CryptoReal
CASE FILE — Dec 19, 2022

Compromised Owner Key Lets Attacker Siphon $4.4M in Fees From Raydium's Solana Pools

Raydium, a Solana-based automated market maker, lost approximately $4.4 million in accumulated fees from its liquidity pools in an incident that began on Friday, December 16, 2022.

01Discovery and response

The first public warning came from PRISM, a DEX aggregator also built on Solana, which posted:

There seems to be a wallet is draining LP Pools from Raydium liquidity pools using admin wallet as a signer without having/burning LP tokens.

We withdrew protocol provided PRISM/USDC liquidity from Raydium

WITHDRAW YOUR PRISM/USDC LIQUIDITY FROM RAYDIUM

Raydium's official acknowledgment followed roughly 40 minutes later, stating that authority had been halted on its AMM and farm programs. In a subsequent update, the team said a patch was in place to prevent the attacker from exploiting the issue further. While the losses did not amount to a full protocol collapse, several million dollars in fees still disappeared.

02Root cause

Per analysis from security firm OtterSec, the incident traced back to a compromised private key controlling the owner account for Raydium's contracts. Raydium itself described the likely cause as a trojan-based attack that compromised the private key of the pool owner account.

Sums referenced in this case file

That owner account held authority over specific pool functions, which let the attacker withdraw accumulated trading and protocol fees through the withdraw_pnl instruction. The attacker additionally altered the SyncNeedTake parameter to inflate the fees the contract believed were owed, extracting more funds than had genuinely accrued.

03Pools affected

The exploit touched the following pools, for a combined protocol loss of $4.4 million:

  • SOL-USDC
  • SOL-USDT
  • RAY-USDC
  • RAY-USDT
  • RAY-SOL
  • stSOL-USDC
  • ZBC-USDC
  • UXP-USDC
  • whETH-USDC

Most of the stolen funds were bridged to Ethereum, converted to ETH, and deposited into Tornado Cash. Around 100,000 SOL (roughly $1.4 million) remained sitting in the attacker's Solana wallet at the time of reporting.

04Context

As with most "compromised key" incidents, the possibility of insider involvement can't be ruled out. The broader bear market has already put smaller teams under considerable financial pressure, and the fallout from FTX's collapse and the downfall of its now-imprisoned founder had left much of the Solana ecosystem — closely tied to FTX — in a precarious position. Whether this incident stemmed from external compromise or an insider under strain is, as with many similar cases, unlikely to ever be definitively known.

RaydiumSolana
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.