← Radar

Incident case file

Sign in to watch

Raydium AMM V3 — Fake LP Token Exploit (Treasury Compensation)

Incident date June 10, 2026

2 views

ResolvedSolanaAMM exploit / Fake LP tokenCluster: RAY-SOL-2026-06

Estimated loss

$1.3M

Victims identified

5
Victim group joining is coming soon.

Investigation

90%

Facts and investigation

Attacker: Solana EOA: 4WnPebowR4HHfumvNPaDjG6Pa5Hi1jxLm6xmmBq33QVk ETH laundering wallet: 0x0eabaab9a56011c6158d4aa7f2e49a82fb34e609 (Funded from KuCoin at 11:28 UTC June 10)

Funds moved to: Solana → deBridge → ETH wallet 0x0eabaab9a56011c6158d4aa7f2e49a82fb34e609 (~820 ETH received in 10 batches) → 810 ETH into Tornado Cash (8×100 ETH + 1×10 ETH deposits) + 7 ETH to FixedFloat. Stolen funds considered unrecoverable; Raydium treasury committed to full LP compensation.
Exploited program (unverified): 27haf8L6oxUeXrHrgEgsexjSY5hbVUWEmvv9Nyxg8vQv Four exploit transactions (Solscan): 1. USDC+RAY ($894K): 1csN6vZKFKpeJEcwZhoiM99xoRJVY7EC3P28CE6kHYrKyrVfj2L5Sf5HfhxeBGxSsuhtFvWmkhVYXtyUAQH3s7s 2. RAY+wSOL: 2gwZ1P37p3S3963YwovvzE1FF7zXY3g1Dj8BUVwzsUAQaJD2W7sxXx9geFcxaUny4tAEguzv187ha1YmE9iBZTMN 3. RAY+SRM: 9jBVvs6stJfpVan97pzkW2huUdynQ41yzWJh14w6j1jXee2MKZwPjCGQ5zHyBdSMBdHX9mbhTYzNMfD1tupbxbR 4. RAY+dust: 5877QVfgQqtNjHrmdfuQDZh1VbtUbdEKszPZdn8LGEAaUcpzjGRf831HosdHCV

Timeline: On June 10, 2026, an attacker exploited a logic flaw in Raydium's legacy AMM V3 program — a deprecated pool system that had been inactive since 2021 but whose deposited liquidity remained on-chain. The vulnerability stemmed from insufficient validation of the LP mint address: the program did not verify that the LP token used for withdrawal was the legitimate one, allowing the attacker to mint a custom token with supply=1 and use it to claim 100% of pool reserves in a single withdrawal call. The attacker funded their wallet from KuCoin at 11:28 UTC, drained all five vulnerable pools by 12:09 UTC, and completed Tornado Cash laundering by 13:41 UTC — under two hours from start to finish. Assets drained included ~150K RAY, ~5,600 SOL, and ~893K USDC across pools: Sollet USDT-RAY, Sollet ETH-RAY, SRM-RAY, USDC-RAY, and RAY-SOL. The exploited program was not accessible through the Raydium UI or SDK. No key compromise occurred — the bug was a self-contained logic flaw in the deprecated code. Raydium's current mainnet programs were not affected. Raydium treasury committed to full compensation of all affected LPs.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)