FacebookTwitterLinkedInTelegramCopy LinkEmail
Crime and Investigations

Raydium Exploit Targets Dormant Liquidity Pools, Draining $1.3 Million

Raydium Exploit Targets Dormant Liquidity Pools, Draining $1.3 Million

Raydium is investigating an exploit that resulted in the loss of approximately $1.3 million from a set of legacy liquidity pools on Solana, marking the latest security incident to expose the long-tail risks associated with dormant decentralized finance infrastructure.

Summary

  • Raydium confirmed a $1.3 million exploit involving legacy AMM V3 pools.
  • The incident did not affect active users, current liquidity pools, or core trading infrastructure.
  • The attack highlights ongoing risks tied to outdated smart contracts that remain active on public blockchains.

The Solana-based decentralized exchange confirmed on June 10 that the exploit targeted deprecated AMM V3 pools. Raydium removed those pools from its user interface years ago but left the contracts active on-chain.

Raydium said attackers did not compromise its current trading systems. The protocol also stated that users could not access the affected pools through the main platform.

The distinction matters. DeFi protocols frequently migrate liquidity and deploy new smart contracts. However, many projects leave older contracts active after upgrades. Those contracts can continue holding assets and processing transactions for years.

Security researchers have repeatedly warned that attackers often target forgotten infrastructure because teams monitor it less aggressively than active products.

Attacker Bridged Funds to Ethereum

On-chain investigators traced the attacker’s activity shortly after the exploit.

According to blockchain data from PeckShield, the attacker initially funded operations through KuCoin. After draining liquidity from the affected pools, the attacker bridged funds from Solana to Ethereum.

Researchers then identified approximately 810 ETH moving into Tornado Cash. Another 7 ETH flowed through FixedFloat.

The movement follows a familiar pattern in DeFi exploits. Attackers often move assets across multiple networks before sending funds through privacy tools. These steps make recovery efforts more difficult and complicate blockchain investigations.

Raydium said it is working with security firms and ecosystem partners to determine the exact exploit path. The team has not yet published a full technical analysis.


READ MORE: Echo Exploit Highlights DeFi’s Growing Access-Control Risks


The protocol also indicated that treasury resources could help address losses tied to the incident.

What This Means for DeFi Users: The “Zombie Contract” Risk

This incident highlights a growing, often overlooked vulnerability in the decentralized finance space: the “zombie contract.” When DeFi protocols migrate to newer versions, older smart contracts are often left active on the blockchain. While these contracts are no longer promoted on the project’s main interface, they continue to hold state and, in some cases, residual liquidity.

For investors and DeFi users, this presents a “long-tail” security risk. Even if you haven’t interacted with a protocol in years, any permissions or assets left tied to deprecated smart contracts remain accessible to exploiters.

Dormant Infrastructure Remains a Security Risk

While the financial damage remains relatively small compared with major DeFi hacks, security researchers view the exploit as an important warning sign.

The incident did not stem from Raydium’s active infrastructure. Instead, it originated from contracts the protocol stopped promoting years ago.

That distinction reflects a broader challenge across decentralized finance. Smart contracts often remain online indefinitely after deployment. Teams can launch newer versions, but older contracts frequently stay active unless developers explicitly disable them.

As a result, attackers continue searching for outdated code, abandoned liquidity pools, and forgotten protocol components that still control assets.

The Raydium exploit demonstrates how those risks can persist long after a project moves forward. Although the affected pools no longer played a meaningful role in the protocol’s daily operations, they still existed on-chain and remained vulnerable to attack.

Institutional investors have increasingly focused on these long-tail risks as capital flows into decentralized finance. Many firms now evaluate not only active infrastructure but also legacy deployments that remain accessible on public blockchains.

Raydium maintains that the exploit did not impact active users or current liquidity pools. Even so, the incident underscores a key reality of blockchain systems: infrastructure that appears inactive can still create meaningful security risks years later.

The industry’s response to the investigation may prove just as important as the exploit itself. As DeFi matures, protocols face growing pressure to audit, isolate, or fully retire legacy infrastructure before attackers discover weaknesses hidden in older code.


The information presented in this article is intended for informational purposes only and should not be interpreted as financial, investment, or trading advice. Coinspress.com does not promote or advocate for any particular investment strategy, asset, or cryptocurrency project. Cryptocurrency markets are highly volatile and unpredictable – always perform your own research and seek guidance from a qualified financial professional before making any investment decisions.

Author
Alexander Zdravkov

Reporter at CoinsPress

Alexander Zdravkov is a market analyst and crypto journalist with interests in economics, broader financial markets and digital assets. His journey into crypto began more than four years ago, driven by a fascination with the rapid evolution of blockchain technology and the transformative potential of decentralized finance. He began analyzing market cycles and identifying emerging trends before they reach the mainstream. He holds a degree in International Relations - a background that helped shape his broader perspective on global economics, geopolitics, and the interconnected nature of modern financial markets. Whether covering the latest developments in the crypto sector or exploring broader macroeconomic themes, Alexander focuses on giving readers context rather than simply repeating headlines. During his career, he has authored more than 10,000 articles covering cryptocurrencies, traditional finance, and global market developments. His work spans everything from Bitcoin and altcoins to macroeconomic trends influencing risk assets worldwide.

Learn more about crypto and blockchain technology.

Glossary