Solana-based decentralized finance protocol Raydium has suffered an exploit, according to a statement from the developer. An initial investigation by the team revealed that the attacker had taken over the account of the exchange’s owner. The team said “authority” over the automated market-maker and farm programs has been paused “for now.”
An exploit on Raydium that affected liquidity pools is being investigated. Details will follow as soon as more is known
⁰Initial understanding is that ownership authority has been seized by the attacker, but authority for AMM and farm programs has been stopped for now
Attacker Accounthttps://t.co/ZnEgL1KSwz
— Raydium (@RaydiumProtocol) December 16, 2022
Twitter user and researcher ZachXBT reported that the attacker has bridged $2 million in Ethereum “so far.”
Then bridged to ETH (~$2 million so far)https://t.co/3OYxDThv7I
— ZachXBT (@zachxbt) December 16, 2022
At around 14:00 UTC on December 16, a Raydium admin account logged almost 1,000 transactions on the Solana network.
Each transaction removed liquidity from Raydium without depositing a corresponding LP token, effectively seizing liquidity provider funds. Various tokens were taken in the exploit, including US Dollar Coin (USDC), Wrapped SOL (wSOL), Raydium, and others.
Transactions from the admin wallet used in the attack. Source: Solscan.io
The exploit appears to have been first discovered by the Prism development team. They posted an alert at 2:01 am that an attacker was draining liquidity from Raydium without depositing and burning LP tokens. Prism warned its users to withdraw their Prism and USDC tokens from the exchange immediately.
There seems to be a wallet that drains LP pools from Raydium liquidity pools by using the admin wallet as a signer without having/burning LP tokens.
We have withdrawn the PRISM/USDC liquidity provided in the protocol from Raydium
WITHDRAW YOUR PRISM/USDC LIQUIDITY FROM RAYDIUM
— PRISM (@prism_ag) December 16, 2022
40 minutes later, the Raydium team took to Twitter to confirm that the exchange had been hacked.
According to crypto audit firm Ottersec, the attacker withdrew funds by calling the contract draw_pnl function, which is used by the developer to withdraw fees. The firm didn’t say whether this feature can be used to take all of the liquidity or just a small percentage from the pools.
Nansen Portfolio, a crypto analytics company, has confirmed that the attacker siphoned over $2.2 million from the exchange.
The wallet, which drains LP pools from Raydium liquidity pools, has now received over $2.2 million, including $1.6 million in SOL
Track here: https://t.co/IQedsOstPE pic.twitter.com/OAQJgaq5Mc
— Nansen Portfolio (@nansenportfolio) December 16, 2022
As of this writing, the Raydium team is still investigating the exploit and has not yet announced whether compensation will be offered to victims of the attack.
Admin account hacks have been a recurring problem in the crypto space lately. On December 2, the Ankr protocol deployer key was stolen and the attacker used it to remove $5 million worth of BNB. Earlier this year, the Ronin Network Bridge was similarly hacked. In this case, the attacker ran away with over $600 million worth of crypto loot.
Ankr has since compensated victims, and ronin developer Axie Infinity has promised to do the same.
Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers
Comments are closed.