Ultimate magazine theme for WordPress.

Raydium under attack, loses $2 million

Solana-based decentralized finance protocol Raydium has suffered an exploit, according to a statement from the developer. An initial investigation by the team revealed that the attacker had taken over the account of the exchange’s owner. The team said “authority” over the automated market-maker and farm programs has been paused “for now.”

An exploit on Raydium that affected liquidity pools is being investigated. Details will follow as soon as more is known

⁰Initial understanding is that ownership authority has been seized by the attacker, but authority for AMM and farm programs has been stopped for now
Attacker Accounthttps://t.co/ZnEgL1KSwz

— Raydium (@RaydiumProtocol) December 16, 2022

Twitter user and researcher ZachXBT reported that the attacker has bridged $2 million in Ethereum “so far.”

Then bridged to ETH (~$2 million so far)https://t.co/3OYxDThv7I

— ZachXBT (@zachxbt) December 16, 2022

At around 14:00 UTC on December 16, a Raydium admin account logged almost 1,000 transactions on the Solana network.

Each transaction removed liquidity from Raydium without depositing a corresponding LP token, effectively seizing liquidity provider funds. Various tokens were taken in the exploit, including US Dollar Coin (USDC), Wrapped SOL (wSOL), Raydium, and others.

Transactions from the admin wallet used in the attack. Source: Solscan.io

The exploit appears to have been first discovered by the Prism development team. They posted an alert at 2:01 am that an attacker was draining liquidity from Raydium without depositing and burning LP tokens. Prism warned its users to withdraw their Prism and USDC tokens from the exchange immediately.

There seems to be a wallet that drains LP pools from Raydium liquidity pools by using the admin wallet as a signer without having/burning LP tokens.

We have withdrawn the PRISM/USDC liquidity provided in the protocol from Raydium

WITHDRAW YOUR PRISM/USDC LIQUIDITY FROM RAYDIUM

— PRISM (@prism_ag) December 16, 2022

40 minutes later, the Raydium team took to Twitter to confirm that the exchange had been hacked.

According to crypto audit firm Ottersec, the attacker withdrew funds by calling the contract draw_pnl function, which is used by the developer to withdraw fees. The firm didn’t say whether this feature can be used to take all of the liquidity or just a small percentage from the pools.

Nansen Portfolio, a crypto analytics company, has confirmed that the attacker siphoned over $2.2 million from the exchange.

The wallet, which drains LP pools from Raydium liquidity pools, has now received over $2.2 million, including $1.6 million in SOL

Track here: https://t.co/IQedsOstPE pic.twitter.com/OAQJgaq5Mc

— Nansen Portfolio (@nansenportfolio) December 16, 2022

As of this writing, the Raydium team is still investigating the exploit and has not yet announced whether compensation will be offered to victims of the attack.

Admin account hacks have been a recurring problem in the crypto space lately. On December 2, the Ankr protocol deployer key was stolen and the attacker used it to remove $5 million worth of BNB. Earlier this year, the Ronin Network Bridge was similarly hacked. In this case, the attacker ran away with over $600 million worth of crypto loot.

Ankr has since compensated victims, and ronin developer Axie Infinity has promised to do the same.

Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers

Comments are closed.

%d bloggers like this: