News

Raydium Announced A Detailed Post-Mortem Of Hack

As Coincu reported, Raydium experienced an attack caused by the private key leak of the fund pool owner accounts. Now the patch has been applied and the platform is looking to recover the tokens. The project also announced details of the aftermath and upcoming plans for restoration.

On December 16, 2022, a malicious actor used the Pool Owner account to start an exploit on the authoritative account of the Raydium Liquidity Pool V4. OtterSec, a blockchain audit company, also published a description of the attack.

The aforementioned Pool Owner account was first set up on a virtual machine with a separate internal server. Additional investigation has revealed that there is currently no proof that the Pool Owner account’s private key has ever been passed, shared, moved, or kept locally outside of the virtual machine where it was first installed.

According to the Raydium team, an attacker can gain control of a remote server leading to a trojan attack is possible.

“Initial suspicions are that the attacker may have gained remote access to the virtual machine or internal server where the account was deployed. The exact intrusion vector has yet to be identified, but a trojan attack may be one possibility.”

The Raydium exploiter account appears to be involved in additional illicit conduct on Solana, according to a preliminary examination. A tweet from cloudzy.sol on November 7 detailing a wallet to exploit totaling 198 SOL that ultimately ended up in the same account that paid the principal Raydium exploiter wallet as described in the initial post-mortem tweet is one indicator of this.

Eight continuous product liquidity pools on Raydium were compromised, and a total of about $4.4 million in funds were taken. The exploit did not impact RAY staking programs or concentrated liquidity pools. The exploit had no impact on any other pool or funds on Raydium.

In order to effectively assess the impact of the exploit on the pools for user LP balances and track attacker wallets, Raydium is simultaneously pursuing possibilities for the repatriation of cash.

The team acknowledged that the monies in question are causing anxiety for all parties but added that more time was needed to gather data and information in order to evaluate all possible future courses of action. As more information becomes available, it will be announced.

DISCLAIMER: The Information on this website is provided as general market commentary and does not constitute investment advice. We encourage you to do your own research before investing.

Join us to keep track of news: https://linktr.ee/coincu

Website: coincu.com

Harold

Coincu News

Harold

With a passion for untangling the complexities of the financial world, I've spent over four years in financial journalism, covering everything from traditional equities to the cutting edge of venture capital. "The financial markets are a fascinating puzzle," I often say, "and I love helping people make sense of them." That's what drives me to bring clear and insightful financial journalism to the readers of Coincu.

Recent Posts

Monad Testnet Begins Rolling Out On Ethereum-Compatible Layer 1

Monad testnet begins phased rollout, delivering up to 10,000 TPS with Ethereum compatibility, optimizing throughput,…

20 minutes ago

Top 3 Altcoins Set to Skyrocket by Year-End – Don’t Miss Out on These Crypto Gem

As the year-end approaches, the spotlight shifts to altcoins poised for significant growth.

21 minutes ago

Starknet v0.13.3 Is Expected To Be Launched Mainnet This Week

Starknet v0.13.3 update cuts blob gas costs to one-fifth, reducing fees for users and improving…

57 minutes ago

MARA Private Offering Of $700M Convertible Senior Notes

MARA Holdings, Inc. announces a $700M MARA Private Offering of convertible senior notes due 2030…

1 hour ago

Plutus Announces Platform Enhancements to Bolster Transparency and Sustainability

London, United Kingdom, 18th November 2024, Chainwire

1 hour ago

This website uses cookies.