{"id":38315,"date":"2022-12-16T18:11:35","date_gmt":"2022-12-16T18:11:35","guid":{"rendered":"http:\/\/egrowonline.com\/?p=38315"},"modified":"2022-12-16T18:11:35","modified_gmt":"2022-12-16T18:11:35","slug":"raydium-is-attacked-loses-2m","status":"publish","type":"post","link":"http:\/\/egrowonline.com\/?p=38315","title":{"rendered":"Raydium is attacked, loses $2M"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div data-v-30a6cf80=\"\">\n<p>Solana-based decentralized finance protocol Raydium has <a target=\"_blank\" href=\"https:\/\/twitter.com\/RaydiumProtocol\/status\/1603762271028748289\" rel=\"noopener nofollow\">suffered<\/a> an exploit, according to a statement from the developer. An initial investigation by the team revealed that the attacker took over the exchange\u2019s owner account. The team said that \u201cauthority\u201d over the automated market maker and farm programs has been paused \u201cfor now.\u201d<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">An exploit on Raydium is being investigated that affected liquidity pools. Details to follow as more is known<\/p>\n<p>\u2070Initial understanding is owner authority was overtaken by attacker, but authority has been halted on AMM &amp; farm programs for now<br \/>Attacker accnt<a target=\"_blank\" href=\"https:\/\/t.co\/ZnEgL1KSwz\" rel=\"noopener\">https:\/\/t.co\/ZnEgL1KSwz<\/a><\/p>\n<p>\u2014 Raydium (@RaydiumProtocol) <a target=\"_blank\" href=\"https:\/\/twitter.com\/RaydiumProtocol\/status\/1603762271028748289?ref_src=twsrc%5Etfw\" rel=\"noopener\">December 16, 2022<\/a><\/p><\/blockquote>\n<p>Twitter user and researcher ZachXBT <a target=\"_blank\" href=\"https:\/\/twitter.com\/zachxbt\/status\/1603758780528861185?s=20&amp;t=ezTPi7OyMkahFcFEZswweQ\" rel=\"noopener nofollow\">reported<\/a> that the attacker has bridged $2 million to Ethereum \u201cso far.\u201d<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Then bridged to ETH (~$2m so far)<a target=\"_blank\" href=\"https:\/\/t.co\/3OYxDThv7I\" rel=\"noopener\">https:\/\/t.co\/3OYxDThv7I<\/a><\/p>\n<p>\u2014 ZachXBT (@zachxbt) <a target=\"_blank\" href=\"https:\/\/twitter.com\/zachxbt\/status\/1603758780528861185?ref_src=twsrc%5Etfw\" rel=\"noopener\">December 16, 2022<\/a><\/p><\/blockquote>\n<p>Around 2 p.m. UTC on Dec. 16, a Raydium admin account <a target=\"_blank\" href=\"https:\/\/solscan.io\/account\/AgJddDJLt17nHyXDCpyGELxwsZZQPqfUsuwzoiqVGJwD#splTransfers\" rel=\"noopener nofollow\">posted<\/a> nearly 1,000 transactions to the Solana network.<\/p>\n<p>Each transaction removed liquidity from Raydium without depositing a corresponding LP token, effectively seizing possession of liquidity providers\u2019 funds. A variety of tokens were taken in the exploit, including US Dollar Coin (USDC), Wrapped SOL (wSOL), Raydium, and others.<\/p>\n<figure><img decoding=\"async\" src=\"https:\/\/s3.cointelegraph.com\/uploads\/2022-12\/d25b124f-16d7-46a1-9bf6-c7d81e68756a.png\" \/><figcaption style=\"text-align: center\">Transactions from the admin wallet that was used in the attack. Source: Solscan.io<\/figcaption><\/figure>\n<p>The exploit appears to have first been discovered by the Prism dev team. They posted a warning at 2:01 that an attacker was draining liquidity from Raydium without depositing and burning LP tokens. Prism warned its users to withdraw their Prism and USDC tokens from the exchange immediately. <\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">There seems to be a wallet is draining LP Pools from Raydium liquidity pools using admin wallet as a signer without having\/burning LP tokens.<\/p>\n<p>We withdrew protocol provided PRISM\/USDC liquidity from Raydium<\/p>\n<p>WITHDRAW YOUR PRISM\/USDC LIQUIDITY FROM RAYDIUM<\/p>\n<p>\u2014 PRISM (@prism_ag) <a target=\"_blank\" href=\"https:\/\/twitter.com\/prism_ag\/status\/1603752282083950592?ref_src=twsrc%5Etfw\" rel=\"noopener\">December 16, 2022<\/a><\/p><\/blockquote>\n<p>40 minutes later, the Raydium team took to Twitter to confirm that the exchange had been hacked.<\/p>\n<p>According to crypto auditing firm Ottersec, the attacker has drained funds by <a target=\"_blank\" href=\"https:\/\/twitter.com\/osec_io\/status\/1603763028775747584\" rel=\"noopener nofollow\">invoking<\/a> the withdraw_pnl function on the contract, which is used by the developer to withdraw fees. The firm did not say whether this function can be used to withdraw all liquidity or only a small percentage from the pools.