
Solana-based automated market maker Aquifer has lost approximately $2.5 million in an exploit involving wallets on both Solana and Ethereum networks. According to reports from Odaily Planet Daily, the attack was identified on August 31, with separate addresses on both blockchains controlled by the suspected exploiter. The protocol has responded by offering the attacker a 20% whitehat bounty if at least 80% of the assets are returned by September 3 at 22:00 UTC. On-chain data shows the whitehat offer was broadcast across major altcoins for monitoring purposes.
As reported by Odaily Planet Daily, Aquifer's whitehat message was authorized through the protocol's Solana upgrade authority and published on-chain. The protocol supplied separate recovery addresses for both Solana and Ethereum networks, allowing assets associated with the attack to be returned on either chain. The attacker may retain up to 20% of the funds as a whitehat bounty if the conditions are met, with Aquifer committing not to pursue civil claims if the terms are complied with, subject to applicable law. The team has pledged not to pursue legal action if the attacker complies with the recovery terms.
According to Odaily Planet Daily, the exploit involved the Solana address 7fTe9pvrwXJRBHq9MaSyVPR4PgEuhqLiA93Dxf4gRk7J and Ethereum address 0x2Dfe9e969796e2797278b02761dd9Ad6aE922746. DefiLlama describes Aquifer as a proprietary automated market maker on Solana with total value locked at approximately $2.8 million. The exact point of compromise remains unclear, with no technical post-mortem yet establishing how access to the affected wallets was obtained, though available information does not indicate Aquifer's smart contract code was exploited. This incident highlights ongoing security challenges in DeFi, especially related to wallet access rather than smart contract vulnerabilities.
This incident follows several Solana-related attacks in 2026 where compromised wallet access has become a major attack route. In June, Raydium lost approximately $1.3 million after an attacker targeted retired AMM infrastructure using fake mint addresses. A separate July incident involving Across Protocol produced losses of less than $4 million after an attacker fabricated Solana deposit events. Private key and wallet compromises have accounted for a substantial portion of crypto thefts in 2026, with CertiK reporting digital asset losses of $1.32 billion during the first half of the year, down 46.8% from the same period in 2025.