• BTC Dominance: %
XBT.Market
Advertisement
  • Home
  • Coins MarketCap
  • Crypto Exchanges
  • Crypto Calculator
  • Top Gainers and Loser
  • News
  • Contact Us
No Result
View All Result
XBT.Market
No Result
View All Result
Home Bitcoin

Raydium announces details of hack, proposes compensation for victims

Jon Hartney by Jon Hartney
December 21, 2022
in Bitcoin, Blockchain, Business, Market
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

The attacker made use of an exploit that allowed entire liquidity pools to be withdrawn as “fees.”

The team behind the Raydium decentralized exchange (DEX) has announced details as to how the hack of Dec. 16 occurred and offered a proposal to compensate victims.

According to an official forum post from the team, the hacker was able to make off with over $2 million in crypto loot by exploiting a vulnerability in the DEX’s smart contracts that allowed entire liquidity pools to be withdrawn by admins, despite existing protections being to prevent such behavior. 

Related articles

Bitcoin derivatives data shows room for BTC price to move higher this week

January 23, 2023

Bitcoin price consolidation opens the door for APE, MANA, AAVE and FIL to move higher

January 22, 2023

The team will use its own unlocked tokens to compensate victims who lost Raydium tokens, also known as RAY. However, the developer does not have the stablecoin and other non-RAY tokens to compensate victims, so it is asking for a vote from RAY holders to use the decentralized autonomous organization (DAO) treasury to buy the missing tokens to repay those affected by the exploit.

1/ Update on remediation of funds for recent exploit

First, thanks for everyone's patience up to now

An initial proposal on a way forward has been posted for discussion. Raydium encourages and appreciates all feedback on the proposal.https://t.co/NwV43gEuI9

— Raydium (@RaydiumProtocol) December 21, 2022

According to a separate post-mortem report, the attacker’s first step in the exploit was to gain control of an admin pool private key. The team does not know how this key was obtained, but it suspects that the virtual machine that held the key became infected with a trojan program.

Once the attacker had the key, they called a function to withdraw transaction fees that would normally go to the DAO’s treasury to be used for buybacks of RAY. On Raydium, transaction fees do not automatically go to the treasury at the moment of a swap. Instead, they remain in the liquidity provider’s pool until withdrawn by an admin. However, the smart contract keeps track of the amount of fees owed to the DAO through parameters. This should have prevented the attacker from being able to withdraw more than 0.03% of the total trading volume that had occurred in each pool since the last withdrawal.

Nevertheless, because of a flaw in the contract, the attacker was able to manually change the parameters, making it appear that the entire liquidity pool was transaction fees that had been collected. This allowed the attacker to withdraw all of the funds. Once the funds were withdrawn, the attacker was able to manually swap them for other tokens and transfer the proceeds to other wallets under the attacker’s control.

Related: Developer says projects are refusing to pay bounties to white hat hackers

In response to the exploit, the team has upgraded the app’s smart contracts to remove admin control over the parameters that were exploited by the attacker.

In the Dec. 21 forum post, the developers proposed a plan to compensate victims of the attack. The team will use its own unlocked RAY tokens to compensate RAY holders who lost their tokens due to the attack. It has asked for a forum discussion on how to implement a compensation plan using the DAO’s treasury to purchase non-RAY tokens that have been lost. The team is asking for a three-day discussion to take place to decide the issue.

The $2 million Raydium hack was first discovered on Dec. 16. Initial reports said that the attacker had used the withdraw_pnl function to remove liquidity from pools without depositing LP tokens. But since this function should have only allowed the attacker to remove transaction fees, the actual method by which they could drain entire pools was not known until after an investigation had been conducted.

Read Entire Article
Tags: CointelegraphCryptocurrencyInvestmentMining Bitcoin
Share76Tweet47

Related Posts

Bitcoin derivatives data shows room for BTC price to move higher this week

by Jon Hartney
January 23, 2023
0

BTC options data suggest that the Bitcoin price rally still has legs, even with wider economic concerns growing and the

Bitcoin price consolidation opens the door for APE, MANA, AAVE and FIL to move higher

by Jon Hartney
January 22, 2023
0

BTC could take a break from its sharp rally and if BTC price bounces off underlying support, APE, MANA, AAVE...

Genesis bankruptcy case scheduled for first hearing

by Jon Hartney
January 22, 2023
0

The first hearing in Genesis Capital's bankruptcy case will be held on January 23, according to court filings

Terra lending protocol Mars to launch mainnet

by Jon Hartney
January 22, 2023
0

The Mars Hub will launch an independent Cosmos application chain and issue MARS to users who hold the token during...