<\/p>\n<p>Nansen Portfolio, a crypto analytics firm, has confirmed that the attacker drained over $2.2 million from the exchange.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">The wallet draining LP Pools from Raydium liquidity pools has received over $2.2M now, including $1.6M <a target=\"_blank\" href=\"https:\/\/twitter.com\/search?q=%24SOL&amp;src=ctag&amp;ref_src=twsrc%5Etfw\" rel=\"noopener\">$SOL<\/a><\/p>\n<p>Track here: <a target=\"_blank\" href=\"https:\/\/t.co\/IQedsOstPE\" rel=\"noopener\">https:\/\/t.co\/IQedsOstPE<\/a> <a target=\"_blank\" href=\"https:\/\/t.co\/OAQJgaq5Mc\" rel=\"noopener\">pic.twitter.com\/OAQJgaq5Mc<\/a><\/p>\n<p>\u2014 Nansen Portfolio (@nansenportfolio) <a target=\"_blank\" href=\"https:\/\/twitter.com\/nansenportfolio\/status\/1603762024667746305?ref_src=twsrc%5Etfw\" rel=\"noopener\">December 16, 2022<\/a><\/p><\/blockquote>\n<p>At the time of writing, the Raydium team is still investigating the exploit and has not yet announced whether compensation will be offered to victims of the attack.<\/p>\n<p>Admin account hacks have been a recurring problem in the crypto space recently. On Dec. 2, Ankr protocol\u2019s <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/ankr-confirms-exploit-asks-for-immediate-trading-halt\" data-amp=\"https:\/\/cointelegraph-com.cdn.ampproject.org\/c\/s\/cointelegraph.com\/news\/ankr-confirms-exploit-asks-for-immediate-trading-halt\/amp\" rel=\"noopener\">deployer key was stolen<\/a>, and the attacker used it to remove $5 million worth of BNB. Earlier in the year, the Ronin network bridge was <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/axie-infinity-s-ronin-bridge-hacked-for-over-600m\" data-amp=\"https:\/\/cointelegraph-com.cdn.ampproject.org\/c\/s\/cointelegraph.com\/news\/axie-infinity-s-ronin-bridge-hacked-for-over-600m\/amp\" rel=\"noopener\">hacked by similar means<\/a>. In this case, the attacker ran off with over $600 million of crypto loot. <\/p>\n<p>Ankr has since <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/ankr-deploys-15m-to-make-whole-users-as-helio-stablecoin-recovers-after-exploit\" data-amp=\"https:\/\/cointelegraph-com.cdn.ampproject.org\/c\/s\/cointelegraph.com\/news\/ankr-deploys-15m-to-make-whole-users-as-helio-stablecoin-recovers-after-exploit\/amp\" rel=\"noopener\">reimbursed victims<\/a>, and Ronin developer Axie Infinity has pledged that it <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/axie-infinity-to-compensate-ronin-exploit-victims-and-relaunch-bridge\" data-amp=\"https:\/\/cointelegraph-com.cdn.ampproject.org\/c\/s\/cointelegraph.com\/news\/axie-infinity-to-compensate-ronin-exploit-victims-and-relaunch-bridge\/amp\" rel=\"noopener\">will do the same<\/a>.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/cointelegraph.com\/news\/raydium-is-attacked-loses-2-million\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Solana-based decentralized finance protocol Raydium has suffered an exploit, according to a statement from the developer. An initial investigation by the team revealed that the attacker took over the exchange\u2019s owner account. The team said that \u201cauthority\u201d over the automated market maker and farm programs has been paused \u201cfor now.\u201d An exploit on Raydium is [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":38316,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false}}},"categories":[38],"tags":[12871,774,12870],"class_list":["post-38315","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blockchain","tag-attacked","tag-loses","tag-raydium"],"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"http:\/\/egrowonline.com\/wp-content\/uploads\/2022\/12\/e25e1397-90fb-40c9-9c83-61bdcaeba6f0.jpg","_links":{"self":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/38315","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=38315"}],"version-history":[{"count":1,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/38315\/revisions"}],"predecessor-version":[{"id":38317,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/38315\/revisions\/38317"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/media\/38316"}],"wp:attachment":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=38315"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=38315"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=38315"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}