The Revelation from the Raydium Theft Incident: New DeFi Vulnerabilities Lurking in Forgotten Old Contracts

Foresight NewsPublicado a 2026-06-13Actualizado a 2026-06-13

Resumen

**Raydium Exploit Reveals DeFi's Hidden Risk: Forgotten "Zombie" Contracts** A recent attack on Raydium's deprecated V3 AMM pools resulted in a loss of approximately $1.34 million. The hacker exploited pools that were no longer supported by Raydium's current UI or SDK but remained fully functional and accessible on-chain. This incident highlights a critical, often overlooked category of risk in DeFi: inactive or legacy smart contracts that projects fail to properly decommission. Since March 2025, there have been at least 8 publicly reported attacks targeting such abandoned contracts, with total losses around $10.8 million. Including older pools and deprecated features, the count rises to 10 incidents with roughly $22.5 million in losses. These "zombie contracts" represent a lifecycle management failure rather than a code vulnerability, yet they are typically misclassified under general "code bug" categories in security reports, masking the true scale of the problem. The root cause is that projects often merely document a contract as "deprecated" without taking essential technical steps to secure it: withdrawing remaining assets, disabling external call functions, and implementing ongoing monitoring. These forgotten, under-monitored components become prime targets for attackers. To address this, the industry needs to recognize "zombie contracts" as a distinct risk category and establish standardized decommissioning protocols. Essential steps should include: 1) a formal ret...


Author: Gino Matos

Compiler: Luffy, Foresight News


TL;DR:


  • Hackers stole approximately $1.34 million in assets by exploiting Raydium's long-discontinued V3 Automated Market Maker liquidity pools.
  • This incident exposes a widespread issue: Old contracts decommissioned by DeFi projects are still operational on-chain. These forgotten underlying infrastructures have become easily overlooked attack targets.
  • Public reports indicate that since March 2025, there have been at least 8 similar theft incidents targeting old contracts within the industry, suggesting that a vast amount of unattended legacy code remains externally callable.


Recently, a vulnerability in Raydium's AMM V3 resulted in a loss of $1.34 million. This incident involved five liquidity pools outside the project's current product ecosystem. These pools were unsupported by Raydium's UI or SDK and inaccessible to ordinary users, yet they were ultimately exploited by hackers.


This attack targeted the neglected old contracts and underlying infrastructures within the industry, revealing major flaws in the full lifecycle management of smart contracts. This type of problem is not unique to this one Solana-based decentralized exchange.


The Overlooked Risk Category


According to publicly available security incident reports, from March 2025 to the present, there have been at least 8 confirmed attack cases explicitly due to abandoned, phased-out, or old contracts, with cumulative losses of approximately $10.8 million.


If attacks involving old liquidity pools and outdated supporting products are included in the statistics, the number of related incidents reaches 10 (including this Raydium theft), with total losses amounting to about $22.5 million.


Most current industry security incident tracking platforms categorize attack types based on technical causes. Common classifications include: smart contract code vulnerabilities, permission control failures, oracle manipulation, private key leakage, cross-chain bridge defects, etc.


Zombie contracts (i.e., old contracts declared discontinued by projects but still normally callable on-chain) belong to a completely different risk dimension. They are security incidents caused by failures in contract lifecycle management, yet they have always been buried within the statistical entries of various conventional vulnerabilities and have not been classified separately.



The reason Raydium's V3 AMM liquidity pools were abandoned stems from the formal shutdown of the Serum project they relied on, rendering this set of old contracts completely non-functional. The corresponding liquidity assets have been idle on-chain ever since.


Raydium's currently used new version of the contract performs dual verification of two key pieces of information: first, it checks asset proportions through a total supply verification mechanism; second, it verifies the minting address of liquidity tokens and various associated account information.


However, this outdated V3 contract completely omitted these two verification processes. Hackers exploited this vulnerability by forging new liquidity tokens and impersonating legitimate certificates, directly bypassing all risk control rules.


In this incident, a total of approximately 150,177 RAY, 5,603 SOL, and 893,700 USDC were stolen. These assets had been stored in the platform's old liquidity pools for a long time. Although detached from mainstream operations, their on-chain call permissions were never deactivated.


