Raydium $1.34M Exploit: Impact on Solana DeFi
Published 6/11/2026, 8:19:35 AM
Incident Overview
On June 10, 2026, Raydium experienced a security breach resulting in approximately $1.34 million in losses from deprecated liquidity pools. The incident is being received as a manageable, contained event rather than a systemic crisis, with minimal impact on Solana DeFi confidence.
| Parameter | Value |
|---|---|
| Date | June 10, 2026 |
| Total Value Lost | $1.34 million |
| Affected Infrastructure | Legacy AMM V3 program (deprecated in 2021) |
| Attack Vector | Flaw in LP mint validation allowing fake LP mint creation |
| Attacker Address | 4WnPebowR4HHfumvNPaDjG6Pa5Hi1jxLm6xmmBq33QVk |
Assets Stolen:
- 150,177 RAY tokens
- 5,603 SOL tokens
- 893,700 USDC
Affected Pools (all deprecated since 2021):
- Sollet USDT-RAY
- Sollet ETH-RAY
- SRM-RAY
- USDC-RAY
- RAY-SOL
Key Finding: No Current User Impact
The exploit exclusively targeted legacy infrastructure that had been inaccessible via Raydium's active UI and SDK since 2021. Current programs—including CLMM, V4, and V5 implementations—remain unaffected. This isolation significantly limits confidence damage.
Market Reaction: Muted
| Metric | Response |
|---|---|
| RAY token | +2.09% daily change (post-announcement stabilization) |
| SOL token | +1.97% daily change (broad market unaffected) |
| Raydium TVL | ~$797M (exploit represents only 0.17% of TVL) |
| 30-Day Fee Revenue | ~$5.15M |
The market response has been notably calm compared to previous exploits. RAY and SOL both posted positive daily changes following the announcement, indicating investor confidence remains intact.
Solana DEX Volume Context
Despite the exploit, Solana DEX volumes remain strong:
| DEX | 24H Volume (June 8, 2026) |
|---|---|
| Uniswap (Ethereum) | $12B |
| PancakeSwap (BSC) | $855M |
| Aerodrome (Base) | $633M |
| Orca (Solana) | $242M |
| Raydium (Solana) | $161M |
| Meteora (Solana) | $132M |
Solana maintains 3 protocols in the top 6 DEXs by volume, demonstrating continued ecosystem strength.
Confidence Impact Assessment
Factors Supporting Resilience:
| Factor | Assessment |
|---|---|
| Isolated scope | Legacy code only; no current user impact |
| Treasury backstop | Full compensation commitment limits direct user harm |
| Transparent response | Official statement released within hours with detailed technical explanation |
| Relative scale | $1.34M = 0.17% of TVL; minimal systemic risk |
| Separate attack surface | Core protocols unaffected; new infrastructure uses virtual supply mechanisms |
Concerns & Risk Factors:
| Risk Factor | Analysis |
|---|---|
| Legacy code risk | Highlights ongoing danger of unmaintained smart contracts across DeFi |
| Cross-chain laundering | ~810 ETH routed through Tornado Cash; ~7 ETH through FixedFloat |
| Initial funding source | Attacker funded via KuCoin (CEX), bridged via deBridge |
| Broader market context | SOL at ~$60 (3-year low), 8 consecutive red monthly candles |
Community Sentiment
The incident generated significant engagement across crypto social platforms:
| Account/Source | Position | Engagement |
|---|---|---|
| Raydium Official | Transparent, confident | 105,210 interactions |
| PeckShieldAlert | Alert/neutral | 64,120 interactions |
| Coin Bureau | Informative | 73,243 interactions |
| Jeremybtc | Analytical | 17,465 interactions |
Bullish Solana voices maintained confidence:
- Raydium: "I am still bullish on Solana" (66,722 interactions)
- SolanaHub_: "Believe in @solana..." (39,772 interactions)
- 0xINFRA: "This is just the beginning..." (4,864 interactions)
Key narrative themes emerging:
- "Deprecated doesn't mean dead" — old code still on-chain poses ongoing risk
- Treasury compensation — full losses covered, no user funds lost
- "Forgotten infrastructure" — hackers target overlooked code, not just active systems
Technical Remediation
Root Cause: Insufficient LP mint validation in the legacy AMM V3 program, allowing the attacker to create a fraudulent LP mint that bypassed proportion checks.
