Crypto news report · source clearly identified

Solana AMM Aquifer hit by $2.5 million exploit, offers 20% bounty

Solana-based automated market maker Aquifer has lost roughly $2.5 million in an exploit involving wallets on Solana and Ethereum, with the protocol offering the attacker a 20% bounty for returning most of the funds.

Solana‑based automated market maker Aquifer suffered an estimated $2.5 million loss after an attacker accessed wallets on both Solana and Ethereum. The protocol has issued a white‑hat bounty, offering the attacker up to 20 % of the recovered amount if at least 80 % of the assets are returned by September 3.

Details of the exploit

Defimon, a blockchain security monitoring service, reported the incident on August 31. The attacker controlled a Solana address (7fTe9pvrwXJRBHq9MaSyVPR4PgEuhqLiA93Dxf4gRk7J) and an Ethereum address (0x2Dfe9e969796e2797278b02761dd9Ad6aE922746). The breach appears to involve compromised wallet access rather than a vulnerability in Aquifer’s smart‑contract code, though a technical post‑mortem has not been released.

White‑hat bounty offer

Aquifer’s on‑chain message, authorized by its Solana upgrade authority, proposes the following terms:

  • Return at least 80 % of the stolen assets to designated recovery addresses on Solana and Ethereum.
  • The deadline for the transfer is September 3, 14:00 UTC.
  • If the conditions are met, the attacker may retain up to 20 % of the assets as a bounty.
  • Aquifer will not pursue civil claims if the bounty terms are satisfied, subject to applicable law.

Context of similar attacks

Recent incidents on Solana have highlighted operational security failures rather than smart‑contract bugs. Examples include:

  • Raydium’s legacy pools lost about $1.3 million after a fake mint address was used to bypass validation checks.
  • Across Protocol suffered under $4 million in losses when fabricated Solana deposit events were processed by an off‑chain relayer.
  • Step Finance shut down after device compromises allowed attackers to move roughly 261,854 SOL, valued near $40 million.

What’s next?

Investigators are tracking the cross‑chain asset flow, but the exact method of wallet compromise remains unknown. Aquifer has not published a detailed technical analysis, leaving the community awaiting clarification on whether private keys, administrator credentials, or another component of its infrastructure was exposed.

Source & attribution

News Source

Publisher
crypto.news
Original date
September 1, 2026, 6:55 AM
Original headline
Solana AMM Aquifer hit by $2.5 million exploit, offers 20% bounty
View original report ↗