Eight Cases Reveal Common Problems


Since 2025, several well-known DeFi projects have stumbled over old contracts. All incidents share the same characteristics: the project team claimed that the current version of the product and active users were unaffected, but because the old contracts were not completely shut down, the project treasury ultimately bore the full losses.



Why Old Contract Risks Are Overlooked


Currently, the vast majority of industry security incident classification systems focus on attack methods, tampering targets, and code failure points, representing an analytical perspective "starting from technical vulnerabilities." This also leads to the masking of zombie contract incidents. The core of such problems is never coding errors, but the failure of projects to execute the necessary complete shutdown of old contracts.


A 2025 industry research paper analyzed 50 major global crypto security incidents between 2022 and 2025, with cumulative losses exceeding $1 billion. The study pointed out that high-harm on-chain attacks are often the result of chain risk superposition, simultaneously involving human operations, daily maintenance, economic models, contract lifecycle management, community governance, and other levels.


The paper proposed a four-layer root cause analysis framework, clearly classifying contract lifecycle management vulnerabilities and community governance vulnerabilities as independent risk categories separate from code writing vulnerabilities. The zombie contract problem is a typical lifecycle management vulnerability. However, in existing security statistics systems, such incidents are uniformly categorized as "code vulnerabilities," and the corresponding loss data is concealed under other classifications, failing to attract sufficient industry attention.


Beware the "Contract Graveyard": Old Infrastructure Becomes a New Attack Hotspot


If DeFi projects continue to treat "contract shutdown" as an optional, trivial matter—merely annotating "this contract is discontinued" in product documentation without transferring idle assets, disabling call functions, or continuously monitoring status—then hackers will persistently target this "contract graveyard."


Every large DeFi project's historical deployment records have now become attack targets that hackers can search and exploit. The currently counted $22.5 million in losses is merely the value from publicly exposed cases; the real risk is far higher.


Those old liquidity pools holding assets but detached from mainstream user workflows, historical authorization interfaces, and early partnership integration modules receive far less operational monitoring than current business systems, making them precisely the preferred targets for hackers.


To change the status quo, "zombie contracts" must first be listed as an independent risk category with separate incident statistics. Secondly, the contract decommissioning process must be incorporated into standardized security procedures, placed on equal footing with code audits. Only by implementing full lifecycle operations and maintenance can the attack surface be effectively reduced.


Currently, the industry's handling methods are largely similar. Raydium used its project treasury to cover the $1.34 million loss. Transit Finance and Huma Finance also bore user losses through the project side.


This also means that contract decommissioning is no longer just a documentation annotation task; it is an essential security control link.


Seven Security Control Standards for Contract Decommissioning


For the shutdown of old contracts, the industry can establish standardized control processes. The specific requirements and their functions are as follows:



Simply annotating "contract discontinued" in documentation merely shifts the security risk to the project treasury, while the attack vulnerability remains. Announcing a shutdown only at the product level without a complete technical deactivation leaves old contracts perpetually callable: project teams neglect oversight, while hackers watch closely at all times.


The value of a DeFi project is not only reflected in its current total value locked (TVL) but also in the historical code and underlying architectures accumulated along its journey. And this forgotten history has now become a new security突破口 (breakthrough point).

Preguntas relacionadas

QWhat is the main vulnerability exploited in the recent Raydium hack, and what was the estimated loss?

AThe main vulnerability was in Raydium's deprecated V3 Automated Market Maker (AMM) liquidity pools. Hackers exploited these old, inactive contracts to steal approximately $1.34 million worth of assets.

QAccording to the article, what new risk category does the Raydium incident and similar attacks highlight for the DeFi industry?

AThe incident highlights the risk category of 'zombie contracts' or outdated smart contracts that have been deprecated but remain operational and callable on the blockchain, becoming overlooked attack surfaces.

QHow many similar attacks targeting outdated or deprecated contracts have been reported since March 2025, and what is the total estimated loss mentioned?

