Whitehat discovers critical Raydium protocol vulnerability, receives $505,000 bounty


8 recorded changes
Want your article here?
Promote with Leviathan News

8 recorded changes
Want your article here?
Promote with Leviathan NewsA bug bounty review published by Immunefi describes how a whitehat hacker uncovered a critical vulnerability in the Raydium protocol’s concentrated liquidity market maker (CLMM) and was awarded a $505,000 bounty under Raydium’s Immunefi program. The issue, reported on January 10, 2024 by the whitehat known as @riproprip, involved a “tick manipulation” bug in Raydium’s CLMM implementation that could have enabled an attacker to drain user funds from impacted pools. Raydium’s TVL was significant and the bug was classified as critical because it directly threatened user assets in core smart contracts. According to Immunefi’s program terms, critical smart contract vulnerabilities can earn up to 10% of the funds at risk, capped at $505,000, which is the maximum payout level that was granted in this case. The Raydium team worked with the reporter to confirm the issue, deploy fixes, and prevent exploitation before disclosure, highlighting the growing role of formal bug bounty programs in securing DeFi infrastructure on Solana. The incident also underscores Raydium’s broader security posture, which has evolved from earlier security incidents toward structured incentives for responsible disclosure through Immunefi and its own published bounty scales.
AI-generated background, compiled from web sources — not editorial content.

𝕏/@Raydium ·

The Block ·

𝕏/@Raydium ·

CoinTelegraph ·

crypto.news ·

Blockworks ·

𝕏/@Raydium ·

The Block ·

𝕏/@Raydium ·

CoinTelegraph ·

crypto.news ·

Blockworks ·
🚀 Love DeFi? Ready to dive in and start earning $SQUID while making an impact?