DeFi protocol Raydium fell victim to a liquidity pool exploit on Friday. The attack appears to have put about $2 million in funds at risk.
Their initial understanding is that the attacker has taken over the exchange’s admin account. The Solana-based log states that “authority” over automated market-maker and farm programs has now been temporarily frozen.
Following these events, Raydium has now published a list of affected wallets.
Also, the suspicious activity began when a Raydium admin account removed significant liquidity from the log. In all, there were nearly 1,000 transactions on the Solana network that didn’t replace it with the required LP token.
Prism identified the attack
Essentially, this means that the liquidity provider’s funds have been stolen. Potential compromise to the viability of the log. The attacker took a variety of tokens including US Dollar Coins (USDC), Wrapped SOL (wSOL) and Raydium.
An exploit on Raydium that affected liquidity pools is being investigated. Details will follow as soon as more is known
⁰Initial understanding is that ownership authority has been seized by the attacker, but authority for AMM and farm programs has been stopped for now
Attacker Accounthttps://t.co/ZnEgL1KSwz
— Raydium (@RaydiumProtocol) December 16, 2022
Fortunately, the Prism team was able to quickly identify the attack. At 14:01 UTC, they alerted the community that someone was draining liquidity from Raydium without properly storing or burning LP tokens.
In response, Prism immediately warned its users to withdraw their Prism and USDC tokens from the decentralized exchange as a precaution. Overall, the team’s quick action and communication helped mitigate the potential impact of the attack.
Raydium then confirmed the attack at 14:41 UTC.
🚨🚨🚨🚨🚨
There seems to be a wallet that drains LP pools from Raydium liquidity pools by using the admin wallet as a signer without having/burning LP tokens.
We have withdrawn the PRISM/USDC liquidity provided in the protocol from Raydium
WITHDRAW YOUR PRISM/USDC LIQUIDITY FROM RAYDIUM
— PRISM (@prism_ag) December 16, 2022
The “post mortem”
According to the protocol’s official Twitter account, Raydium is investigating alongside teams from Solana and external auditors. As of 21:12 UTC, Raydium has implemented a patch covering their vulnerability.
1/ First Autopsy: Raydium is working with third party examiners and teams across Solana to gather additional information. A patch is now available that prevents further exploits by the attacker.
The following contains information so far. A big thank you to all teams providing support https://t.co/yKRdA6BAqv
— Raydium (@RaydiumProtocol) December 16, 2022
After the attack became public, the protocol took immediate action by revoking the previous owner’s rights and replacing “all program accounts with new hard wallet accounts.” In addition, the protocol has assured users that it effectively neutralized the attacker’s threat to the system’s liquidity. Overall, the protocol has taken swift and decisive action to protect its users and restore trust in the system.
Raydium has asked the perpetrator to return all funds in exchange for a “white hat bug bounty”. The attacker can contact through the “normal channels” or via the address:
0x6d3078ED15461E989fbf44aE32AaF3D3Cfdc4a90
Disclaimer
BeInCrypto has reached out to companies or individuals involved in the story for an official statement on recent developments, but has yet to receive a response.
Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers
Comments are closed.