Ultimate magazine theme for WordPress.

Raydium Protocol Suffers $2 Million Liquidity Pool Attack

The DeFi Raydium protocol fell victim to a liquidity pool exploit on Friday. The attack appears to have compromised about $2 million in funds.

According to their initial insights, the attacker took over the admin account of the exchange. The Solana-based protocol states that “authority” over automated market makers and farming programs has now been temporarily frozen.

Following these events, Raydium published a list of affected wallets.

Additionally, the suspicious activity began when a Raydium admin account drained significant liquidity from the log. In total, there were almost 1,000 transactions on the Solana network that were not replaced with the necessary LP token.

Prism has identified the attack

Essentially, this means that the liquidity provider’s funds have been stolen. Compromise the viability of the protocol. The attacker captured various tokens including the United States Dollar Coin (USDC), Wrapped SOL (wSOL), and Raydium.

An exploit in Raydium affecting liquidity pools is under investigation. Details will follow as soon as more is known

⁰Initial findings assume that the attacker has overridden the owner’s authority, but authority has been halted at the AMM and agrarian programs for now
Attacker Accounthttps://t.co/ZnEgL1KSwz

— Raydium (@RaydiumProtocol) December 16, 2022

Fortunately, the Prism team was able to quickly identify the attack. At 14:01 UTC, they alerted the community that someone was draining Raydium’s liquidity without properly storing or burning LP tokens.

In response, Prism immediately warned its users to remove their Prism and USDC tokens from the decentralized exchange as a precaution. Overall, the team’s quick action and communication helped mitigate the potential impact of the attack.

After that, Raydium confirmed the attack at 14:41 UTC.

🚨🚨🚨🚨🚨
It seems there is a wallet that withdraws LP funds from Raydium liquidity pools by using the admin wallet as a signer without having/burning LP tokens.

We’re releasing the protocol that provides PRISM/USDC liquidity from Raydium

WITHDRAW YOUR PRISM/USDC LIQUIDITY FROM RAYDIUM

— PRISM (@prism_ag) December 16, 2022

The “post mortem”

According to the protocol’s official Twitter account, Raydium is conducting investigations along with Solana teams and external auditors. At 21:12 UTC, Raydium deployed a patch covering the vulnerability.

1/ First Postmortem: Raydium is working with external auditors and teams at Solana to gather additional information. As of now, there is a patch that prevents the attacker from performing further attacks.

Below is previous information. Thank you to all the teams that support us. https://t.co/yKRdA6BAqv

— Raydium (@RaydiumProtocol) December 16, 2022

After the attack became public, the protocol took immediate action, stripping the previous owner of privileges and replacing “all program accounts with new hard wallet accounts.” Furthermore, the protocol has assured users that it effectively neutralized the attacker’s threat to system liquidity. Overall, the protocol has taken swift and decisive action to protect its users and restore trust in the system.

Raydium has asked the perpetrator to return all funds in exchange for a “white hat bug bounty”. The attacker can contact through the “normal channels” or via the address:

0x6d3078ED15461E989fbf44aE32AaF3D3Cfdc4a90

Disclaimer

BeInCrypto has reached out to the company or person involved in the story for an official statement on the recent developments, but has yet to receive a response.

Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers

Comments are closed.

%d bloggers like this: