Raydium AMM Hack

REPORTED LOSS $4.4M
Medium Compromised pool-owner key solana

What happened

On December 16, 2022, an attacker controlling Raydium's pool-owner account drained approximately $4.4 million from eight constant-product pools. Concentrated-liquidity pools and RAY staking were unaffected. Raydium later funded a compensation program from treasury assets and team token reserves.

Technical Root Cause

Compromised pool-owner authority could inflate fee accounting and withdraw pool assets.

Case & protocol details

Classification Infrastructure / Exchange (DEX) / Key Compromise
Protocol Type DEX
Affected asset / contract RAY
Implementation language Rust
Official Website raydium.io/
Protocol Twitter/X @RaydiumProtocol

How it happened

  1. The attacker gained control of the pool-owner authority; the intrusion method remained unconfirmed.
  2. SetParams with AmmParams::SyncNeedTake inflated amounts recorded as collectible fees.
  3. Repeated withdrawPNL calls removed those amounts from pool vaults.
  4. Raydium revoked the compromised authority, removed unnecessary admin parameters and moved remaining controls to a multisig.

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.