Cointime

Download App
iOS & Android

Raydium Protocol: Exploit Appears to Stem From Compromised Private Key for Pool Owner Account

Cointime Official

Solana-based decentralized finance protocol Raydium announced Initial Post-Mortem on its 7-figure exploit. As of now, a patch is in place preventing further exploits from the attacker.

"The exploit appears to stem from a trojan attack and compromised private key for the pool owner account." Raydium wrote in its Tweet, "Previous owner authority has been revoked and all program accounts have been updated to new hard wallet accounts. As such, the attacker no longer has access authority and is no longer able to exploit the pools".

"If the attacker returns the funds, 10% of the total amount will be offered and considered as a white-hat bug bounty. " Raydium added.

 In earlier report, Raydium has suffered an exploit, around $2 million worth of different cryptocurrencies was sitting in the account of an attacker that managed to maliciously withdraw user funds from Raydium exchange pools.

“Initial understanding is owner authority was overtaken by attacker, but authority has been halted on AMM & farm programs for now,” Raydium said on Tweet.

Full thread from @RaydiumProtocol on Twitter:

1/ Initial Post-Mortem: Raydium is working w 3rd-party auditors and teams across Solana to gather additional info. As of now, a patch is in place preventing further exploits from the attacker.

The following includes info up to now. Big thanks to all teams providing support

2/ Raydium’s upgrade authority is held by a @SquadsProtocol multisig. This attack was not related to upgrade authority on the program itself. The exploit appears to stem from a trojan attack and compromised private key for the pool owner account.

3/ The attacker accessed the pool owner account and was then able to call the withdrawalPNL function, a function used to collect trading/protocol fees earned by swaps in pools.

4/ The hacker was also able to set the SyncNeedTake parameters to change the out_put.need_take_pnl for quote and base tokens in the affected pools in order to modify expected fees and then withdraw those amounts.

5/ Pools affected:

SOL-USDC

SOL-USDT

RAY-USDC

RAY-USDT

RAY-SOL

stSOL-USDC

ZBC-USDC

UXP-USDC

whETH-USDC

Approx total funds exploited by attacker

RAY 1,879,638

stSOL 3,214

whETH 39.3

USDC 1,094,613

SOL120,512

UXP 21,068,507

ZBC9,758,647

USDT110,427

Total USD: ~4,395,237

6/ As an immediate solution, previous owner authority has been revoked and all program accounts have been updated to new hard wallet accounts. As such, the attacker no longer has access authority and is no longer able to exploit the pools.

7/ If the attacker returns the funds, 10% of the total amount will be offered and considered as a white-hat bug bounty. The attacker is encouraged to reach out through normal channels or via the below address

0x6d3078ED15461E989fbf44aE32AaF3D3Cfdc4a90

8/ Thank you to the Solana community for the support, specifically @solanafm@HelloMoon_io@wormholecrypto@osec_io and exchanges that blacklisted the hacker’s associated addresses. More details will follow as they become available. Everyone's support is greatly appreciated1334

Comments

All Comments

Recommended for you

  • Equation News calls out Binance for "insider trading": You are destroying the sentiment of the trading market

    On November 25th, Formula News reported that to those insider traders who participated in the listing of Binance perpetual contracts, please slow down when selling your chips next time. The WHY and CHEEMS crashes you caused resulted in a 100% negative return for everyone involved in the trade, and you are destroying the emotions of the trade. Earlier today, Binance announced the listing of 1000WHYUSDT and 1000CHEEMSUSDT perpetual contracts, which caused a short-term crash in WHY and CHEEMS and sparked intense discussion within the community.

  • U.S. Congressman Mike Flood: Looking forward to working with the next SEC Chairman to revoke the anti-crypto banking policy SAB 121

     US House of Representatives will investigate Representative Mike Flood's recent statement: "Despite widespread opposition, SAB 121 is still operating as a regulation, even though it has never gone through the normal Administrative Procedure Act process." Flood said, "I look forward to working with the next SEC chairman to revoke SAB 121. Whether Chairman Gary Gensler resigns on his own or President Trump fulfills his promise to dismiss Gensler, the new government has an excellent opportunity to usher in a new era after Gensler's departure." He added, "It's not surprising that Gensler opposed the digital asset regulatory framework passed by the House on a bipartisan basis earlier this year. 71 Democrats and House Republicans passed this common-sense framework together. Although the Democratic-led Senate rejected it, it represented a breakthrough moment for cryptocurrency and may provide information for the work of the unified Republican government when the next Congress begins in January next year."

