🚨 Raydium legacy
@Raydium liquidity pools on
#Solana were exploited through an LP mint validation bypass, with public reporting attributing about $1.3M in drained value.
💰 Impact: In independently checked sample transactions, burning only 1 attacker-minted fake LP token released 5,602.964099112
#WSOL, 83,341.713143
#RAY, and 10,692.215336 SRM to attacker-controlled token accounts. Public reporting states broader losses of about $1.3M.
⏰ Time: 2026-06-10 12:09:21 UTC, Solana slot 425542754
🔎 Root cause: Raydium legacy RemoveLiquidity accepted caller-supplied LP mint / LP token accounts without sufficiently binding them to the pool's canonical LP mint. The vulnerable path used the supplied fake mint's supply = 1 as the withdrawal denominator, so withdraw_amount = 1 redeemed the real vault balances.
🧭 Attack trace:
1. Attacker 4WnPebowR4HHfumvNPaDjG6Pa5Hi1jxLm6xmmBq33QVk created a fresh SPL mint with zero decimals and attacker-controlled mint authority.
2. The attacker created a token account for that mint and minted exactly 1 fake LP-like token.
3. The fake mint/account was supplied to Raydium legacy RemoveLiquidity on program 27haf8L6oxUeXrHrgEgsexjSY5hbVUWEmvv9Nyxg8vQv with instruction amount 1.
4. Raydium calculated the withdrawal against lp_mint_supply=1, transferred real RAY / WSOL / SRM from pool vaults, then burned the fake token.
📌 Key addresses:
Attacker: 4WnPebowR4HHfumvNPaDjG6Pa5Hi1jxLm6xmmBq33QVk
Vulnerable Program: 27haf8L6oxUeXrHrgEgsexjSY5hbVUWEmvv9Nyxg8vQv
Ethereum Receiver: 0x0EaBAAb9a56011c6158D4aA7f2E49A82fB34E609
🧾 Tx:
solscan.io/tx/2gwZ1P37p3S396…
🛡️ Takeaway: Remove-liquidity paths must derive and verify the canonical LP mint, user LP token mint, vault accounts, and authority seeds before any vault transfer. Burning an arbitrary SPL token must never unlock pool reserves.
Powered by
#DarkNavy Web3 AI Agent