Fact-check findings
What an automated fact-checker found when it re-read Raydium AMM against the sources the page cites. Only the most recent review is shown.
These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.
“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.
Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.
unverifiable
1 claimNo source the reviewer could reach confirms or contradicts the claim.
- #7[unverifiable][awaiting moderator]in section: December 2022 Admin Key Exploit
“the funding source was 5ndLnEYqSFiA5yUFHo6LVZ1eWc6Rhh11K5CfJNkoHEPs, later identified as a FixedFloat exchange wallet”
reviewerFunding source wallet 5ndLnEYqSFiA5yUFHo6LVZ1eWc6Rhh11K5CfJNkoHEPs was later identified as a FixedFloat exchange walletNo source consulted, including the cited official post-mortem and CertiK analysis, corroborates the specific FixedFloat attribution for this address; an unrelated blacklist report links the same address string to a different, later scam context, adding ambiguity rather than confirmation. Could not verify either way.
link rot
6 claimsA cited source no longer resolves or no longer says what the page attributes to it.
- #28[link rot][awaiting moderator]in section: Centralization Risk and Admin Key Architecture
“https://docs.raydium.io/raydium/protocol/security”
reviewerDocs.raydium.io security documentation page is a valid, current citation for the security architecture claimsThe Raydium docs site was reorganized; the cited path no longer resolves but an archived snapshot exists in sources_used and a live successor page covers the same content.Proposed correction (not yet applied)https://docs.raydium.io/security/index - #29[link rot][awaiting moderator]in section: Security Improvements and Current Status
“https://docs.raydium.io/raydium/protocol/security”
reviewerDocs.raydium.io security documentation page is a valid, current citation (second occurrence, Security Improvements section)Same underlying dead URL as the Centralization Risk section; grouped under the same defect.Proposed correction (not yet applied)https://docs.raydium.io/security/index - #30[link rot][awaiting moderator]in the cited sources
“https://docs.raydium.io/raydium/protocol/security”
reviewerDocs.raydium.io security documentation page is a valid, current citation (sources_used entry)Third occurrence of the same dead URL; grouped under the same defect group.Proposed correction (not yet applied)https://docs.raydium.io/security/index - #31[link rot][awaiting moderator]in section: User Compensation Program
“https://docs.raydium.io/raydium/updates/archive/claim-portal”
reviewerDocs.raydium.io claim-portal archive page is a valid, current citation for the compensation-plan claim-portal timelineUnlike the security page, this content has been fully removed from the live docs site rather than relocated; the only available live-adjacent evidence is the archive.org snapshot already stored in sources_used.Proposed correction (not yet applied)http://web.archive.org/web/20260216135707/https://docs.raydium.io/raydium/updates/archive/claim-portal - #32[link rot][awaiting moderator]in the cited sources
“https://docs.raydium.io/raydium/updates/archive/claim-portal”
reviewerDocs.raydium.io claim-portal archive page is a valid, current citation (sources_used entry)Second occurrence of the same dead URL; grouped under the same defect group.Proposed correction (not yet applied)http://web.archive.org/web/20260216135707/https://docs.raydium.io/raydium/updates/archive/claim-portal - #33[link rot][awaiting moderator]in the timeline
“https://docs.raydium.io/raydium/updates/archive/claim-portal”
reviewerTimeline entry source URL for the May 14, 2023 claim-portal closure cites a live docs pageThird occurrence of the same dead URL, this time as a timeline source_url field; grouped under the same defect group.Proposed correction (not yet applied)http://web.archive.org/web/20260216135707/https://docs.raydium.io/raydium/updates/archive/claim-portal
confirmed
26 claimsThe cited evidence supports the claim as written.
- #1[confirmed][no action needed]in the summary
“Raydium is a leading Solana-based automated market maker (AMM) and decentralized exchange (DEX) launched in February 2021 by a pseudonymous team.”
reviewerRaydium is a Solana-based AMM/DEX launched February 2021 by a pseudonymous teamLaunch date and pseudonymous team structure are consistently corroborated across independent sources. - #2[confirmed][no action needed]in the summary
“On December 16, 2022, a compromise of the protocol's admin private key enabled an attacker to drain approximately $4.4 million from eight liquidity pools”
reviewerDecember 16, 2022 admin key compromise drained ~$4.4M from eight liquidity poolsThe $4.4M figure (precisely ~$4.395M per some outlets) and eight-pool scope are consistently corroborated. - #3[confirmed][no action needed]in the summary
“the stolen funds were subsequently laundered through Tornado Cash in January 2023”
reviewerStolen funds were laundered through Tornado Cash in January 2023Well corroborated across CoinDesk, CoinTelegraph, and CryptoSlate. - #4[confirmed][no action needed]in the summary
“The team implemented a phased compensation plan and post-incident security upgrades, including migration of admin authority to a Squads multisig, but the incident exposed significant centralization risks that were not apparent prior to the exploit.”