  • Indian billionaire Adani summoned by US SEC to explain position on bribery case

    Indian billionaire Gautam Adani and his nephew, Sahil Adani, have been subpoenaed by the US Securities and Exchange Commission (SEC) to explain allegations of paying over $250 million in bribes to win solar power contracts. According to the Press Trust of India (PTI), the subpoena has been delivered to the Adani family's residence in Ahmedabad, a city in western India, and they have been given 21 days to respond. The notice, issued on November 21 by the Eastern District Court of New York, states that if the Adani family fails to respond on time, a default judgment will be made against them.

  • U.S. Congressman: SEC Commissioner Hester Peirce may become the new acting chairman of the SEC

    US Congressman French Hill revealed at the North American Blockchain Summit (NABS) that Republican SEC Commissioner Hester Peirce is "likely" to become the new acting chair of the US Securities and Exchange Commission (SEC). He noted that current chair Gary Gensler will step down on January 20, 2025, and the Republican Party will take over the SEC, with Peirce expected to succeed him.

  • Tether spokesperson: The relationship with Cantor is purely business, and the claim that Lutnick influenced regulatory actions is pure nonsense

     a spokesperson for Tether stated: "The relationship between Tether and Cantor Fitzgerald is purely a business relationship based on managing reserves. Claims that Howard Lutnick's joining the transition team in some way implies an influence on regulatory actions are baseless."

  • Bitwise CEO warns that ETHW is not suitable for all investors and has high risks and high volatility

    Hunter Horsley, CEO of Bitwise, posted on X platform that he was happy to see capital inflows into Bitwise's Ethereum exchange-traded fund ETHW, iShares, and Fidelity this Friday. He reminded that ETHW is not a registered investment company under the U.S. Investment Company Act of 1940 and therefore is not protected by the law. ETHW is not suitable for all investors due to its high risk and volatility.

  • Musk said he liked the "WOULD" meme, and the related tokens rose 400 times in a short period of time

    Musk posted a picture on his social media platform saying he likes the "WOULD" meme. As a result, the meme coin with the same name briefly surged. According to GMGN data, the meme coin with the same name created 123 days ago surged over 400 times in a short period of time, with a current market value of 4.5 million US dollars. Reminder to users: Meme coins have no practical use cases, prices are highly volatile, and investment should be cautious.

  • Victory Securities: Funding Rates halved and fell, Bitcoin's short-term direction is not one-sided

    Zhou Lele, the Vice Chief Operating Officer of Victory Securities, analyzed that the macro and high-level negative impact risks in the cryptocurrency market have passed. The risks are now more focused on expected realization, such as the American entrepreneur Musk and the American "Efficiency Department" (DOGE) led by Ramaswamy. After media reports, the increase in Dogecoin ($DOGE) was only 5.7%, while Dogecoin rose by 83% in the week when the US election results were announced. Last week, the net inflow of off-exchange Bitcoin ETF was US$1.67 billion, and the holdings of exchange contracts and CME contracts remained high, but the funding rates halved and fell back, indicating that the direction of Bitcoin in the short term is not one-sided, and bears are also accumulating strength.

  • Why is Solana's Dogwifhat (WIF) memecoin crashing?

    WIF price risks declining by another 48% due to the formation of a classic bearish reversal setup.

  • Solana Edge Data Intelligent Network 375ai Completes $5 Million Seed Round of Financing, Led by 6MV

    Solana's edge data intelligent network 375ai announced the completion of a $5 million seed round of financing on X platform, with 6MV as the lead investor and participation from Arca, Escap Velocity, Primal Capital, and Auros. Specific valuation information has not been disclosed. 375ai provides decentralized edge data intelligent network nodes and mobile applications based on blockchain for real-time data collection. Users can participate in the network by deploying nodes, using applications, or staking tokens, while also receiving rewards.