Post-exploit response score
Raydium's assessment for RD-F-081 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Curator score: 4/5. Compensation: 90–100% of principal + 20% bonus RAY from team vesting (strong). Transparency: detailed post-mortem published 1 day post-exploit with specific accounts and attack mechanic named (strong). Root-cause depth: trojan/remote-access suspected but exact intrusion vector not confirmed (moderate). Operational recovery: Squads multisig migration completed within ~24h (strong). User communication: Twitter + Medium + Discourse compensation proposal (strong). One deduction: unresolved intrusion vector ambiguity. 4/5 = yellow under the green ≥4/5-with-clean-remediation threshold.
Sources #
- URLRaydium — Detailed Post-Mortem and Next StepsRaydium detailed post-mortem (2022-12-17) — root cause, remediation, compensation planretrieved 2026-04-29
- Raydium Protocol Security DocumentationRaydium security page — Squads multisig migration detailsretrieved 2026-04-29
- Raydium removed the /updates/archive/ section in the 2024-2025 docs reorganization; the transparency-on-exploit-compensation-funds page is gone with no canonical replacement on docs.raydium.io. The Dec 2022 exploit compensation plan (RAY buyback treasury + vested team allocation; LPs in RAY-pairs claimed 100%, non-RAY pairs claimed 90% + 10% in RAY + 20% bonus) is documented in third-party reporting (Cointelegraph 'Raydium announces details of hack, proposes compensation for victims', CertiK 'Raydium Protocol Exploit Incident Analysis'). archive.org is blocked from this environment so a snapshot URL could not be captured. Grader to substitute a third-party citation if direct primary source needed. [dead-link, original: https://docs.raydium.io/raydium/updates/archive/transparency-on-exploit-compensation-funds]retrieved 2026-05-06
Methodology #
Curator-score (1–5) the most recent incident response on: compensation completeness, transparency of disclosure, root-cause analysis depth, and operational recovery speed.
See the full factor methodology and distribution across all protocols →