No present customers of Raydium are affected by this exploit or would have been in a position to work together with these swimming pools by the UI since…
— Infra | Raydium (@0xINFRA) June 10, 2026
Pseudonymous Raydium contributor 0xInfra confirmed the exploit was “a self-contained logic flaw” within the previous program, not a key compromise or authority-level subject, which means Raydium’s present mainnet applications carry no equal vulnerability.
However the broader implication is uncomfortable: what number of different DeFi protocols working on Solana or different chains have deprecated contracts quietly holding dormant liquidity that has by no means been formally migrated or frozen? This incident means that quantity could also be greater than anybody has audited.
Solana’s ecosystem has been evolving rapidly, however legacy infrastructure can lag far behind governance selections.
DISCOVER: The 12+ Hottest Crypto Presales to Buy Right Now
Observe 99Bitcoins on X For the Newest Market Updates and Subscribe on YouTube For Day by day Knowledgeable Market Evaluation.
The submit Solana Raydium DEX Lost $1.34M to Hackers, Here’s What Actually Happened appeared first on 99Bitcoins.
