Compromised Owner Key Lets Attacker Siphon $4.4M in Fees From Raydium's Solana Pools
Raydium, a Solana-based automated market maker, lost approximately $4.4 million in accumulated fees from its liquidity pools in an incident that began on Friday, December 16, 2022.
01Discovery and response

The first public warning came from PRISM, a DEX aggregator also built on Solana, which posted:
There seems to be a wallet is draining LP Pools from Raydium liquidity pools using admin wallet as a signer without having/burning LP tokens.
We withdrew protocol provided PRISM/USDC liquidity from Raydium
WITHDRAW YOUR PRISM/USDC LIQUIDITY FROM RAYDIUM
Raydium's official acknowledgment followed roughly 40 minutes later, stating that authority had been halted on its AMM and farm programs. In a subsequent update, the team said a patch was in place to prevent the attacker from exploiting the issue further. While the losses did not amount to a full protocol collapse, several million dollars in fees still disappeared.
02Root cause
Per analysis from security firm OtterSec, the incident traced back to a compromised private key controlling the owner account for Raydium's contracts. Raydium itself described the likely cause as a trojan-based attack that compromised the private key of the pool owner account.
That owner account held authority over specific pool functions, which let the attacker withdraw accumulated trading and protocol fees through the withdraw_pnl instruction. The attacker additionally altered the SyncNeedTake parameter to inflate the fees the contract believed were owed, extracting more funds than had genuinely accrued.
03Pools affected
The exploit touched the following pools, for a combined protocol loss of $4.4 million:
- SOL-USDC
- SOL-USDT
- RAY-USDC
- RAY-USDT
- RAY-SOL
- stSOL-USDC
- ZBC-USDC
- UXP-USDC
- whETH-USDC

Most of the stolen funds were bridged to Ethereum, converted to ETH, and deposited into Tornado Cash. Around 100,000 SOL (roughly $1.4 million) remained sitting in the attacker's Solana wallet at the time of reporting.
- Attacker's Solana address: AgJddDJLt17nHyXDCpyGELxwsZZQPqfUsuwzoiqVGJwD
- Attacker's Ethereum address: 0x7047912c295cd54d6617b5d0d6d8b324a11c91db
04Context
As with most "compromised key" incidents, the possibility of insider involvement can't be ruled out. The broader bear market has already put smaller teams under considerable financial pressure, and the fallout from FTX's collapse and the downfall of its now-imprisoned founder had left much of the Solana ecosystem — closely tied to FTX — in a precarious position. Whether this incident stemmed from external compromise or an insider under strain is, as with many similar cases, unlikely to ever be definitively known.
Get new scam files the moment we publish them — usually 2–3 emails a week.