Raydium's $1.34M Exploit: Treasury Compensation &
Published 6/15/2026, 6:06:40 AM
Note: The research provided detailed narrative findings but did not include clickable source URLs for verification. All factual claims below are drawn from the research summary, but readers should seek primary sources for independent verification.
Exploit Overview
On June 10, 2026, Raydium confirmed an exploit draining approximately $1.34 million from five deprecated Legacy AMM V3 liquidity pools. The protocol immediately committed to full compensation from its treasury.
| Metric | Details |
|---|---|
| Loss Amount | ~$1.34 million |
| Affected Assets | 150,177 RAY, 5,603 SOL, 893,700 USDC |
| Affected Pools | 5 deprecated pools (Sollet USDT-RAY, Sollet ETH-RAY, SRM-RAY, USDC-RAY, RAY-SOL) |
| Vulnerability | Flawed LP mint validation in legacy AMM V3 withdrawal logic |
| Attack Method | Attacker created fraudulent LP mint to bypass security checks |
Treasury Compensation Assessment
| Factor | Assessment |
|---|---|
| Compensation Scope | Full reimbursement for all affected users |
| Funding Source | Raydium protocol treasury |
| Current User Impact | None — active pools (CLMM, V4, V5) unaffected |
| Protocol TVL | ~$797 million (exploit = <0.2% of TVL) |
| 30-Day Fee Revenue | ~$5.15 million |
Will Compensation Restore User Confidence?
Likely outcome: Largely yes, for most users. The combination of full treasury compensation, zero impact to current operations, strong protocol fundamentals ($797M TVL), and proactive transparency should substantially restore confidence.
Supporting factors:
- Swift treasury response — Full compensation committed within days demonstrates financial responsibility
- No current user losses — Deprecated pools were inaccessible via SDK/front-end since 2021; active users completely unaffected
- Strong fundamentals — $797M TVL and ~$5.15M monthly fee revenue indicate capacity to absorb the loss
- Transparent disclosure — Detailed on-chain breakdown shared publicly, including technical explanation
Residual concerns:
- Legacy code risk — Deprecated contracts from 2021 remained live on-chain with residual assets for 3+ years, exposing "zombie contract" risks
- Industry pattern — 8+ exploits since 2025 targeted deprecated/abandoned contracts (~$108M+ losses), raising broader DeFi security questions
- Regulatory attention — Attacker used Tornado Cash (810 ETH laundered) and funded via KuCoin
Community Sentiment
Social media and on-chain discussions show mixed but predominantly constructive sentiment:
- Positive: Praise for swift response, transparency, and treasury backing. One user noted: "Still one of the strongest Solana protocols imo"
- Negative: Concerns about legacy code management and why deprecated pools retained on-chain assets
- Neutral: Recognition that "deprecated ≠ secure" is an industry-wide lesson
Conclusion
The $1.3M treasury compensation is likely sufficient to restore confidence for the majority of Raydium users and liquidity providers. However, sophisticated DeFi users and institutional actors may remain cautious about legacy code management practices, as the incident reveals that deprecated infrastructure can remain an attack surface years after being "retired" from the UI.
Research Gap: The analysis lacks primary source URLs for independent verification. The evidence ledger notes that source names (Crypto Briefing, The Defiant, DefiLlama, PeckShield) were provided but no direct URLs were included in the research output.
Suggested Next Steps
- Obtain primary source verification — Locate and review the original PeckShieldAlert tweet and Raydium contributor 0xINFRA announcement on-chain to confirm the exact compensation timeline and wallet addresses.
- Monitor TVL and sentiment trends — Set a recurring check (7–14 days post-incident) to track whether Raydium's TVL stabilizes above $750M and whether social sentiment shifts from mixed to positive.