Central African Republic eyes legal framework for crypto adoption

by Jon Hartney
January 22, 2023
0

A 15-member committee is tasked with working on a legal framework that will allow cryptocurrencies to operate in

Load More
  • Trending
  • Comments
  • Latest

Ethereum Classic gets ‘endorsement’ from Vitalik Buterin, but ETC price still risks 50% crash

July 27, 2022

Critique on Helium’s $6.5K monthly revenue causes a stir

July 28, 2022

All aboard! Elon Musk’s Vegas Loop now taking Dogecoin payments

July 7, 2022

Cardano Vasil hard fork hit with another delay for several weeks

July 29, 2022

All aboard! Elon Musk’s Vegas Loop now taking Dogecoin payments

0

Crypto owners banned from working on US Government crypto policies

0

Korean startup Uprise lost $20M shorting LUNC

0

Ethereum testnet Merge mostly successful — ‘Hiccups will not delay the Merge.’

0

Bitcoin derivatives data shows room for BTC price to move higher this week

January 23, 2023

Bitcoin price consolidation opens the door for APE, MANA, AAVE and FIL to move higher

January 22, 2023

Genesis bankruptcy case scheduled for first hearing

January 22, 2023

Terra lending protocol Mars to launch mainnet

January 22, 2023

XBT.Market

This website is an automated news feed powered by the Nebulome cloud system. The site is made possible by YYC TECH Consulting and Alberta Digital Mining Company. As a team with major crypto and bitcoin enthusiasm, we have curated major sources of news, trading and financial data to bring you, our viewer, an unbiased source of truth.

Recent Posts

  • Bitcoin derivatives data shows room for BTC price to move higher this week January 23, 2023
  • Bitcoin price consolidation opens the door for APE, MANA, AAVE and FIL to move higher January 22, 2023
  • Genesis bankruptcy case scheduled for first hearing January 22, 2023
  • Terra lending protocol Mars to launch mainnet January 22, 2023
  • Central African Republic eyes legal framework for crypto adoption January 22, 2023

News Categories

  • Bitcoin
  • Blockchain
  • Business
  • Market

Tags

bitcoinMagzine Cointelegraph Cryptocurrency insidebitcoins Investment Mining Bitcoin NewsBTC

Quicklinks

  • Home
  • Coins MarketCap
  • Crypto Exchanges
  • Crypto Calculator
  • Top Gainers and Loser
  • News
  • Contact Us

© 2022 Xbt.Market - Powered by YYC Tech Consulting & ADMCO.

No Result
View All Result
  • Home
  • Coins MarketCap
  • Crypto Exchanges
  • Crypto Calculator
  • Top Gainers and Loser
  • News
  • Contact Us

© 2022 Xbt.Market by Nebulome.

