{"id":42533,"date":"2022-12-22T14:11:48","date_gmt":"2022-12-22T18:11:48","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=42533"},"modified":"2022-12-22T14:11:51","modified_gmt":"2022-12-22T18:11:51","slug":"raydium-discloses-hack-details-compensation-plan","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/raydium-discloses-hack-details-compensation-plan\/","title":{"rendered":"Raydium Discloses Hack Details, Compensation Plan"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\" id=\"h-raydium-team-has-disclosed-the-details-of-the-hack-on-the-protocol-that-took-place-and-has-offered-a-compensation-plan-for-all-affected-users\">Raydium team has disclosed the <a href=\"https:\/\/coinscreed.com\/staging\/ankr-protocol-hack-trader-allegedly-sees-over-5000x-gains.html\" target=\"_blank\" rel=\"noreferrer noopener\">details of the hack on the protocol<\/a> that took place  and has offered a compensation plan for all affected users.<\/h5>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/12\/jpg_20221222_185334_0000-1024x576.jpg\" alt=\"Raydium Discloses Hack Details, Compensation Plan\" class=\"wp-image-42535\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/12\/jpg_20221222_185334_0000-1024x576.jpg 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/12\/jpg_20221222_185334_0000-300x169.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/12\/jpg_20221222_185334_0000-768x432.jpg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/12\/jpg_20221222_185334_0000-150x84.jpg 150w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/12\/jpg_20221222_185334_0000-750x422.jpg 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/12\/jpg_20221222_185334_0000-1140x641.jpg 1140w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/12\/jpg_20221222_185334_0000.jpg 1200w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Raydium Discloses Hack Details, Compensation Plan<\/figcaption><\/figure>\n\n\n\n<p>The <a href=\"https:\/\/coinscreed.com\/staging\/solana-based-dex-orca-partners-with-stripe-for-fiat-transactions.html\" target=\"_blank\" rel=\"noreferrer noopener\">Raydium decentralized exchange<\/a> (DEX) team has disclosed specifics regarding the incident that happened on December 16 and has put forth a suggestion to make amends for victims.<\/p>\n\n\n\n<p>According to a team forum post, the hacker was able to escape with more than $2 million in cryptocurrency loot by taking advantage of a flaw in the DEX's smart contracts that allowed administrators to withdraw entire liquidity pools despite existing safeguards being intended to prevent such behavior.<\/p>\n\n\n\n<p>In order to recompense victims who lost Raydium tokens, also known as RAY, the team will utilize its own unlocked tokens. However, the developer lacks the stablecoin and other <a href=\"https:\/\/coinscreed.com\/staging\/coinbase-introduces-recovery-tool-for-lost-erc-20-tokens.html\" target=\"_blank\" rel=\"noreferrer noopener\">non-RAY tokens<\/a> necessary to compensate victims, therefore it is requesting a vote from RAY holders to utilize the DAO treasury to purchase the necessary tokens and recompense people harmed by the exploit.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">1\/ Update on remediation of funds for recent exploit <br><br>First, thanks for everyone&#39;s patience up to now<br><br>An initial proposal on a way forward has been posted for discussion. Raydium encourages and appreciates all feedback on the proposal.<a href=\"https:\/\/t.co\/NwV43gEuI9\" target=\"_blank\">https:\/\/t.co\/NwV43gEuI9<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a><\/p>&mdash; Raydium (@Raydium) <a href=\"https:\/\/twitter.com\/Raydium\/status\/1605531145130504197?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">December 21, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>An admin pool private key was taken over by the attacker as part of the vulnerability, according to a different post-mortem report. The team does not know how this key was obtained, but it has a <a href=\"https:\/\/www.google.com\/search?q=Raydium+Discloses+Hack+Details%2C+Compensation+Plan&oq=Raydium+Discloses+Hack+Details%2C+Compensation+Plan&aqs=chrome..69i57j33i160l2.786j0j7&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noreferrer noopener\">suspicion that a trojan application was installed<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> on the virtual computer that housed the key.<\/p>\n\n\n\n<p>Once they got the key, the assailant called a function to remove transaction fees that would typically be sent to the DAO's treasury to be used for RAY buybacks.<\/p>\n\n\n\n<p>Transaction fees on Raydium do not always go to the Treasury when a swap occurs. Instead, they hang out in the pool of the liquidity provider until an admin takes them out. <\/p>\n\n\n\n<p>However, the smart contract uses parameters to keep track of the fees owing to the DAO. The attacker shouldn't have been able to withdraw more than 0.03% of the entire trading volume that had taken place in each pool since the last withdrawal because of this.<\/p>\n\n\n\n<p>However, the attacker was able to manually alter the parameters due to a contract fault, giving the impression that the whole liquidity pool was made up of transaction fees. <\/p>\n\n\n\n<p>The attacker was able to take all of the money as a result. After the money was taken out, the hacker was able to manually exchange it for other tokens and then send the money to other wallets that were under his or her control.<\/p>\n\n\n\n<p>The team has updated the app's smart contracts in response to the exploit to eliminate admin control over the parameters that were misused by the attacker. The developers put up a strategy to make amends for attack victims in the forum post on December 21.<\/p>\n\n\n\n<p>To recompense RAY holders who lost their tokens as a result of the attack, the team will utilize its own unlocked RAY tokens. It has requested a forum discussion on how to carry out a <a href=\"https:\/\/coinscreed.com\/staging\/first-official-dao-in-the-u-s-to-fight-sec-without-attorneys.html\" target=\"_blank\" rel=\"noreferrer noopener\">compensation plan that uses the DAO's treasury<\/a> to pay for lost non-RAY tokens.<\/p>\n\n\n\n<p>The group is requesting that the matter be decided after a three-day deliberation. On December 16, the $2 million Raydium hack became known. Initial reports claimed that the attacker had removed liquidity from pools without depositing LP tokens via the withdraw_pnl function.<\/p>\n\n\n\n<p> However, since the attacker should only have been able to withdraw transaction fees using this function, it wasn't until after an investigation had been done that it became clear how they were actually able to drain entire pools.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Raydium team has disclosed the details of the hack on the protocol that took place and has offered a compensation plan for all affected users. The Raydium decentralized exchange (DEX) team has disclosed specifics regarding the incident that happened on December 16 and has put forth a suggestion to make amends for victims. According to [&hellip;]<\/p>\n","protected":false},"author":43,"featured_media":42535,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476,73],"tags":[197,12002],"class_list":["post-42533","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","category-defi-news","tag-defi","tag-hacks"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/12\/jpg_20221222_185334_0000.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/42533","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/43"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=42533"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/42533\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/42535"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=42533"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=42533"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=42533"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}