reviewerTeam implemented phased compensation plan and post-incident security upgrades, including migration of admin authority to a Squads multisigCompensation plan and multisig migration are both independently confirmed. - #5[confirmed][no action needed]in section: December 2022 Admin Key Exploit
“On December 16, 2022 at approximately 10:12 UTC, a malicious actor gained control of the Raydium Pool Owner (Admin) account and exploited eight constant product liquidity pools in the V4 AMM program.”
reviewerCompromise began at approximately 10:12 UTC on Dec 16, 2022 and patch was deployed at 14:16 UTC the same dayBoth timestamps independently corroborated via secondary reporting quoting the official post-mortem verbatim. - #6[confirmed][no action needed]in section: December 2022 Admin Key Exploit
“The attacker used two mechanisms: first, abusing the withdrawPNL instruction to drain accumulated protocol fees directly from pool vaults; second, using the SetParams instruction with AmmParams::SyncNeedTake to artificially inflate need_take_pc and need_take_coin balances without corresponding trading volume, then repeatedly withdrawing those inflated figures as fees.”
reviewerAttacker used withdrawPNL and SetParams/SyncNeedTake mechanisms to drain fundsTechnical exploit mechanism is accurately and specifically described, matching independent technical writeups. - #8[confirmed][no action needed]in section: December 2022 Admin Key Exploit
“Raydium's team attributed the private key compromise to a trojan program infecting the virtual machine on which the Pool Owner account was deployed, though no definitive forensic proof was published.”
reviewerRaydium attributed the compromise to a trojan program on the VM hosting the Pool Owner account, with no definitive forensic proof publishedAccurately reflects Raydium's own hedged attribution. - #9[confirmed][no action needed]in section: December 2022 Admin Key Exploit
“Concentrated liquidity (CLMM) pools and the RAY staking program were not affected.”
reviewerCLMM pools and RAY staking program were not affected by the exploitConfirmed by independent technical writeups. - #10[confirmed][no action needed]in section: December 2022 Admin Key Exploit
“CoinDesk reported that ZachXBT tracked the attacker bridging approximately $2 million of the stolen assets to Ethereum in real time during the incident.”
reviewerCoinDesk reported that ZachXBT tracked the attacker bridging approximately $2 million of stolen assets to Ethereum in real timeConfirmed via secondary corroboration of the underlying CoinDesk reporting; could not directly fetch the CoinDesk page due to rate limiting. - #11[confirmed][no action needed]in section: Stolen Funds Laundered via Tornado Cash
“On January 19, 2023, the wallet tagged as 'Raydium Exploiter' (0xb98acc055e331a709a765569eb6854bb2f0c8282 on Ethereum) deposited a total of 1,774.5 ETH (approximately $2.7 million at the time) into Tornado Cash across 42 separate transactions.”
reviewerJanuary 19, 2023: Raydium Exploiter wallet deposited 1,774.5 ETH (~$2.7M) into Tornado Cash across 42 transactionsFigures precisely match across three independent outlets. - #12[confirmed][no action needed]in section: Stolen Funds Laundered via Tornado Cash
“Tornado Cash had been placed on the U.S. Treasury Office of Foreign Assets Control (OFAC) sanctions list in November 2022, due to its alleged use by state-affiliated threat actors including North Korea-linked Lazarus Group.”
reviewerTornado Cash was placed on OFAC's sanctions list in November 2022 due to alleged use by Lazarus GroupWell-established public record; accurately summarized. - #13[confirmed][no action needed]in section: Centralization Risk and Admin Key Architecture
“CertiK's post-mortem stated explicitly that 'one wallet was able to withdraw liquidity from multiple pools,' and characterized the incident as a consequence of protocols that 'are not fully decentralized' requiring accounts with access to 'critical network controls.'”
reviewerCertiK stated 'one wallet was able to withdraw liquidity from multiple pools' and described the incident as a consequence of protocols that 'are not fully decentralized' requiring accounts with access to 'critical network controls'Both quoted fragments verified word-for-word against the CertiK source. - #14[confirmed][no action needed]in section: Centralization Risk and Admin Key Architecture
“In the immediate aftermath, Raydium migrated admin authority to a hardware wallet (December 16) and then to a Squads multisig (December 17).”
reviewerRaydium migrated admin authority to a hardware wallet on Dec 16 and then to a Squads multisig on Dec 17Sequence and dates match independent reporting. - #15[confirmed][no action needed]in section: Centralization Risk and Admin Key Architecture
“As of 2025, Raydium updated program admin authority to Squads V4 with a 24-hour timelock.”
reviewerAs of 2025, Raydium updated program admin authority to Squads V4 with a 24-hour timelockThe underlying fact is confirmed on the current Raydium docs site, though the specific cited URL no longer resolves (see separate link_rot finding for that URL). - #16[confirmed][no action needed]in section: User Compensation Program
“Following a community governance vote that passed on December 30, 2022 with 5,598,814 approvals, Raydium implemented a phased compensation plan for affected liquidity providers.”