ASince March 2025, there have been at least 8 reported attacks specifically targeting deprecated or old contracts, with a cumulative loss of about $10.8 million. Including older liquidity pools and related products, the total is 10 incidents with losses around $22.5 million.

QWhy are these 'zombie contract' risks often overlooked in current security incident classifications?

ACurrent security classifications focus on technical vulnerabilities (like code bugs, oracle manipulations). 'Zombie contract' issues stem from lifecycle management failures—contracts not being properly decommissioned—and are therefore often mis-categorized under general 'code vulnerability' labels, obscuring their specific nature.

QWhat does the article suggest as a key action to properly address the risk of outdated contracts?

AThe article suggests establishing standardized security control processes for contract decommissioning. This includes measures like withdrawing all idle assets, permanently disabling key functions, revoking permissions, and continuous monitoring, treating contract sunsetting as a critical security task on par with code auditing.

Lecturas Relacionadas

Blockchain Has Finally Started to Sail into the Mainstream After 18 Years

Blockchain Finds Its True Path After 18 Years: Becoming the Financial Backbone for AI Agents and Autonomy This analysis explores a pivotal shift in the blockchain and crypto investment landscape, driven by the dominance of AI. Major venture capital firms, including Variant, Paradigm, Haun Ventures, and YZi Labs, are moving beyond pure "crypto" investment theses. They are expanding their focus to AI, robotics, and frontier tech, signaling that blockchain is no longer seen as a standalone sector but as an underlying infrastructure layer. The core argument is that blockchain's killer application may not be user-facing apps, but rather providing the economic rails for the coming wave of AI agents, autonomous robots, and automated systems. Key capabilities like self-custody wallets, programmable stablecoins for micropayments, on-chain identity, and verifiable smart contracts are positioned as essential for a future where machines conduct economic activity. The recent $1.4 billion investment by Tether (via its venture arm) in German robotics company NEURA Robotics exemplifies this, aiming to embed Tether's wallet tools directly into robots for autonomous transactions. While many "AI + Crypto" projects remain superficial, the article concludes that true value lies where crypto is a necessary component—enabling machine-to-machine payments, agent autonomy, verifiable data provenance, and open financial settlement for the AI era. For crypto venture capital, this convergence with AI represents both an adaptation to shifting capital flows and a potential path to unlocking the large-scale, non-speculative utility the industry has long sought.

marsbitHace 18 min(s)

Blockchain Has Finally Started to Sail into the Mainstream After 18 Years

marsbitHace 18 min(s)

Blockchain has finally begun sailing toward the main channel after 18 years

After 18 years of development, blockchain technology is beginning to move from a specialized niche into mainstream adoption, according to a recent industry analysis. The shift is reflected in the changing strategies of major crypto venture capital firms, which are expanding their focus beyond pure "digital ownership" towards broader themes like "autonomy." The report highlights that leading VC firms like Variant, Paradigm, Haun Ventures, and YZi Labs are broadening their investment mandates to include not only crypto but also artificial intelligence (AI), robotics, biotech, and other frontier technologies. This reflects a recognition that the isolated "crypto investment" narrative is losing appeal to limited partners (LPs) as capital and attention increasingly flow toward AI and other high-growth tech sectors. A key emerging thesis is that blockchain's most significant future application may not be as a consumer-facing product, but as the underlying economic and settlement infrastructure for the AI era. As AI agents and autonomous systems become more prevalent, they will require programmable, global, and low-cost payment networks (like stablecoins), verifiable digital identities, and secure wallets to manage transactions and assets on behalf of users. The investment by stablecoin issuer Tether into robotics company NEURA, with plans to integrate its wallet technology, is cited as a prime example of this convergence. However, the article cautions that simply labeling projects as "AI + Crypto" is insufficient. True value lies in integrations where blockchain technology is essential—such as enabling machine-to-machine micropayments, verifiable data provenance for AI, or transparent governance for autonomous organizations—rather than being a superficial marketing add-on. In conclusion, while AI currently dominates the tech narrative and capital flows, it may ultimately create the real-world, high-frequency demand that the crypto industry has long sought. For crypto VCs and projects, the path forward is to position blockchain not as a competing sector, but as a critical foundational layer powering autonomy and economic activity in an AI-driven future.

