Raydium AMM Hack
What happened
On December 16, 2022, an attacker controlling Raydium's pool-owner account drained approximately $4.4 million from eight constant-product pools. Concentrated-liquidity pools and RAY staking were unaffected. Raydium later funded a compensation program from treasury assets and team token reserves.
Compromised pool-owner authority could inflate fee accounting and withdraw pool assets.
Case & protocol details
How it happened
- The attacker gained control of the pool-owner authority; the intrusion method remained unconfirmed.
SetParamswithAmmParams::SyncNeedTakeinflated amounts recorded as collectible fees.- Repeated
withdrawPNLcalls removed those amounts from pool vaults. - Raydium revoked the compromised authority, removed unnecessary admin parameters and moved remaining controls to a multisig.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report twitter.com
- report Detailed Post-Mortem and Next Steps raydium.medium.com
- analysis Web Archive archive.ph
- analysis Website reference twitter.com
- analysis Website reference twitter.com
- analysis Compensation Plan and Next Steps raydium.medium.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.