Scan to download
BTC $64,269.82 +0.99%
ETH $1,681.20 +1.13%
BNB $609.73 +0.62%
XRP $1.14 +2.46%
SOL $68.51 +1.91%
TRX $0.3169 +1.16%
DOGE $0.0883 +0.91%
ADA $0.1748 +1.88%
BCH $208.62 +1.35%
LINK $8.02 +2.54%
HYPE $59.90 +0.33%
AAVE $67.03 +4.45%
SUI $0.7731 +3.11%
XLM $0.1908 +1.07%
ZEC $416.49 -0.52%
BTC $64,269.82 +0.99%
ETH $1,681.20 +1.13%
BNB $609.73 +0.62%
XRP $1.14 +2.46%
SOL $68.51 +1.91%
TRX $0.3169 +1.16%
DOGE $0.0883 +0.91%
ADA $0.1748 +1.88%
BCH $208.62 +1.35%
LINK $8.02 +2.54%
HYPE $59.90 +0.33%
AAVE $67.03 +4.45%
SUI $0.7731 +3.11%
XLM $0.1908 +1.07%
ZEC $416.49 -0.52%

mainnet

Raydium core contributors: will fully compensate for stolen assets, the current mainnet program has not been affected

Raydium core contributor InfraRAY posted on platform X, stating that the team has confirmed that the old version of the AMM V3 program, which was previously discontinued in 2021, has been attacked. The attacker unauthorizedly removed part of the liquidity, but this incident does not affect current Raydium users, and the related liquidity pools have been unable to interact through the official Raydium UI since being disabled. The Raydium SDK and DApp also do not support operations on the mainnet old version AMM V3 liquidity pools.The five affected liquidity pools include: Sollet USDT-RAY, Sollet ETH-RAY, SRM-RAY, USDC-RAY, and RAY-SOL. Preliminary statistics show that the stolen assets include approximately 150,177 RAY, 5,603 SOL, and 893,700 USDC, with a total value of about $1.34 million. The related losses will be fully compensated by the treasury.Investigations reveal that the vulnerability originated from insufficient verification of the LP token minting address. The attacker created new LP tokens and impersonated legitimate LP tokens, bypassing the protocol's ratio verification mechanism to extract funds. However, this incident is classified as an independent logical vulnerability and is not due to private key leakage or permission intrusion, and there is no risk of spread. Currently, all existing Raydium mainnet programs have not been affected.

Sui attributed the three mainnet interruptions to upgrade vulnerabilities, with known interruption risks before the fix

According to The Block, the Sui Foundation released an incident analysis report on the recent three interruptions of the mainnet, attributing the three network outages that occurred last Thursday and Friday to two independent vulnerabilities introduced by the v1.72 version upgrade. The first interruption lasted about six and a half hours, while the second and third occurred on Friday morning and afternoon, respectively.The first two interruptions were caused by the "address balance" feature introduced in v1.72, which exposed flaws in the transaction fee deduction method. When a transaction was canceled due to insufficient funds, the network would still spend those funds, resulting in a negative balance that caused the validation node reconciliation process to crash. The foundation acknowledged that the temporary fix pushed urgently on Thursday carried known interruption risks, and the team accepted this risk to quickly restore on-chain services, which led to another network interruption on Friday morning.The third interruption was triggered by another undisclosed random state vulnerability, occurring when the validation nodes restarted to install the fix patch. Sui stated that user funds were never at risk, that both vulnerabilities have been fixed, and that a mechanism to forcibly terminate stalled epochs has been established. The foundation also mentioned that AI agents with access to its production systems significantly accelerated the diagnostic process.
app_icon
ChainCatcher Building the Web3 world with innovations.