链捕手Hace 24 min(s)

Blockchain has finally begun sailing toward the main channel after 18 years

链捕手Hace 24 min(s)

Y Combinator Co-founder: How to Make a Billion Dollars?

The Y Combinator co-founder argues that becoming a billionaire by founding a successful startup is not only possible but demonstrably achievable without unfair or unethical practices. He disputes a politician's claim to the contrary, using the example of a founder whose company grew at 93% monthly solely through creating a product users loved and recommended. The core mechanism is exponential growth. A conservative 15% monthly growth rate compounds to a 4384x increase over five years, which can easily lead to billion-dollar valuations and founder wealth. The process depends on two key variables: the growth rate and the duration it can be sustained. A high growth rate stems from a great product that users naturally promote, while a long duration requires a large enough market. For aspiring founders, especially young ones, the simplest path is to build something they and their friends genuinely need. Young people's current needs often predict future mass-market trends. He advises against actively "searching" for ideas, as this tends to filter out unconventional but promising ones. Instead, inspiration should come from working on interesting projects with friends, as many iconic companies (e.g., Apple, Facebook) started this way. Ultimately, building a massively valuable startup is not about exploitation but empathy: deeply understanding a user group and building a product that significantly improves their lives. This, powered by exponential growth in a large market, is the legitimate path to immense wealth creation.

Foresight NewsHace 27 min(s)

Y Combinator Co-founder: How to Make a Billion Dollars?

Foresight NewsHace 27 min(s)

The 800V Voltage Standard Championed by Nvidia: Which Infrastructure Providers Stand to Benefit?

NVIDIA is actively promoting the 800VDC architecture as a key direction for its next-generation AI factories and high-power racks, particularly for the upcoming Rubin and Kyber platforms. The primary driver is the rapidly increasing power density of AI racks, with designs like GB200/GB300 NVL72 reaching 120-140kW and future systems potentially hitting 180-220kW. At such high power levels, traditional low-voltage power delivery becomes inefficient due to massive current, leading to significant copper use, cable bulk, heat, and power loss. The 800VDC standard aims to increase efficiency by transmitting power at higher voltage and lower current to the rack before stepping it down locally for GPUs. NVIDIA claims this can improve efficiency by up to 5%, reduce total cost of ownership (TCO) by up to 30%, and cut copper usage by approximately 45%. This shift redefines infrastructure roles, pushing power engineering to the forefront alongside GPU performance. Key beneficiaries and ecosystem partners highlighted include: 1. **Power Infrastructure Providers:** Companies like Vertiv, Schneider Electric, Delta Electronics (台达电), and Korean firms LS Electric and HD Hyundai Electric are involved in designing next-gen AI factory power distribution, rack power supplies, and backup systems. 2. **Power Semiconductors:** Suppliers of SiC/GaN devices, such as Infineon and STMicroelectronics, are better suited for high-voltage, high-efficiency conversion in this new architecture. 3. **Connectivity & Structure:** The focus shifts to high-reliability components like busbars, high-voltage connectors, and advanced PCBs that meet stricter insulation and safety requirements. 4. **Liquid Cooling & Rack ODM:** As power and heat density rise, liquid cooling becomes critical. Full-rack system integrators (e.g., Dell, Wiwynn, Wistron) must now demonstrate robust pre-delivery testing capabilities, including burn-in testing under full load, requiring significant power and cooling infrastructure in their factories. The transition is not immediate for all data centers but is targeted at high-density AI factories. NVIDIA’s 800VDC ecosystem is in a preparatory phase, with full-scale production expected to align with the 2027 launch of Kyber rack-scale systems. The investment thesis revolves around which companies can demonstrate proven product integration, customer validation, and reliable delivery of complete, high-power AI rack systems, making power, cooling, and testing capabilities new critical variables in the AI infrastructure value chain alongside GPUs.

marsbitHace 47 min(s)

The 800V Voltage Standard Championed by Nvidia: Which Infrastructure Providers Stand to Benefit?

marsbitHace 47 min(s)

Trading

Spot
Futuros
活动图片