"Radium" Solana Scams: Spotting Fake Raydium Tokens and Sites
"Radium" Solana Scams: Spotting Fake Raydium Tokens and Sites
Written by Marcus Chen, Research Fellow. Reviewed by Dr. Sarah Mitchell, Blockchain Security Analyst. Updated August 26, 2026.
Before anything else, a quick correction: the project people mean when they type radium solana is Raydium, spelled with a y, a decentralized exchange on Solana. That one letter matters because the misspelling is exactly what fraudsters use to slip fake tokens and copycat sites in front of unsuspecting searchers. This guide focuses on safety, showing the warning signs and a repeatable way to verify what is real.
How does the "radium" misspelling lead to scams?
The misspelling gives scammers a ready made disguise. Because radium looks like a believable variant of Raydium, fraudulent tokens and websites adopt it to appear connected to the real project. People who typed the wrong word are then more likely to accept whatever lookalike appears in front of them.
Search behavior does the rest of the work. A common misspelling attracts its own results, some of which are deliberately built to intercept that traffic. A page can rank or advertise against radium solana and present a polished imitation of the genuine exchange.
The mechanism is simple but effective. Attackers do not need to break any technology; they only need a name that feels close enough to trusted. That is why correcting the spelling and verifying the source, rather than trusting appearances, is the core defense.
What do fake Raydium sites and lookalike tokens look like?
Fake sites usually copy the real design closely while living on a slightly different domain, such as an added word, a swapped letter, or an unusual ending. Lookalike tokens copy the RAY name, symbol, or logo but carry a different on-chain mint address. The imitation is cosmetic, not structural.
On the website side, the giveaways are in the address bar rather than the page body. A clone can reproduce every graphic and paragraph, so the visual match tells you nothing. What it cannot easily fake is the exact official domain, which is why the domain is the thing to read carefully.
On the token side, the deception relies on names being freely reusable. Anyone can mint a Solana token and label it RAY or radium with a matching logo. The blockchain, however, identifies a token by its unique mint address, and that address is what the imitation cannot share with the genuine RAY.
How to tell a real Raydium (RAY) token from a "radium" scam lookalike: step by step
To confirm a token is the genuine RAY, get the official mint address from the real site, open a trusted Solana explorer, and compare the full address rather than the name. On-chain data, not branding, is what proves authenticity.
Step 1: Get the official mint address
Find the official RAY token mint address on the genuine Raydium site rather than from a chat message or advertisement. This published value becomes your single reference point.
Step 2: Open a reputable explorer
Open a reputable Solana block explorer that you reached directly instead of through a link someone sent you. Reaching it yourself avoids a spoofed explorer built to confirm a fake.
Step 3: Compare the full mint address
Paste the token's mint address into the explorer and compare it against the official one character by character across the whole string. Lookalikes often match at the start and end while differing in the middle.
Step 4: Review the on-chain history
Check the token's holders, age, and transfer history on the explorer, since a genuine token shows a long and consistent record. A brand new token with almost no history is a warning sign.
Step 5: Reject name-only matches
Reject any token that matches only by name, symbol, or logo but not by the exact official mint address. If the address does not match, the branding is irrelevant.
Why is the token name never enough to trust it?
Because token names on Solana are not unique. Anyone can create a token and give it any name, symbol, or logo they choose, including RAY or radium. The blockchain distinguishes tokens by their mint address, so the visible name carries no guarantee of authenticity at all.
This is a deliberate feature of open token standards, not a flaw. Permissionless creation is what lets legitimate projects launch freely, but the same openness lets bad actors clone a name in seconds. The safeguard was never meant to be the label; it was always the unique address underneath.
Practically, this means your trust should attach to a verified mint address you have checked once and saved, not to a familiar word on a screen. A matching name with a different address is the single most common shape of a token scam.
What are the biggest red flags to walk away from?
The clearest red flags are a request for your recovery phrase, pressure to act immediately, a domain that is almost but not quite right, and a token identified only by name. Any one of these is reason to stop and verify from the official source before doing anything else.
| Red flag | Why it matters | Safer response |
|---|---|---|
| Asks for your recovery phrase | Gives away full control of funds | Never enter it anywhere |
| Urgency or countdown timers | Rushes you past verification | Slow down and check the source |
| Almost-correct domain | Signals a clone site | Type raydium.io yourself |
| Token known only by name | Names are freely copyable | Verify the exact mint address |
None of these checks take long once they are habit. The aim is a routine you run every time rather than occasional caution, so that a single distracted click does not become a costly mistake. Fraud relies on speed and familiarity, and a steady verification habit removes both.
Can you recover funds after interacting with a fake?
Often you cannot. On-chain transactions are generally irreversible, so funds sent to a scam are usually gone. The realistic response is damage control: stop further approvals, review and revoke token permissions tied to the suspicious contract, and move remaining assets to a fresh wallet.
If you signed an approval rather than sending funds outright, acting quickly can still help. An approval grants a contract permission to move certain tokens later, and revoking it from your wallet closes that door before it is used. Reviewing your active approvals periodically is a sound habit even when nothing has gone wrong.
The larger lesson is that prevention carries almost all of the weight in this space. Because recovery is rarely possible, the checks described above are not optional polish; they are the main protection you have, and running them before you act is far cheaper than trying to respond afterward.
Frequently asked questions
Does the real Raydium ever ask for my recovery phrase?
No. A genuine decentralized protocol never needs your secret recovery phrase, and entering it hands full control of your funds to whoever asked. Any page or message requesting that phrase is fraudulent regardless of how closely it resembles Raydium.
Can a fake site look identical to the official one?
Yes. Copying a website's appearance is trivial, so a clone can match the colors, layout, and wording exactly. The reliable difference is the domain name and the on-chain data, not the visual design, which is why you should verify the address rather than the look.
What is the official Raydium website address?
The official domain is raydium.io. Typing it yourself and saving it as a bookmark avoids the lookalike domains that lean on the radium misspelling, small letter swaps, or extra words tacked onto the name.
Should I trust a token just because a wallet displays its logo?
No. Logos and names are set by whoever created the token and can be copied freely, so a familiar image is not proof of authenticity. Only the exact mint address confirms that a token is the genuine RAY rather than a lookalike.