On June 10, 2026, a hacker exploited five stale liquidity pools on Raydium, Solana’s largest decentralized exchange, draining approximately $1.34 million in crypto assets through a counterfeit LP token attack on the protocol’s legacy AMM V3 program.
The stolen funds included approximately $900,000 in USDC, approximately $357,000 in SOL, and approximately $86,000 in RAY tokens. The RAY token rose 2% in the 24 hours following the incident, recently changing hands at $0.578, already down about 7% for the week and sitting 96.6% below its all-time high of $16.83.
Raydium confirms $1.34M exploit on legacy AMM V3 pools. No current users are affected; full compensation from the Treasury. pic.twitter.com/tqmKATA2tH
– Solana Hub (@SolanaHub_) June 10, 2026
EXCLUSIVE: Earn $10 USDC via Binance Signup
Solana Raydium Exploit Explained: How a Fake Token Tricked a Withdrawn Smart Contract
Think of it like a disused bank branch that closed its doors to customers years ago, but whose management forgot to take the money out of the safe. The tellers have left, the ATM is turned off, the branch no longer appears on the bank’s website. But if someone found a side door still unlocked, the money inside would be just as real as ever.
That’s almost exactly what happened here. Raydium functions as an AMM, an automated market maker, meaning it uses liquidity pools managed by smart contracts instead of traditional order books to facilitate trading on Solana. In 2021, Raydium phased out its legacy AMM V3 program after Serum’s backlog depreciated, replacing it with an updated architecture. The old program was removed from the user interface, but the underlying smart contract and the funds contained within it remained online.

The attacker discovered a smart contract vulnerability in this existing code: the AMM V3 program did not properly validate the LP mint address, the token that represents a liquidity provider’s share of a pool. By creating a fake LP token and presenting it to the contract, the hacker convinced the program’s internal accounting that their counterfeit tokens represented legitimate pool property. The contract then allowed them to withdraw the actual assets from the pools as if it were a real LP buying back a position.
In five pools, Sollet USDT-RAY, Sollet ETH-RAY, SRM-RAY, USDC-RAY and RAY-SOL, the attacker withdrew ~150,177 RAY, ~5,603 SOL and ~893,700 USDC. After the liquidity pool hack, the funds were transferred from Solana to Ethereum and deposited into Tornado Cash, a crypto mixer that interrupts the path of on-chain transactions, an increasingly common laundering pattern in DeFi exploits of 2026. The attacker’s Solana address (ending in Bq33QVk) was initially funded through KuCoin.
EXCLUSIVE: Earn $10 USDC via Binance Signup
The structural story: why retired code still held live funds
The most important thing to understand about this DeFi exploit is what “obsolete” actually means on a public blockchain, and what it does not mean. When a protocol deprecates a program, it typically stops directing users to it through the interface and focuses development attention elsewhere.
What it almost never does automatically is freeze contract status or migrate funds out of old pools.
On Solana, on Ethereum, and virtually every other smart contract platform, a deployed program remains callable by anyone who knows its address, whether or not it appears on a front end. Unless a protocol explicitly suspends the contract, burns its upgrade authority, or migrates all liquidity, the code continues to run.
Raydium’s old AMM V3 was invisible to everyday users for four years, but it was never grounded. This is the structural gap that this feat crossed.
Raydium is aware of an exploit involving the unauthorized removal of liquidity from its legacy AMM V3 program, which was previously deleted in 2021.
No current Raydium users are affected by this exploit or could have interacted with these pools through the UI since…
— Infra | Raydium (@0xINFRA) June 10, 2026
Pseudonymous Raydium contributor 0xInfra confirmed that the exploit was “a standalone logical flaw” in the old program, not a key compromise or authority level issue, meaning that Raydium’s current mainnet programs have no equivalent vulnerabilities.
But the broader implication is uncomfortable: How many other DeFi protocols running on Solana or other chains have depreciated contracts quietly holding dormant liquidity that was never formally migrated or frozen? This incident suggests that number may be higher than anyone has audited.
The Solana ecosystem has evolved rapidly, but existing infrastructure can lag far behind governance decisions.
DISCOVER: The 12+ Most Popular Crypto Presales to Buy Now
Follow 99Bitcoins on X for the latest market updates and subscribe on YouTube for daily market analysis from experts.
The post Solana Raydium DEX Lost $1.34 Million to Hackers, Here’s What Really Happened appeared first on 99Bitcoins.



Raydium confirms $1.34M exploit on legacy AMM V3 pools. No current users are affected; full compensation from the Treasury.