Solana-based automated market maker Aquifer has suffered an exploit that resulted in approximately $2.5 million in digital assets being drained, according to blockchain security monitoring service Defimon.
The incident involved wallets on both Solana and Ethereum, while Aquifer has offered the suspected attacker a 20% whitehat bounty in exchange for returning at least 80% of the stolen assets.
The recovery offer gives the attacker until September 3 at 14:00 UTC to return the funds to addresses provided by Aquifer.
Aquifer Offers 20% Whitehat Bounty
Following the incident, Aquifer published an on-chain message offering the suspected exploiter a deal.
The attacker can retain up to 20% of the stolen funds if at least 80% is returned before the deadline.
Aquifer also said it would not pursue civil claims arising from the incident if the conditions are satisfied, subject to applicable law.
The agreement does not prevent law enforcement agencies, regulators or other government authorities from taking action.
The recovery addresses cover both Solana and Ethereum, reflecting the cross-chain movement of assets linked to the exploit.
Exploit Affected a Large Portion of Aquifer's TVL
Aquifer operates as a proprietary automated market maker on Solana, providing liquidity for token swaps.
According to DeFiLlama, the protocol had roughly $2.8 million in total value locked, meaning the reported $2.5 million loss represents a substantial portion of the liquidity associated with the protocol.
Defimon identified separate Solana and Ethereum addresses allegedly controlled by the attacker.
However, the exact method used to gain access to the funds remains unclear.
Aquifer has not yet released a detailed technical post-mortem confirming whether the incident involved compromised private keys, administrator credentials, operational infrastructure or a vulnerability in its smart contracts.
That distinction is important because a wallet compromise and a smart-contract exploit carry very different implications for other Solana protocols.
No Evidence Yet of a Solana Blockchain Vulnerability
Current information does not establish that Solana itself was exploited.
The incident involved wallets operating across Solana and Ethereum, but cross-chain activity alone does not reveal the original point of compromise.
Aquifer has yet to explain whether an attacker gained control of privileged accounts, compromised signing infrastructure or exploited a specific piece of protocol code.
Until a technical investigation is published, the exact attack vector remains unknown.
Solana DeFi Has Faced Multiple Attack Vectors
Aquifer's incident comes after several other attacks involving Solana-based protocols.
Earlier this year, an attacker exploited legacy Raydium liquidity pools, resulting in approximately $1.3 million in losses. Raydium said its active pools were not affected because the vulnerable infrastructure had already been retired.
Another incident involving Across Protocol resulted in losses of less than $4 million after attackers generated fraudulent Solana deposit events. The issue was later attributed to a flaw in off-chain event-reading infrastructure rather than Solana's blockchain or Across' smart contracts.
These incidents highlight an important trend: crypto exploits do not always originate from the underlying blockchain or smart-contract logic.
They can also involve:
Private keys
Wallet infrastructure
Admin credentials
Off-chain systems
Oracles
Relayers
Legacy contracts
User interfaces
Wallet Security Remains a Major Risk
Wallet compromises have become an increasingly important source of cryptocurrency losses.
A similar incident involving payments company Triple-A saw unauthorized access to treasury wallets across multiple blockchain networks. The company later said customer funds were segregated from the affected treasury infrastructure.
The incidents demonstrate why security assessments need to extend beyond smart-contract audits.
A protocol can have audited contracts while still being vulnerable through compromised signing devices, administrative wallets or other operational systems.
For Aquifer, determining the initial point of access will therefore be critical to understanding the full impact of the incident.
What Happens Next?
The immediate focus is now on recovering the stolen assets.
Aquifer's whitehat offer expires on September 3 at 14:00 UTC, giving the suspected attacker a limited window to return at least 80% of the funds.
The next major development will likely be a technical post-mortem explaining:
How the attacker gained access
Which wallets were compromised
Whether smart contracts were involved
How much was ultimately recovered
What security measures will be introduced
Until those details are released, users should treat the exact cause of the exploit as unconfirmed.
Bottom Line
Solana AMM Aquifer has reportedly lost around $2.5 million in an exploit involving assets and wallets across Solana and Ethereum.
The protocol has offered the attacker a 20% bounty to return at least 80% of the funds by September 3.
While the incident highlights continued security risks across Solana DeFi, there is currently no evidence that the Solana blockchain itself was compromised.
The most important unanswered question is how the attacker gained access to Aquifer's funds.
A detailed post-mortem will determine whether the incident was caused by a smart-contract vulnerability, compromised wallet infrastructure or another operational security failure.