Raydium Old Liquidity Pool Reportedly Exploited, With $1.34 Million Moved to Ethereum and Tornado Cash

By: WEEX|2026/06/11 00:30:22
0
Share
copy

On June 3, according to Foresight News citing on-chain investigator Specter, an old liquidity pool linked to Solana DeFi protocol Raydium was suspected of being exploited. The attacker reportedly stole around $1.34 million in assets, involving USDC, RAY, and wSOL.

Based on the currently disclosed on-chain path, the funds were later bridged to Ethereum and deposited into Tornado Cash. The incident is still being described as a suspected attack. At this stage, there has not yet been a complete public explanation from Raydium confirming the nature of the incident, the exact status of the affected pool, or the scope of user impact.

Based on the available information, the affected target does not appear to refer to all Raydium protocol assets, but rather a specific old liquidity pool. This distinction is important for understanding the potential spread of risk.

If the issue was limited to a legacy or low-activity pool, the impact may be concentrated among that pool and its corresponding liquidity providers. However, if the incident is later found to involve main routing, front-end calls, permission settings, or shared infrastructure, the scope of investigation could widen.

At present, the public information can only confirm the reported loss size, the stolen asset types, and the movement of funds. It is not enough to determine whether there were deeper contract-level or operational security issues.

After stealing the assets on Solana, the attacker quickly bridged the funds to Ethereum and then deposited them into Tornado Cash. This type of exit path usually makes later tracking, freezing, and recovery more difficult.

For the market, the direct impact of this type of event may not necessarily be a full protocol shutdown. The more important effect is that users may reprice risks around old pools, abandoned pools, and legacy contracts. Since more official disclosure is still missing, the market will need to watch Raydium’s technical explanation, details of the affected pool, and whether any remediation measures are introduced.


Why It Matters

The focus of this incident is not only the size of the loss. More importantly, it once again highlights the tail risk of old asset pools and historical deployments in DeFi protocols.

Even if a core protocol continues to upgrade, early pools, older contracts, or leftover permission settings can still become attack surfaces. For a leading liquidity infrastructure project in the Solana ecosystem, this type of incident can directly affect liquidity providers’ risk appetite toward non-core pools. It may also push projects to clean up legacy pools and front-end access points more aggressively.

Another important issue is the fund flow. The stolen assets were bridged to Ethereum and sent to Tornado Cash, suggesting that the attacker had a mature exit route. For law enforcement cooperation, exchange risk control, and on-chain tracking teams, the next focus is not only attribution, but also whether tainted funds may re-enter CEXs, aggregators, or OTC channels.


WEEX View

The core question is not simply whether Raydium was hacked. The real issue is whether Raydium can isolate the incident as a single old-pool accident.

If the project later confirms that only an abandoned pool or low-TVL historical position was affected, the market may price the incident as an edge risk, and liquidity in major trading pairs may not be significantly damaged. But if the investigation points to front-end routing, pool migration logic, permission management, or shared market-making components, then this would no longer be a one-off bad debt event. It could trigger a broader repricing of older liquidity infrastructure across Solana.

For front-line CEX businesses, the most practical indicators are RAY-related spot depth, on-chain deposit and withdrawal patterns, and whether the stolen funds follow a typical laundering path of theft, bridging, mixing, small-value splitting, and re-entry into exchanges.

The commercial interests of the project team, on-chain investigators, bridge protocols, and centralized exchanges are not fully aligned. The project team has an incentive to narrow the incident to an old pool in order to protect core pools and brand confidence. Bridge and downstream protocols are more concerned about being labeled as laundering channels. CEX risk teams need to determine whether tainted addresses could enter deposit systems, affecting asset deposit efficiency and market maker inventory allocation.

If this firewall fails, the issue may move beyond a single pool security incident. It could become a broader problem involving cross-chain tainted fund identification, a liquidity discount for RAY spot markets, and rising risk premiums for long-tail Solana DeFi assets.

The next three variables are the most important to watch. First, whether Raydium discloses the affected pool address and confirms whether related access points have been removed. Second, whether the stolen funds continue to be split, swapped, or routed back toward centralized platforms. Third, whether market makers actively reduce inventory exposure in RAY, wSOL, or related long-tail trading pairs.

If these details remain unclear, the market may default to pricing in a worse-case scenario. Legacy pool assets could be marginalized first, while arbitrage boundaries narrow quickly.

-- Price

--

You may also like

Morning Report | OpenAI has submitted an S-1 registration statement draft to the U.S. SEC; Morpho completes $175 million financing

Overview of Important Market Events on June 9th

Galaxy Deep Research Report: How Hyperliquid's HIP-4 Upgrade Changes the Landscape of Prediction Markets?

The platform that wins this competition will be the one whose execution layer is the hardest to replicate, whose builder ecosystem delivers the fastest, and whose regulatory path is the most open.

Latest research from 13 top universities including Cornell University: The current state, challenges, and misconceptions of the fusion of Crypto and AI

The combination of AI and crypto is still in its early stages, with both serving as complementary "middleware": AI translates human intentions into executable programs, while cryptographic technology provides verifiable and tamper-proof guarantees for computational processes and results. In the dire...

Deconstructing Anthropic: The Best AI Company, Possibly Also a Type of Organizational Invention

Instead of competing with ambition, focusing on restraint, how does Anthropic leverage extreme strategic focus and an "counterintuitive" geek culture to counterattack OpenAI on the AI battlefield?

Every exchange is a "Universal Exchange."

You initially build infrastructure for something, then realize it can also be used for many other things, and then you continuously expand the business to accommodate everything that the infrastructure can support.

The counterattack of traditional finance: Alliance chains are quietly reviving

Whether public chains win or consortium chains win has never been the focus.

Popular coins

Latest Crypto News

Read more
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com