Home / News / DeFi / Solana AMM Protocol Aquifer Exploit Drains $2.5 Million, 20% Bounty

Written By

Solana AMM Protocol Aquifer Exploit Drains $2.5 Million, 20% Bounty

Solana AMM Protocol Aquifer Exploit Drains $2.5 Million, 20% Bounty
Solana AMM Protocol Aquifer Exploit Drains $2.5 Million, 20% Bounty

What to Know

  • $2.5 million was stolen from Solana AMM protocol Aquifer in an exploit reported Aug. 31.
  • Aquifer offered the attacker a 20% bounty for returning the stolen funds.
  • The attacker has until Sept. 3 at 14:00 UTC to send back at least 80% of the assets.
  • CertiK tracked $1.32 billion in total crypto losses during the first half of 2026, down 46.8%.

The Aquifer exploit drained $2.5 million from the Solana automated market maker on Aug. 31, 2026. The attack hit wallets on both Solana and Ethereum. Aquifer has offered the attacker a 20% bounty to return the rest.

What Happened in the Aquifer Exploit?

Blockchain security monitor Defimon flagged the Aquifer $2.5 million exploit on Aug. 31, 2026, hours after the attacker began moving funds. The firm traced the drain to one Solana wallet and one Ethereum wallet linked to the same person. Both addresses were flagged within minutes of the first outbound transfer, giving Aquifer a narrow window to respond.

Defimon identified the Solana address 7fTe9pvrwXJRBHq9MaSyVPR4PgEuhqLiA93Dxf4gRk7J. It also flagged the Ethereum address 0x2Dfe9e969796e2797278b02761dd9Ad6aE922746. Aquifer says both belong to the same person.

Aquifer runs as a proprietary automated market maker on Solana, known as a prop AMM. The protocol uses its own liquidity to power token swaps. It does not pool funds from outside liquidity providers the way many DeFi platforms do.

The exploit adds Aquifer to a growing list of Solana-linked projects targeted this year. Most of these cases share one trait. The attackers did not need to break the underlying blockchain to succeed.

ETH price and market data
Source: CoinMarketCap

What Is Aquifer’s 20% Whitehat Bounty Deal?

Aquifer is offering the attacker a whitehat deal following the Aug. 31 breach. The attacker can keep 20% of the stolen funds, roughly $500,000 of the $2.5 million total. In return, they must send back at least 80% of the assets, worth close to $2 million, to Aquifer’s recovery addresses before the deadline.

The offer comes with a strict deadline. The attacker has until Sept. 3 at 14:00 UTC to act. Funds must go to recovery addresses set up by Aquifer.

Aquifer published the offer on-chain. The message went out through the protocol’s Solana upgrade authority. Separate recovery addresses exist for both Solana and Ethereum, so the attacker can return funds on either network.

Aquifer said it will not pursue civil claims if the attacker meets the terms. That promise depends on applicable law. It also does not bind police, regulators, or sanctions authorities.

Whitehat deals like this one have become a common response to crypto hacks. Projects offer a cut of the stolen funds in exchange for the rest coming back quietly. The approach avoids costly legal fights and can return most of the money faster than a lawsuit.

Aquifer’s $2.8 Million TVL and Prop AMM Model

What Is a Prop AMM?

Data tracker DefiLlama tracks the Aquifer $2.8 million total value locked figure for the protocol. DefiLlama labels Aquifer a prop AMM. That means the protocol supplies its own liquidity instead of pooling funds from outside users.

A $2.8 million TVL is small next to many Solana projects. Still, the exploit shows smaller protocols face real security risk too. Attackers do not always need a huge target to walk away with meaningful funds.

A prop AMM differs from typical decentralized exchanges. Regular AMMs like Uniswap or Raydium pool liquidity from many outside users. A prop AMM instead relies on the protocol’s own capital, which can limit how many people are exposed when something goes wrong.

Other Solana Exploits Show a Pattern in 2026

The Aquifer hack is not an isolated case. Several Solana-linked attacks this year did not break smart contract code directly. Instead, attackers found weak points outside the blockchain itself.

In June, Solana project Raydium lost about $1.3 million. Attackers targeted five retired liquidity pools no longer active. On-chain investigator Specter said the attacker used a fake mint address to bypass validation checks in an older AMM program.

The stolen assets included 150,177 RAY, 5,603 SOL, and 893,700 USDC. Raydium said its active pools and current users were not affected. The vulnerable infrastructure had already been phased out. Raydium committed to repaying the loss from its treasury.

A separate incident hit Across Protocol in July. Losses there stayed under $4 million. The attacker created 1,627 fake Solana deposit events worth a stated $41.7 million.

Risk Labs’ relayer processed 581 of the fraudulent requests before Solana operations were paused. The relayer advanced about $4.5 million of its own capital. Roughly $500,000 tied to the attacker stayed trapped, keeping the net loss under $4 million.

Across later said the flaw sat in Risk Labs’ off-chain event-reading software. Neither its smart contracts nor the Solana network were at fault. Legitimate user transfers were completed or refunded.

A pattern shows up across each case. Raydium’s flaw sat in retired code. Across Protocol’s flaw sat in off-chain software. Step Finance’s flaw sat in compromised employee devices. None of these attacks needed a break in Solana’s core network itself.

Wallet Compromises Now Drive Most Crypto Losses

Stablecoin payments firm Triple-A confirmed a treasury breach in July. Attackers gained unauthorized access to company wallets. Researchers first tracked suspicious withdrawals across Ethereum, Solana, TRON, and TON. Some reports also flagged activity on Polygon and Arbitrum.

Triple-A said client funds stayed safe. Customer assets were kept apart from the compromised treasury systems. Researchers had estimated the loss near $11.8 million before the firm confirmed the breach. Triple-A said cybersecurity specialists and Singapore police are investigating.

Solana project Step Finance shut down entirely after a separate attack this year. Hackers targeted devices used by the team’s executives. They gained access to treasury and fee wallets. About 261,854 SOL moved out, with total losses near $40 million.

Investigators found Step Finance’s smart contracts were not the entry point. Compromised devices gave attackers wallet access instead. The financial hit later pushed the team to close the platform for good.

Security firm CertiK tracked the wider trend. The CertiK $1.32 billion crypto losses H1 2026 figure covers the first half of the year, down 46.8% from the same period in 2025. CertiK said wallet compromises became the top attack method in the second quarter, passing phishing.

No Post-Mortem Yet From Aquifer

Aquifer has not released a technical post-mortem. The report has not said whether private keys were exposed. It also has not named which credentials or systems were compromised.

Public information does not show that Aquifer’s smart contract code was exploited. The addresses on Ethereum and Solana give investigators a trail to follow. That trail alone does not explain how the funds were first accessed.

The recovery process now rests on the whitehat offer. The attacker can keep 20% of the funds. The deadline to return the rest is Sept. 3 at 14:00 UTC.

Users of Aquifer and similar small Solana protocols now face a familiar wait. They need to see whether the attacker takes the bounty offer. They also need Aquifer to explain how the breach happened in the first place.

Frequently Asked Questions

What happened in the Aquifer exploit?

Solana-based AMM protocol Aquifer lost about $2.5 million in an exploit reported on Aug. 31, 2026. Blockchain security monitor Defimon traced the attack to linked wallets on both Solana and Ethereum. Aquifer confirmed the incident and quickly began its recovery process the same day.

What is Aquifer's whitehat bounty offer?

Aquifer is offering the attacker a 20% bounty. In exchange, the attacker must return at least 80% of the stolen funds. The deadline is Sept. 3 at 14:00 UTC, sent to Aquifer’s recovery addresses on Solana and Ethereum. Aquifer says it will not pursue civil claims if the attacker complies.

How much crypto has been stolen in 2026?

CertiK reported $1.32 billion in digital asset losses during the first half of 2026. That figure is down 46.8% from the same period in 2025. Wallet compromises passed phishing as the top attack method in the second quarter, according to CertiK’s mid-2026 security report.

Was Aquifer's smart contract code hacked?

Public information does not confirm that Aquifer’s smart contract code was exploited. No post-mortem has explained how the wallets were compromised. Investigators have not said whether private keys or credentials were exposed in the attack. The exploit instead relied on wallet access gained outside the blockchain itself.

This article is for informational purposes only and does not constitute investment advice. Every investment and trading decision involves risk. Readers should conduct their own research before making any financial decisions.

Share With Your Network :

Facebook
X
LinkedIn
Pinterest
Reddit
Telegram
WhatsApp
Email
Threads

Elena Vasquez

Elena Vasquez is a DeFi and Technology Writer at TheCryptoWorld, covering the technical side of blockchain — from Layer 1 protocols and scaling solutions to decentralized finance, smart contract security, and the intersection of AI and crypto. With a computer science background and experience as a blockchain developer, Elena brings hands-on technical expertise to her writing. She’s passionate about making complex protocol mechanics accessible to a broad audience without sacrificing accuracy.
0 0 votes
Article Rating
Subscribe
Notify of
guest

6 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
Priya Venkatesh
Priya Venkatesh
9 days ago

20% bounty is generous but the real question is whether the exploiter used a flash loan to manipulate the pool ratios or found a rounding bug in the swap math. Aquifer’s post-mortem better include the exact tx hash.

Viktor Novak
Viktor Novak
9 days ago

another solana amm drained, shocker

Marco Reinhardt
Marco Reinhardt
9 days ago

Skeptical of the whitehat framing here. $500k walk-away money is nice but if the attacker already laundered through Wormhole or a mixer, that bounty offer is just optics for the community.

Tomas Lindqvist
Tomas Lindqvist
9 days ago

Been watching solana defi since the Mango episode in 2022 and the pattern rarely changes: unaudited AMM launches, TVL climbs, one bad invariant check drains it. Aquifer is just the latest name on a long list.

Jonah Beckett
Jonah Beckett
9 days ago

$2.5M drain on Aug 31 and I hadn’t even heard of Aquifer until today, curious how much TVL they had before the exploit and whether any LPs are getting made whole outside the bounty recovery?

Arjun Bhatt
Arjun Bhatt
9 days ago

Does anyone know if the Aquifer team has published the vulnerable contract address yet? Want to check if any of the forks running similar code are exposed.

Table of Contents

Check also

Specific Crypto details

Fear & greed index
49
▲ +4 from yesterday
Updated: April 11, 2026
▼ Fear
Recovering from extreme fear
0
Extreme fear
25
Fear
50
Neutral
75
Greed
100
Extreme greed
Yesterday
45
Fear
Last week
30
Fear
April 8
11
Extreme fear
0 0 votes
Article Rating
Subscribe
Notify of
guest

6 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
Priya Venkatesh
Priya Venkatesh
9 days ago

20% bounty is generous but the real question is whether the exploiter used a flash loan to manipulate the pool ratios or found a rounding bug in the swap math. Aquifer’s post-mortem better include the exact tx hash.

Viktor Novak
Viktor Novak
9 days ago

another solana amm drained, shocker

Marco Reinhardt
Marco Reinhardt
9 days ago

Skeptical of the whitehat framing here. $500k walk-away money is nice but if the attacker already laundered through Wormhole or a mixer, that bounty offer is just optics for the community.

Tomas Lindqvist
Tomas Lindqvist
9 days ago

Been watching solana defi since the Mango episode in 2022 and the pattern rarely changes: unaudited AMM launches, TVL climbs, one bad invariant check drains it. Aquifer is just the latest name on a long list.

Jonah Beckett
Jonah Beckett
9 days ago

$2.5M drain on Aug 31 and I hadn’t even heard of Aquifer until today, curious how much TVL they had before the exploit and whether any LPs are getting made whole outside the bounty recovery?

Arjun Bhatt
Arjun Bhatt
9 days ago

Does anyone know if the Aquifer team has published the vulnerable contract address yet? Want to check if any of the forks running similar code are exposed.

Solana ETF Inflows Overtake XRP as SOL Nears $100

Altcoin Predictions

2 weeks ago

Solana ETF Inflows Overtake XRP as SOL Nears $100

Sarah Chen

Satoshi Nakamoto's Bitcoin Holdings Surge as BTC Nears $81K

Bitcoin

2 weeks ago

Satoshi Nakamoto’s Bitcoin Holdings Surge as BTC Nears $81K

James Wright

Ripple's Evernorth Gets SEC Approval for Nasdaq XRP Listing

Altcoins

2 weeks ago

Ripple’s Evernorth Gets SEC Approval for Nasdaq XRP Listing

James Wright

Bitwise Solana ETF Tops $1 Billion as SOL Price Rally Continues Higher

Altcoins

2 weeks ago

Bitwise Solana ETF Tops $1 Billion as SOL Price Rally Continues Higher

James Wright

Market Analysis

The Future of Crypto, Covered Daily

Real-time news, expert analysis, and market insights  trusted by thousands of crypto investors worldwide.

You have been successfully Subscribed! Ops! Something went wrong, please try again.
6
0
Would love your thoughts, please comment.x
()
x