We're about to see alot of these exploits of long forgotten liquidity
How to lose $1,340,000
(Easy guide)
- Raydium
- launch an AMM
- deprecate it in 2021
- remove it from the UI
- assume nobody uses it anymore
- leave five legacy pools on-chain
- leave liquidity inside
- a hacker finds an LP validation bug
- creates a fake LP mint
- tricks the AMM into accepting it
- starts withdrawing assets
drain ~150,177 RAY
drain ~5,603 SOL
drain ~893,700 USDC
- bridge funds to Ethereum
- send 810 ETH to Tornado Cash
$1,340,000 gone
From a program retired five years ago.