Aquifer, a Solana automated market maker, lost about $2.5 million in an exploit spanning Solana and Ethereum wallets, offering the attacker a 20 percent bounty.
Blockchain security monitoring service Defimon reported the attack on Aug. 31, identifying separate Solana and Ethereum addresses controlled by the suspected exploiter. Aquifer later published an on-chain whitehat offer seeking the return of at least 80 percent of the assets linked to the incident.
The offer gives the attacker until Sept. 3 at 14:00 UTC to transfer the assets, or their equivalent value, to recovery addresses provided by Aquifer. The person controlling the wallets may retain up to 20 percent of the funds as a whitehat bounty if the conditions are met. Aquifer said it would not pursue civil claims arising from the exploit if the attacker complies, subject to applicable law.
Aquifer operates as a proprietary automated market maker on Solana, where its liquidity supports token swaps. DefiLlama lists the protocol's total value locked at about $2.8 million. The incident follows several Solana-related attacks this year where the point of compromise sat outside the underlying blockchain.
Defimon linked the Solana address 7fTe9pvrwXJRBHq9MaSyVPR4PgEuhqLiA93Dxf4gRk7J and the Ethereum address 0x2Dfe9e969796e2797278b02761dd9Ad6aE922746 to the attacker. Aquifer's whitehat message was authorized through the protocol's Solana upgrade authority and published on-chain, with separate recovery addresses supplied for each network.
Public information has not yet established exactly how the wallets were compromised. No technical post-mortem has been released explaining whether private keys, administrator credentials or another part of Aquifer's operational infrastructure was exposed. Available information similarly does not establish that Aquifer's smart contract code was exploited.
The pattern echoes earlier Solana incidents. In June, five legacy liquidity pools belonging to Raydium lost roughly $1.3 million after an attacker targeted retired AMM infrastructure, with on-chain investigator Specter saying the attacker used a fake mint address to bypass validation checks in an older AMM program. Raydium said its active pools were unaffected and committed to reimbursing the assets from its treasury.
A separate July incident involving Across Protocol produced losses of less than $4 million after an attacker fabricated 1,627 fake Solana deposit events with a combined stated value of $41.7 million. Risk Labs' relayer processed 581 of the fraudulent requests before Solana operations were suspended, advancing about $4.5 million of its own capital.
Wallet access has become a major attack route across the industry. CertiK reported in July that digital asset losses reached $1.32 billion during the first half of 2026, down 46.8 percent from the same period in 2025, with wallet compromises replacing phishing as the largest attack method during the second quarter. Step Finance, another Solana project, shut down after an attack this year moved about 261,854 SOL, with later estimates placing total losses near $40 million.
For Aquifer, the recovery process centers on its whitehat proposal. The attacker has been offered the right to retain up to 20 percent of the assets if at least 80 percent is returned to the designated recovery addresses by Sept. 3 at 14:00 UTC. Whether the breach erodes user confidence in Solana DeFi will depend on how quickly the protocol publishes a post-mortem identifying the initial point of access.
This article is for informational purposes only and does not constitute investment advice.