Ultimate magazine theme for WordPress.

Detailed Post-Mortem and Next Steps | by Raydium

Follow the recent Raydium Liquidity Pool exploit

On December 16, 2022 at 10:12 UTC, a malicious actor started an exploit on the Raydium Liquidity Pool V4 authority account by gaining access to the pool owner (Admin) account.

OtterSec posted an initial overview of the attack.

This update also extends the first post mortem posted by Raydium’s official account on Twitter.

This detailed post-mortem attempts to provide a thorough description of how the exploit ran, how the problem was fixed, and the next steps.

The Pool Owner account mentioned above was originally deployed on a virtual machine with a dedicated internal server. Upon additional verification, there is currently no evidence that the private key for the pool owner account was ever shared, shared, transferred, or stored locally outside of the virtual machine on which it was originally deployed.

An internal security review is underway to determine the nature and cause of the account compromise. It is initially suspected that the attacker gained remote access to the virtual machine or internal server on which the account was provisioned. The exact attack vector has yet to be identified, but a Trojan horse attack could be a possibility.

Initial verification suggests that the Raydium exploit account is involved in other nefarious activities on Solana. A clue to this is a tweet from cloudzy.sol on Nov. 7 describing a 198 SOL wallet exploit that ultimately ended up in the same account that originally funded the primary Raydium exploiter wallet, as in the first post- Mortem tweet mentioned. (Edit) Address 5ndL…HEPs has been confirmed as a hot wallet address by FixedFloat Exchange. The latest details about the exploit can be found here.

The attacker compromised eight constant product liquidity pools on Raydium totaling approximately $4.4M in stolen funds. Concentrated liquidity pools and RAY staking programs were unaffected by the exploit. All other pools or funds on Raydium were unaffected by the exploit.

The image below shows assets transferred from affected pools by the attacker during the exploit. “Base” token refers to the token on the left of the token pair, “Quote” refers to the token on the right of the pair (usually stablecoin or SOL).

A full list of transaction history and lost funds can be found here: https://github.com/raydium-io/dec_16_exploit

  1. The withdrawPNL There is an instruction to charge protocol fees for RAY buybacks and is based on a predefined amount of assets determined by need_take_pc and need_take_coin which should equal 12% of the total fees earned by the pool or 3bps of the 25bps from swap transactions. The attacker used this feature to withdraw funds (known as fees) from the pool vault. After initiating drawPNL, need_take_pc and need_take_coin are calculated automatically reset to zero.
  2. The attacker used the SetParams Instruction combined with AmmParams::SyncNeedTake to inflate the balances for need_take_pc and need_take_coin without the need for trading volume to occur, allowing the attacker to do so change and increase the expected fees and then Withdrawing the funds (referred to as fees) from the pool vault via withdrawPNL, repeated.

On December 16, 2022 at 14:16 UTC, Raydium deployed a hot patch or stub, also known as a controllable replacement for an existing dependency for all programs. In other words, the compromised account (HggGrUeg4ReGvpPMLJMFKV69NTXL1r4wQ9Pk9Ljutwyv) had its authority revoked and upgraded to a new account held on a hardware wallet.

This patch stripped the attacker of the authority and ability to further exploit the pools.

December 17, 10:27 UTC: The Raydium AMM V4 program has been updated via Squads Multisig to remove unnecessary management parameters that could potentially impact funds if compromised.

The following parameters have been removed:

  • AmmParams::MinSize
  • AmmParams::SyncLp
  • AmmParams::SetLpSupply
  • AmmParams::SyncK
  • AmmParams::SyncNeedTake

Also, all admin parameters have been removed for:

  • Raydium stall pools
  • Raydium Accelerator
  • Raydium DropZone

All remaining management parameters, including the RetractPNL feature, were updated at approximately 15:00 UTC on Dec 17 to the Squads multisig currently used for program upgrades.

Raydium is approaching the next steps on two fronts at once:

  1. Pinpointing the exploit’s impact on user LP balance pools

Raydium creates snapshots and collects data for all LP balances and the corresponding position sizes before the hack and extrapolates the discrepancy of the original balances resulting from the exploit. Ensuring that an accurate balance account is determined is necessary to find an appropriate solution going forward. It will take time to get accurate information for all accounts and LP balances in the affected pools. Patience during this time is greatly appreciated.

2. Tracking attackers’ wallets and exploring options for returning funds

Raydium has been in contact with a number of Solana teams, third party auditors and central exchanges who have provided support and potential leads regarding the attacker and relevant accounts. While there is nothing definitive at the moment, evidence has surfaced linking the wallets involved in the exploit (as mentioned under “Background” above) to previous NFT fraud projects and malicious user wallet deletion. Raydium will continue to communicate with relevant teams and security experts to explore ways to retrieve funds.

Raydium offers a 10% bonus in exchange for returning funds. Raydium offers the exploited RAY credit as an additional reward.

Much work remains to be done to assess the overall impact on each user’s LP balances and funds. While Raydium understands that all parties are concerned about the funds in question, time will be needed to gather data and information before all options for further action can be evaluated. Further details will be communicated as they become available.

If you have any relevant information about the attacker or the nature of this exploit, please connect via the Raydium Discord server.

Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers

Comments are closed.

%d bloggers like this: