Skip to main content
AVOID.NET
Raydium AMMreviewed 2026-09-05 · 33 claims checked

Fact-check findings

What an automated fact-checker found when it re-read Raydium AMM against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

unverifiable 1link rot 6confirmed 266 corrections pending · 0 applied

unverifiable

1 claim

No source the reviewer could reach confirms or contradicts the claim.

  1. #7[unverifiable][awaiting moderator]in section: December 2022 Admin Key Exploit
    the funding source was 5ndLnEYqSFiA5yUFHo6LVZ1eWc6Rhh11K5CfJNkoHEPs, later identified as a FixedFloat exchange wallet
    reviewerFunding source wallet 5ndLnEYqSFiA5yUFHo6LVZ1eWc6Rhh11K5CfJNkoHEPs was later identified as a FixedFloat exchange walletNo source consulted, including the cited official post-mortem and CertiK analysis, corroborates the specific FixedFloat attribution for this address; an unrelated blacklist report links the same address string to a different, later scam context, adding ambiguity rather than confirmation. Could not verify either way.

confirmed

26 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in the summary
    Raydium is a leading Solana-based automated market maker (AMM) and decentralized exchange (DEX) launched in February 2021 by a pseudonymous team.
    reviewerRaydium is a Solana-based AMM/DEX launched February 2021 by a pseudonymous teamLaunch date and pseudonymous team structure are consistently corroborated across independent sources.
  2. #2[confirmed][no action needed]in the summary
    On December 16, 2022, a compromise of the protocol's admin private key enabled an attacker to drain approximately $4.4 million from eight liquidity pools
    reviewerDecember 16, 2022 admin key compromise drained ~$4.4M from eight liquidity poolsThe $4.4M figure (precisely ~$4.395M per some outlets) and eight-pool scope are consistently corroborated.
  3. #3[confirmed][no action needed]in the summary
    the stolen funds were subsequently laundered through Tornado Cash in January 2023
    reviewerStolen funds were laundered through Tornado Cash in January 2023Well corroborated across CoinDesk, CoinTelegraph, and CryptoSlate.
  4. #4[confirmed][no action needed]in the summary
    The team implemented a phased compensation plan and post-incident security upgrades, including migration of admin authority to a Squads multisig, but the incident exposed significant centralization risks that were not apparent prior to the exploit.
    reviewerTeam implemented phased compensation plan and post-incident security upgrades, including migration of admin authority to a Squads multisigCompensation plan and multisig migration are both independently confirmed.
  5. #5[confirmed][no action needed]in section: December 2022 Admin Key Exploit
    On December 16, 2022 at approximately 10:12 UTC, a malicious actor gained control of the Raydium Pool Owner (Admin) account and exploited eight constant product liquidity pools in the V4 AMM program.
    reviewerCompromise began at approximately 10:12 UTC on Dec 16, 2022 and patch was deployed at 14:16 UTC the same dayBoth timestamps independently corroborated via secondary reporting quoting the official post-mortem verbatim.
  6. #6[confirmed][no action needed]in section: December 2022 Admin Key Exploit
    The attacker used two mechanisms: first, abusing the withdrawPNL instruction to drain accumulated protocol fees directly from pool vaults; second, using the SetParams instruction with AmmParams::SyncNeedTake to artificially inflate need_take_pc and need_take_coin balances without corresponding trading volume, then repeatedly withdrawing those inflated figures as fees.
    reviewerAttacker used withdrawPNL and SetParams/SyncNeedTake mechanisms to drain fundsTechnical exploit mechanism is accurately and specifically described, matching independent technical writeups.
  7. #8[confirmed][no action needed]in section: December 2022 Admin Key Exploit
    Raydium's team attributed the private key compromise to a trojan program infecting the virtual machine on which the Pool Owner account was deployed, though no definitive forensic proof was published.
    reviewerRaydium attributed the compromise to a trojan program on the VM hosting the Pool Owner account, with no definitive forensic proof publishedAccurately reflects Raydium's own hedged attribution.
  8. #9[confirmed][no action needed]in section: December 2022 Admin Key Exploit
    Concentrated liquidity (CLMM) pools and the RAY staking program were not affected.
    reviewerCLMM pools and RAY staking program were not affected by the exploitConfirmed by independent technical writeups.
  9. #10[confirmed][no action needed]in section: December 2022 Admin Key Exploit
    CoinDesk reported that ZachXBT tracked the attacker bridging approximately $2 million of the stolen assets to Ethereum in real time during the incident.
    reviewerCoinDesk reported that ZachXBT tracked the attacker bridging approximately $2 million of stolen assets to Ethereum in real timeConfirmed via secondary corroboration of the underlying CoinDesk reporting; could not directly fetch the CoinDesk page due to rate limiting.
  10. #11[confirmed][no action needed]in section: Stolen Funds Laundered via Tornado Cash
    On January 19, 2023, the wallet tagged as 'Raydium Exploiter' (0xb98acc055e331a709a765569eb6854bb2f0c8282 on Ethereum) deposited a total of 1,774.5 ETH (approximately $2.7 million at the time) into Tornado Cash across 42 separate transactions.
    reviewerJanuary 19, 2023: Raydium Exploiter wallet deposited 1,774.5 ETH (~$2.7M) into Tornado Cash across 42 transactionsFigures precisely match across three independent outlets.
  11. #12[confirmed][no action needed]in section: Stolen Funds Laundered via Tornado Cash
    Tornado Cash had been placed on the U.S. Treasury Office of Foreign Assets Control (OFAC) sanctions list in November 2022, due to its alleged use by state-affiliated threat actors including North Korea-linked Lazarus Group.
    reviewerTornado Cash was placed on OFAC's sanctions list in November 2022 due to alleged use by Lazarus GroupWell-established public record; accurately summarized.
  12. #13[confirmed][no action needed]in section: Centralization Risk and Admin Key Architecture
    CertiK's post-mortem stated explicitly that 'one wallet was able to withdraw liquidity from multiple pools,' and characterized the incident as a consequence of protocols that 'are not fully decentralized' requiring accounts with access to 'critical network controls.'
    reviewerCertiK stated 'one wallet was able to withdraw liquidity from multiple pools' and described the incident as a consequence of protocols that 'are not fully decentralized' requiring accounts with access to 'critical network controls'Both quoted fragments verified word-for-word against the CertiK source.
  13. #14[confirmed][no action needed]in section: Centralization Risk and Admin Key Architecture
    In the immediate aftermath, Raydium migrated admin authority to a hardware wallet (December 16) and then to a Squads multisig (December 17).
    reviewerRaydium migrated admin authority to a hardware wallet on Dec 16 and then to a Squads multisig on Dec 17Sequence and dates match independent reporting.
  14. #15[confirmed][no action needed]in section: Centralization Risk and Admin Key Architecture
    As of 2025, Raydium updated program admin authority to Squads V4 with a 24-hour timelock.
    reviewerAs of 2025, Raydium updated program admin authority to Squads V4 with a 24-hour timelockThe underlying fact is confirmed on the current Raydium docs site, though the specific cited URL no longer resolves (see separate link_rot finding for that URL).
  15. #16[confirmed][no action needed]in section: User Compensation Program
    Following a community governance vote that passed on December 30, 2022 with 5,598,814 approvals, Raydium implemented a phased compensation plan for affected liquidity providers.
    reviewerGovernance vote passed December 30, 2022 with 5,598,814 approvals authorizing the compensation planExact figure and date verified word-for-word against the cited CertiK source.
  16. #17[confirmed][no action needed]in section: User Compensation Program
    RAY pricing for compensation was calculated using a 30-day TWAP of $0.1813 (December 6, 2022 through January 3, 2023).
    reviewerCompensation terms: RAY pools eligible for 100% recovery; six other pools received 90% native-asset recovery plus 10% shortfall in RAY at a 1:1.2 ratio, priced via a 30-day TWAP of $0.1813TWAP price, date range, and compensation ratio all verified against the cited official compensation-plan post.
  17. #18[confirmed][no action needed]in section: User Compensation Program
    The claim portal opened January 5, 2023 and was extended through May 14, 2023 to accommodate third-party integrations including Francium and Tulip leveraged vault positions.
    reviewerClaim portal opened January 5, 2023 and was extended through May 14, 2023 to accommodate Francium and Tulip leveraged vault positionsUnderlying facts confirmed via secondary excerpts of the (now-dead) cited docs page; see link_rot finding on the URL itself.
  18. #19[confirmed][no action needed]in section: January 2024 CLMM Tick Manipulation Vulnerability
    On January 10, 2024, a whitehat researcher identified as @riproprip reported a critical vulnerability in Raydium's CLMM (concentrated liquidity) program via Immunefi.
    reviewerJanuary 10, 2024, whitehat @riproprip reported a critical CLMM tick-manipulation vulnerability via Immunefi involving increase_liquidity.rs and tickarray_bitmap_extensionTechnical details and date match the Immunefi writeup precisely.
  19. #20[confirmed][no action needed]in section: January 2024 CLMM Tick Manipulation Vulnerability
    The whitehat was awarded a $505,000 bounty in RAY tokens, the maximum payout under Raydium's Immunefi program. No funds were lost as a result of this vulnerability.
    reviewerWhitehat was awarded a $505,000 bounty in RAY tokens, the maximum payout under Raydium's Immunefi program; no funds were lostBounty amount and no-loss outcome independently confirmed.
  20. #21[confirmed][no action needed]in section: Team Anonymity and Governance
    Raydium was founded by a pseudonymous team using the pseudonyms AlphaRay (strategy), XRay (technology), and GammaRay (marketing), with additional core contributors known as StingRay and RayZor.
    reviewerRaydium was founded by pseudonymous team AlphaRay (strategy), XRay (technology), GammaRay (marketing), with additional contributors StingRay and RayZor, coming from an algorithmic trading/commodities background transitioning to crypto around 2017Team pseudonyms, roles, and background narrative all corroborated by independent tertiary sources.
  21. #22[confirmed][no action needed]in section: Security Improvements and Current Status
    OtterSec conducted audits of the updated AMM, the CLMM program, and the staking program in late 2022 and early 2023.
    reviewerOtterSec audited the updated AMM, CLMM program, and staking program in late 2022 and early 2023Programs audited match exactly; the audit window is more precisely 'late 2022' than extending into 'early 2023,' a minor imprecision that does not materially mischaracterize the claim.
  22. #23[confirmed][no action needed]in section: Security Improvements and Current Status
    MadShield audited the OpenBook integration (Q2 2023) and the CPMM (constant product market maker) in Q1 2024.
    reviewerMadShield audited the OpenBook integration (Q2 2023) and the CPMM in Q1 2024Auditor, scope, and quarters all verified exactly against the public audit repository.
  23. #24[confirmed][no action needed]in section: Security Improvements and Current Status
    As of 2025–2026, Raydium remains one of the largest DEX protocols on Solana by TVL (reported at approximately $1–2.5 billion depending on timeframe) and daily trading volume.
    reviewerAs of 2025-2026, Raydium remains one of the largest DEX protocols on Solana by TVL (~$1-2.5 billion) and daily trading volumeThe wide range hedges appropriately for a volatile metric; figures fall within the cited range.
  24. #25[confirmed][no action needed]in section: Security Improvements and Current Status
    Coinbase discontinued RAY perpetual futures in April 2026 as part of a broader 25-product review, though spot trading of RAY continued.
    reviewerCoinbase discontinued RAY perpetual futures in April 2026 as part of a broader 25-product review, though spot trading continuedDate, scope (25 products), and spot-trading continuity all independently confirmed.
  25. #26[confirmed][no action needed]in the timeline
    Raydium AMM launched on Solana mainnet by pseudonymous founding team (AlphaRay, XRay, GammaRay).
    reviewerTimeline: Raydium AMM launched Solana mainnet Feb 2021Consistent with the summary claim already verified.
  26. #27[confirmed][no action needed]in the timeline
    Raydium removes exploited admin parameters from AMM V4 program and transfers remaining admin authority to Squads multisig.
    reviewerTimeline: Dec 17, 2022 Raydium removes exploited admin parameters and transfers authority to Squads multisigMatches independently corroborated post-mortem detail.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.