  • bitcoinBitcoin(BTC)$28,477.001.52%
  • ethereumEthereum(ETH)$1,828.772.54%
  • USDEXUSDEX(USDEX)$1.07-0.53%
  • tetherTether(USDT)$1.00-0.08%
  • binancecoinBNB(BNB)$317.360.29%
  • usd-coinUSD Coin(USDC)$1.00-0.18%
  • rippleXRP(XRP)$0.54-0.91%
  • cardanoCardano(ADA)$0.4027846.61%
  • Lido Staked EtherLido Staked Ether(STETH)$1,827.892.95%
  • dogecoinDogecoin(DOGE)$0.0762512.16%
  • matic-networkPolygon(MATIC)$1.111.56%
  • SolanaSolana(SOL)$20.962.40%
  • polkadotPolkadot(DOT)$6.334.06%
  • Binance USDBinance USD(BUSD)$1.00-0.06%
  • litecoinLitecoin(LTC)$89.631.48%
  • Shiba InuShiba Inu(SHIB)$0.0000112.11%
  • tronTRON(TRX)$0.0659062.24%
  • AvalancheAvalanche(AVAX)$17.712.86%
  • daiDai(DAI)$1.00-0.06%
  • UniswapUniswap(UNI)$6.083.56%
  • wrapped-bitcoinWrapped Bitcoin(WBTC)$28,472.001.66%
  • chainlinkChainlink(LINK)$7.635.52%
  • cosmosCosmos Hub(ATOM)$11.18-0.38%
  • ToncoinToncoin(TON)$2.215.75%
  • leo-tokenLEO Token(LEO)$3.470.49%
  • stellarStellar(XLM)$0.1102514.62%
  • ethereum-classicEthereum Classic(ETC)$20.682.32%
  • moneroMonero(XMR)$157.340.82%
  • OKBOKB(OKB)$41.780.20%
  • Aerarium FiAerarium Fi(AERA)$7.14-13.09%
  • bitcoin-cashBitcoin Cash(BCH)$124.073.35%
  • filecoinFilecoin(FIL)$5.672.70%
  • HederaHedera(HBAR)$0.07405014.43%
  • Lido DAOLido DAO(LDO)$2.467.79%
  • true-usdTrueUSD(TUSD)$1.00-0.03%
  • AptosAptos(APT)$11.301.92%
  • QuantQuant(QNT)$124.86-1.13%
  • ArbitrumArbitrum(ARB)$1.382.81%
  • CronosCronos(CRO)$0.0690001.39%
  • NEAR ProtocolNEAR Protocol(NEAR)$2.004.18%
  • vechainVeChain(VET)$0.0234552.57%
  • algorandAlgorand(ALGO)$0.223614-1.06%
  • Internet ComputerInternet Computer(ICP)$5.214.17%
  • ApeCoinApeCoin(APE)$4.183.39%
  • eosEOS(EOS)$1.201.35%
  • FantomFantom(FTM)$0.4729036.82%
  • The GraphThe Graph(GRT)$0.1461642.75%
  • StacksStacks(STX)$0.93-1.35%
  • The SandboxThe Sandbox(SAND)$0.631.68%
  • MultiversXMultiversX(EGLD)$42.460.47%
  • decentralandDecentraland(MANA)$0.591.70%
  • AaveAave(AAVE)$73.273.42%
  • FraxFrax(FRAX)$1.000.02%
  • tezosTezos(XTZ)$1.121.40%
  • FlowFlow(FLOW)$0.992.42%
  • theta-tokenTheta Network(THETA)$1.031.72%
  • ImmutableXImmutableX(IMX)$1.121.71%
  • EdgecoinEdgecoin(EDGT)$1.00-0.28%
  • Axie InfinityAxie Infinity(AXS)$8.361.49%
  • neoNEO(NEO)$12.51-0.37%
  • ConfluxConflux(CFX)$0.4108751.51%
  • Rocket PoolRocket Pool(RPL)$44.173.41%
  • kucoin-sharesKuCoin(KCS)$8.28-0.41%
  • havvenSynthetix Network(SNX)$2.513.95%
  • WhiteBIT TokenWhiteBIT Token(WBT)$5.320.82%
  • BitDAOBitDAO(BIT)$0.531.00%
  • paxos-standardPax Dollar(USDP)$1.00-0.01%
  • Terra Luna ClassicTerra Luna Classic(LUNC)$0.0001252.19%
  • Curve DAOCurve DAO(CRV)$0.942.66%
  • GateGate(GT)$5.132.31%
  • OptimismOptimism(OP)$2.283.33%
  • USDDUSDD(USDD)$0.990.03%
  • KlaytnKlaytn(KLAY)$0.226946-1.15%
  • bitcoin-cash-svBitcoin SV(BSV)$35.921.87%
  • PancakeSwapPancakeSwap(CAKE)$3.700.65%
  • Mina ProtocolMina Protocol(MINA)$0.772.06%
  • GMXGMX(GMX)$75.942.38%
  • dashDash(DASH)$58.123.63%
  • ChilizChiliz(CHZ)$0.1196562.23%
  • Frax ShareFrax Share(FXS)$8.855.05%
  • CloutContractsCloutContracts(CCS)$52.461,000.00%
  • makerMaker(MKR)$686.922.41%
  • BitTorrentBitTorrent(BTT)$0.0000012.57%
  • eCasheCash(XEC)$0.0000311.29%
  • iotaIOTA(MIOTA)$0.2142801.94%
  • huobi-tokenHuobi(HT)$3.64-0.12%
  • XDC NetworkXDC Network(XDC)$0.0423123.59%
  • KaspaKaspa(KAS)$0.0321905.68%
  • Bitget TokenBitget Token(BGB)$0.3955290.12%
  • cETHcETH(CETH)$36.632.56%
  • singularitynetSingularityNET(AGIX)$0.4225253.24%
  • Tokenize XchangeTokenize Xchange(TKX)$6.371.79%
  • PAX GoldPAX Gold(PAXG)$1,975.94-0.50%
  • Trust WalletTrust Wallet(TWT)$1.17-0.19%
  • Tether GoldTether Gold(XAUT)$1,973.02-0.63%
  • RenderRender(RNDR)$1.356.97%
  • Mask NetworkMask Network(MASK)$6.330.13%
  • cUSDCcUSDC(CUSDC)$0.022789-0.08%
  • zilliqaZilliqa(ZIL)$0.0290664.57%
  • 1inch1inch(1INCH)$0.56-1.73%