A vulnerability in Raydium's deprecated AMM V3 program allowed attackers to drain approximately $1.34 million from five liquidity pools that had already been phased out of the protocol's active product roadmap. These legacy contracts were unsupported by Raydium's UI or SDK and inaccessible to current users, yet remained live on-chain as unmonitored attack surfaces. The incident highlights a systemic lifecycle-management failure common across DeFi: old smart contracts are retired from front-end interfaces but never formally decommissioned on-chain, leaving residual funds exposed. Security teams rarely apply active monitoring to deprecated infrastructure, creating blind spots that sophisticated attackers can exploit. The Raydium case signals that the DeFi industry needs clearer protocols for sunsetting legacy code, including fund migration, contract deprecation notices, and ongoing vulnerability assessments for inactive deployments.


Read the original article →

— Sponsored —

Trade smarter on BYDFI

Get a bonus on your first deposit — from $50 at $100, up to $2,000 at $20k. 200x leverage, 600+ perpetuals, deep liquidity.

Claim your bonus →