Protocol Security

Solana AMM Aquifer Hit by $2.5 Million Exploit, Offers 20% Bounty

Solana-based automated market maker Aquifer has suffered an approximate $2.5 million loss following an incident involving wallets across Solana and Ethereum, according to blockchain security monitoring service Defimon. The protocol has proposed a whitehat arrangement offering the attacker a twenty percent bounty if at least eighty percent of the compromised funds are returned, though the precise mechanism of the intrusion remains not officially confirmed.

Digital risk intelligence graphic representing multi-chain wallet exploit monitoring.
Image: crypto.news

Overview of the Incident and Multi-Chain Activity

Blockchain security monitoring service Defimon initially flagged the unauthorized activity affecting the Solana-based automated market maker Aquifer, identifying compromised addresses spanning multiple blockchain networks. According to public reporting, the losses are estimated at approximately $2.5 million, with distinct addresses utilized on both the Solana and Ethereum ecosystems to move the digital assets. The proprietary automated market maker, which facilitates token swaps and maintains a total value locked reported around $2.8 million by DefiLlama, suddenly found its operational security compromised through mechanisms that required urgent investigation by protocol administrators and independent security researchers alike.

The involvement of multiple blockchain networks in the movement of stolen funds demonstrates the growing complexity of cross-chain security incidents within the decentralized finance sector. Security analysts observed that the suspected attacker quickly established transfer pathways connecting Solana addresses with Ethereum counterparts, creating an immediate trail for on-chain investigators to track. This multi-chain footprint underscores the necessity for comprehensive monitoring tools capable of detecting anomalous transaction flows across disparate ledger environments before significant capital can be laundered through mixing services or decentralized exchanges.

Whitehat Bounty Proposal and Recovery Terms

In response to the financial drain, Aquifer authorized an on-chain whitehat message utilizing the protocol's Solana upgrade authority to communicate directly with the suspected exploiter. The recovery proposal communicated through the blockchain stipulated that the individual or group controlling the compromised wallets could retain up to twenty percent of the extracted funds as a whitehat bounty. To qualify for this arrangement, the recipient was required to transfer at least eighty percent of the assets, or their equivalent value, back to designated recovery addresses established separately for Solana and Ethereum.

The on-chain message established a strict deadline for compliance while offering specific legal assurances under applicable law if the conditions were met. Aquifer stated that it would refrain from pursuing civil litigation claims arising directly from the exploit should the attacker fulfill the return requirements within the specified timeframe. However, the protocol explicitly clarified that the agreement would not bind external law enforcement agencies, regulatory bodies, sanctions authorities, or any other government entities from pursuing independent investigations or legal actions against the perpetrators.

Lack of Official Post-Mortem and Vulnerability Context

Despite extensive tracking of the stolen assets across multiple networks, available public information has not established the exact initial vector of compromise. No formal technical post-mortem has been published by Aquifer to clarify whether private keys, administrator credentials, or other critical components of the platform's operational infrastructure were exposed to unauthorized parties. Furthermore, preliminary assessments indicate that Aquifer's smart contract code itself was not directly exploited, distinguishing this event from traditional protocol logic flaws where automated code execution drains liquidity pools without prior credential theft.

This incident aligns with a broader industry trend observed throughout the year wherein operational security failures and wallet access compromises have superseded smart contract code vulnerabilities as a primary source of digital asset losses. Security firm reports indicate that private key and endpoint compromises have increasingly affected various decentralized finance projects, leading to substantial financial damages and, in some severe cases, complete protocol wind-downs. Without a detailed technical disclosure from Aquifer, distinguishing between compromised administrative endpoints and other infrastructure weaknesses remains provisional for external observers.

Broader Ecosystem Impact and Comparable Solana Incidents

The Aquifer event follows several notable security breaches within the Solana ecosystem that highlighted different attack vectors and operational vulnerabilities over recent months. Earlier incidents involving legacy liquidity pools and off-chain event-reading software demonstrated that peripheral infrastructure often presents significant risk to protocols operating on high-speed blockchain networks. For instance, legacy pools and cross-chain bridge integrations have previously suffered substantial financial extraction due to outdated validation checks or software reading errors rather than inherent weaknesses in the underlying blockchain consensus mechanism.

As decentralized platforms continue to integrate multi-chain functionalities and rely on complex operational setups, the attack surface extends well beyond core smart contract architecture. Security analysts emphasize that executive device compromises, compromised treasury wallets, and flawed off-chain relayers represent persistent threats across the digital asset landscape. The recurrence of these non-contractual exploits necessitates a fundamental reassessment of institutional custody practices, multi-signature administrative controls, and endpoint security standards among emerging and established crypto projects alike.

Conclusion and Actionable Protocol Next Steps

In conclusion, blockchain security monitoring service Defimon reported that Solana-based automated market maker Aquifer suffered an approximate $2.5 million loss resulting from an exploit involving wallets on Solana and Ethereum. While the protocol has issued an on-chain whitehat bounty proposal offering the attacker a twenty percent retention reward for returning at least eighty percent of the assets by September 3, the precise intrusion mechanism, initial vector, and vulnerability details remain not officially confirmed by an authoritative technical post-mortem.

The affected entity is Aquifer, and the primary user group impacted includes liquidity providers and protocol participants whose operational stability depends on secure infrastructure. Moving forward, the required change involves strict verification of multi-chain wallet controls and heightened transparency regarding administrative access, while the immediate next action for users is to monitor official communications while avoiding unverified links or fraudulent recovery scams.

Cexvia conclusion

Incident Status and Operational Next Steps

Blockchain security monitoring service Defimon reported that Solana-based automated market maker Aquifer experienced losses totaling approximately $2.5 million via addresses spanning Solana and Ethereum. While the protocol has extended a conditional whitehat recovery proposal, the exact intrusion vector and whether smart contracts were compromised remain not officially confirmed.

Risk meaning
The incident highlights ongoing vulnerabilities related to multi-chain operational wallets and administrative infrastructure within decentralized finance platforms. When wallet access is compromised without apparent smart contract code flaws, projects face complex recovery challenges that require immediate on-chain negotiation and transparent post-mortem analysis to restore user confidence.
User action
Users interacting with protocols affected by operational or multi-chain wallet compromises should monitor official communication channels for verified updates regarding recovery efforts. Participants must remain vigilant against potential phishing attempts or unauthorized communications purporting to represent the affected project during active security incidents.
Aquifer