Solana-based proprietary AMM Aquifer suffered a major liquidity-vault drain on August 31.
The strongest current evidence comes from independent on-chain reconstruction rather than an Aquifer technical post-mortem.
Bitquery calculates approximately $2.47 million removed from Aquifer token vaults across 212 settlements in roughly 40 minutes. In the reconstructed transactions, Aquifer paid real assets while receiving no matching input token payment.
How the exploit appears to have worked
The evidence points to a trust-boundary failure in Aquifer’s swap path.
Independent researchers describe caller-controlled token-program or account state that Aquifer trusted instead of strictly verifying the expected canonical Solana token transfer.
A reconstructed early transaction paid roughly $8,600 worth of HYPE while no corresponding USDC payment arrived. The transaction still succeeded, and the pattern repeated.
Aquifer has not published source code or a final post-mortem, so the exact code-level defect remains Developing.
Loss estimate
Bitquery calculates approximately $2.47M net removed.
Other security monitoring rounds the incident to about $2.5M.
CEXVia uses $2.47M but labels it On-chain / Independent, not Official final loss.
Where the funds went
The attacker rapidly converted assets and moved value cross-chain.
Bitquery traced approximately 1,000.8 ETH to an attacker-linked Ethereum wallet that had not moved the funds at analysis time.
Whitehat deadline
Aquifer’s upgrade authority published an on-chain whitehat offer.
The attacker may retain up to 20% if at least 80% is returned to designated recovery addresses before September 3 at 14:00 UTC.
Aquifer says it would not pursue civil claims if the terms are satisfied, subject to applicable law. The offer does not bind regulators, law enforcement or sanctions authorities.
At report time the deadline has not passed and no qualifying return has been verified.
Why the exploit matters technically
A secure Solana swap must verify:
- the expected token program;
- correct source and destination ownership;
- actual token movement;
- amount transferred;
- post-transfer account state.
A program that simply trusts caller-supplied program/account state can execute “successfully” while receiving no real payment.
The Aquifer reconstruction strongly suggests one or more of those invariants failed.
User and LP impact
The loss was large relative to Aquifer’s available liquidity. Security reporting placed TVL near $2.8M around the event.
Bitquery also observed an approximately 99.9% fall in venue traffic after the incident.
Liquidity providers therefore face both direct vault-loss risk and a collapse in venue activity.
Evidence Status
Confirmed / On-chain
- 212 exploit-style settlements.
- Approx. $2.47M net vault outflow.
- Cross-chain movement.
- Approx. 1,000.8 ETH at attacker-linked Ethereum address at analysis time.
- On-chain whitehat offer.
Developing
- Exact source-code defect.
- Final recovery.
- Attacker acceptance.
- LP reimbursement.
Risk Assessment
High.
What to Watch Next
- September 3 14:00 UTC deadline.
- Any return transaction.
- Movement of 1,000.8 ETH.
- Aquifer post-mortem.
- Program patch.
- LP reimbursement.
- Aggregator routing changes.
- Law-enforcement action.
FAQ
How much was lost?
Independent on-chain reconstruction puts the loss near $2.47M.
Is that an official Aquifer figure?
No.
What caused the exploit?
Evidence points to a swap verification/trust-boundary failure, but the final code-level cause is not official.
Has the attacker returned funds?
No qualifying return was verified at report time.
What is the deadline?
September 3 at 14:00 UTC.