Raydium DEX suffered a $1.34M exploit on a retired AMM program; the treasury will reimburse affected users.
Security & Exploits ·
Raydium's deprecated Legacy AMM V3 program suffered an exploit worth approximately $1.34 million, with an LP mint validation flaw enabling an attacker to circumvent proportion checks. The vulnerability was confined to inactive Legacy AMM V3 pools; the project stated that active mainnet programs, its SDK, and DApp interface all remained unaffected by the incident.
The exploit targeted five dormant liquidity pools within the retired AMM system. Because these pools were no longer in use, the breach did not expose active liquidity providers to direct losses.
Raydium committed to fully reimbursing affected users and launched a broader security review of all mainnet programs. The incident underscores risks lingering in deprecated code paths even after migration to newer versions, though the containment to legacy infrastructure limited the scope of exposure.