Aquifer 是今天最值得单独展开的新 exploit。
Bitquery 根据 Solana 和 Ethereum 的 transaction history 重建认为,8 月 31 日 Aquifer liquidity vault 在约 40 分钟内被 drain 约 $2.47M。
攻击过程出现 212 次 one-sided settlement:Aquifer 放出真实 token,但对应 input token 并没有真正进入 protocol。
Exploit 是怎么发生的?
目前 strongest technical evidence 指向:
Caller-controlled token program / account validation failure
也就是说,Aquifer 的 swap instruction 接受了攻击者提供的 program/account state,并把它当成真实付款证明。
一笔早期攻击 transaction 中,Aquifer 放出约 $8,600 的 HYPE,但并没有收到对应 USDC;transaction 仍然成功。
Aquifer 没有公开 source code,也没有发布 final technical post-mortem,因此不能把某一行代码写成 official root cause。
Loss:$2.47M 是 On-chain Reconstruction
Bitquery 计算 net vault outflow:
约 $2.47M
其他安全监控多写约 $2.5M。
CEXVia 采用 $2.47M,同时明确标记:
On-chain / Independent
而不是 Official Final Loss。
资金去了哪里?
攻击者快速把多种资产换成 SOL,并进一步跨到 Ethereum。
Bitquery 当时追踪到约:
1,000.8 ETH
仍在 attacker-linked Ethereum wallet 中。
Whitehat Offer:今天 14:00 UTC 到期
Aquifer upgrade authority 已在链上签署 whitehat offer:
- 9 月 3 日 14:00 UTC 前返还至少 80%;
- Attacker 最多保留 20% bounty;
- 满足条件后 Aquifer 不追究 civil claim;
- 但不约束 regulator、law enforcement 或 sanctions authority。
本次日报生成时没有 verified qualifying return。
为什么这个漏洞值得重视?
这个事件属于典型的 smart-contract trust-boundary failure。
Solana program 在处理 CPI/token transfer 时不能只检查 instruction 有没有返回 success,还必须验证:
- 正确 token program;
- 正确 source/destination ownership;
- input token 实际移动;
- amount 与预期一致;
- balance state 真正变化。
如果 protocol 信任 caller-controlled state,就可能出现“程序显示成功,但实际上根本没收到钱”。
对 LP 的影响
事件发生前 Aquifer TVL 约 $2.8M 左右,因此 $2.47M drain 比例非常高。
Bitquery 还观察到 exploit 后 venue traffic 大幅下降。
LP 面临 direct vault loss + venue activity collapse 两层风险。
Evidence Status
Confirmed / On-chain
212 settlements、~$2.47M outflow、cross-chain movement、~1,000.8 ETH、on-chain whitehat message。
Developing
Exact source-code defect、final recovery、attacker acceptance、LP reimbursement。
Risk Assessment
High。
What to Watch Next
Deadline、return tx、ETH movement、Aquifer post-mortem、patch、LP compensation、aggregator routing、law enforcement。
FAQ
Aquifer 损失多少?
约 $2.47M on-chain reconstruction。
这是官方数字吗?
不是。
漏洞本质是什么?
目前 evidence 指向 swap validation / trust-boundary failure。
攻击者已经返还资金了吗?
本次报告生成时没有 verified return。
Whitehat Deadline 是什么时候?
9 月 3 日 14:00 UTC。