Raydium's Response:
- Confirmed scope and published technical details within hours
- Committed to full treasury-funded compensation
- Announced comprehensive security review of all mainnet programs
- Confirmed current mainnet, SDK, and dApp were not compromised
Security Improvement: Current Raydium programs use virtual supply mechanisms with proper LP mint verification—addressing the specific vulnerability exploited.
Comparative Context: Drift Protocol ($285M Hack)
The simultaneous attention on Solana DeFi security is dominated by the $285 million Drift Protocol exploit (April 1, 2026)—the largest DeFi hack of 2026. The Raydium exploit, by contrast, is a relatively contained incident targeting deprecated infrastructure.
| Metric | Raydium (June 2026) | Drift (April 2026) |
|---|---|---|
| Amount | $1.34M | $285M |
| Infrastructure | Deprecated 2021 | Active governance |
| Attack type | LP mint validation flaw | Governance/social engineering |
| Attribution | Unknown | DPRK state-sponsored (preliminary) |
| User impact | None (treasury compensating) | Significant (20+ protocols affected) |
| Market reaction | Muted | DRIFT crashed 40% |
The Raydium exploit has received significantly less market attention than Drift, with sentiment remaining largely neutral-to-bullish.
Conclusion
Impact on Solana DeFi Confidence: MODERATE & CONTAINED
The Raydium $1.34M exploit is being absorbed by the market as a manageable incident rather than a systemic crisis. The key differentiators limiting confidence damage:
- No retail users harmed — treasury compensating all losses
- Deprecated infrastructure — pools inaccessible since 2021
- Rapid, transparent response — detailed technical disclosure within hours
- Minimal TVL impact — only 0.17% of total liquidity
- Isolated vulnerability — no propagation risk to active protocols
Broader implications: The incident highlights the "forgotten code" attack vector—legacy smart contracts that remain on-chain despite being deprecated from active UI. This is a systemic risk across DeFi, not unique to Raydium or Solana.
Unresolved Gaps
| Claim | Gap |
|---|---|
| c1: Exploit details | No specific URLs provided in task results — only generic "Web Search" citations. Whether stolen funds were frozen by exchanges or chain analytics is not explicitly confirmed. |
| c2: Community sentiment | Social engagement metrics and quoted statements provided, but no NLP-based sentiment analysis scores or specific Telegram channel discussions documented. |
| c3: Historical precedent | Strong evidence for the Raydium incident itself, but limited comparative data on how previous Solana DeFi exploits affected TVL/token prices medium-term. |
| c4: Measurable consequences | Pre-exploit TVL baseline not provided to show actual change magnitude. No documented pool outflows or competitor migration metrics — only general Solana DEX volume figures. |
Evidence Summary
| Claim | Evidence | Source |
|---|---|---|
| $1.34M exploit on deprecated AMM V3 | "On June 10, 2026, Raydium...experienced a security breach resulting in approximately $1.34 million in losses from deprecated liquidity pools" | Web Search |
| No current user impact | "The exploit has been contained, with no impact on current users or active protocols" | Web Search |
| Treasury compensation commitment | "Raydium has committed to full treasury-funded compensation" | Web Search |
| TVL at $797M, exploit = 0.17% | "Total Value Locked (TVL): ~$797 million...Exploit Impact: 0.17% of TVL" | Web Search |
| RAY +2.09%, SOL +1.97% post-announcement | "RAY token: Daily change +2.09%...SOL token: Daily change +1.97%" | Web Search |
| 5 deprecated pools affected | "Sollet USDT-RAY, Sollet ETH-RAY, SRM-RAY, USDC-RAY, RAY-SOL" | Web Search |
| Funds laundered via Tornado Cash | "810 ETH funneled through Tornado Cash...~7 ETH routed through FixedFloat" | Web Search |
| Solana DEX volume strength | "Orca (Solana): $242M...Raydium (Solana): $161M...Meteora (Solana): $132M" | Web Search |
| Current programs use virtual supply | "Current programs—including CLMM, V4, and V5 implementations—remain unaffected" | Web Search |
| Security review announced | "Comprehensive audit of all mainnet programs initiated" | Web Search |
Suggested Next Steps
-
Monitor legacy infrastructure across Solana protocols — The "forgotten code" attack vector exposed by this incident may prompt increased scrutiny of deprecated but still-on-chain contracts. Consider setting up alerts for similar security disclosures on competing AMMs (Orca, Meteora, Jupiter).
-
Track post-compensation TVL recovery — Watch whether Raydium's TVL stabilizes or grows over the next 30 days as a real-world gauge of user confidence restoration. A failure to recover would signal deeper sentiment damage than the initial muted market reaction suggests.