reviewerGovernance vote passed December 30, 2022 with 5,598,814 approvals authorizing the compensation planExact figure and date verified word-for-word against the cited CertiK source. - #17[confirmed][no action needed]in section: User Compensation Program
“RAY pricing for compensation was calculated using a 30-day TWAP of $0.1813 (December 6, 2022 through January 3, 2023).”
reviewerCompensation terms: RAY pools eligible for 100% recovery; six other pools received 90% native-asset recovery plus 10% shortfall in RAY at a 1:1.2 ratio, priced via a 30-day TWAP of $0.1813TWAP price, date range, and compensation ratio all verified against the cited official compensation-plan post. - #18[confirmed][no action needed]in section: User Compensation Program
“The claim portal opened January 5, 2023 and was extended through May 14, 2023 to accommodate third-party integrations including Francium and Tulip leveraged vault positions.”
reviewerClaim portal opened January 5, 2023 and was extended through May 14, 2023 to accommodate Francium and Tulip leveraged vault positionsUnderlying facts confirmed via secondary excerpts of the (now-dead) cited docs page; see link_rot finding on the URL itself. - #19[confirmed][no action needed]in section: January 2024 CLMM Tick Manipulation Vulnerability
“On January 10, 2024, a whitehat researcher identified as @riproprip reported a critical vulnerability in Raydium's CLMM (concentrated liquidity) program via Immunefi.”
reviewerJanuary 10, 2024, whitehat @riproprip reported a critical CLMM tick-manipulation vulnerability via Immunefi involving increase_liquidity.rs and tickarray_bitmap_extensionTechnical details and date match the Immunefi writeup precisely. - #20[confirmed][no action needed]in section: January 2024 CLMM Tick Manipulation Vulnerability
“The whitehat was awarded a $505,000 bounty in RAY tokens, the maximum payout under Raydium's Immunefi program. No funds were lost as a result of this vulnerability.”
reviewerWhitehat was awarded a $505,000 bounty in RAY tokens, the maximum payout under Raydium's Immunefi program; no funds were lostBounty amount and no-loss outcome independently confirmed. - #21[confirmed][no action needed]in section: Team Anonymity and Governance
“Raydium was founded by a pseudonymous team using the pseudonyms AlphaRay (strategy), XRay (technology), and GammaRay (marketing), with additional core contributors known as StingRay and RayZor.”
reviewerRaydium was founded by pseudonymous team AlphaRay (strategy), XRay (technology), GammaRay (marketing), with additional contributors StingRay and RayZor, coming from an algorithmic trading/commodities background transitioning to crypto around 2017Team pseudonyms, roles, and background narrative all corroborated by independent tertiary sources. - #22[confirmed][no action needed]in section: Security Improvements and Current Status
“OtterSec conducted audits of the updated AMM, the CLMM program, and the staking program in late 2022 and early 2023.”
reviewerOtterSec audited the updated AMM, CLMM program, and staking program in late 2022 and early 2023Programs audited match exactly; the audit window is more precisely 'late 2022' than extending into 'early 2023,' a minor imprecision that does not materially mischaracterize the claim. - #23[confirmed][no action needed]in section: Security Improvements and Current Status
“MadShield audited the OpenBook integration (Q2 2023) and the CPMM (constant product market maker) in Q1 2024.”
reviewerMadShield audited the OpenBook integration (Q2 2023) and the CPMM in Q1 2024Auditor, scope, and quarters all verified exactly against the public audit repository. - #24[confirmed][no action needed]in section: Security Improvements and Current Status
“As of 2025–2026, Raydium remains one of the largest DEX protocols on Solana by TVL (reported at approximately $1–2.5 billion depending on timeframe) and daily trading volume.”
reviewerAs of 2025-2026, Raydium remains one of the largest DEX protocols on Solana by TVL (~$1-2.5 billion) and daily trading volumeThe wide range hedges appropriately for a volatile metric; figures fall within the cited range. - #25[confirmed][no action needed]in section: Security Improvements and Current Status
“Coinbase discontinued RAY perpetual futures in April 2026 as part of a broader 25-product review, though spot trading of RAY continued.”
reviewerCoinbase discontinued RAY perpetual futures in April 2026 as part of a broader 25-product review, though spot trading continuedDate, scope (25 products), and spot-trading continuity all independently confirmed. - #26[confirmed][no action needed]in the timeline
“Raydium AMM launched on Solana mainnet by pseudonymous founding team (AlphaRay, XRay, GammaRay).”
reviewerTimeline: Raydium AMM launched Solana mainnet Feb 2021Consistent with the summary claim already verified. - #27[confirmed][no action needed]in the timeline
“Raydium removes exploited admin parameters from AMM V4 program and transfers remaining admin authority to Squads multisig.”
reviewerTimeline: Dec 17, 2022 Raydium removes exploited admin parameters and transfers authority to Squads multisigMatches independently corroborated post-mortem detail.