Aquifer, a Solana-based automated market maker (AMM), has suffered an exploit resulting in losses of approximately $2.5 million, with the protocol offering the attacker a 20% bounty in exchange for returning the majority of the stolen funds.
The incident was first flagged on Aug. 31 by blockchain security monitoring platform Defimon, which identified suspected attacker-controlled wallets on both the Solana and Ethereum networks. Following the breach, Aquifer issued an on-chain whitehat proposal, giving the attacker until Sept. 3 at 14:00 UTC to return at least 80% of the assets or their equivalent value.
Under the offer, the attacker would be allowed to keep up to 20% of the recovered funds as a bounty. Aquifer also stated it would not pursue civil claims related to the incident if the terms are met, although the agreement would not prevent action by regulators, law enforcement agencies, or other government authorities.
Aquifer operates a proprietary AMM on the Solana blockchain and currently has a total value locked of roughly $2.8 million. Security researchers linked the exploit to wallets on both Solana and Ethereum, prompting the protocol to provide separate recovery addresses for each network.
At this stage, the exact cause of the breach remains unclear. Aquifer has not released a technical post-mortem, and there is no confirmed evidence that its smart contracts were exploited. Investigators are instead focusing on the possibility that private keys, administrator credentials, or other operational infrastructure may have been compromised.
The incident adds to a growing list of crypto security breaches in 2026 that have involved compromised wallets rather than vulnerabilities in blockchain networks or smart contract code.
Recent examples include the theft of around $1.3 million from legacy Raydium liquidity pools, a multi-chain attack on Across Protocol that resulted in losses of less than $4 million, and an $11.8 million treasury wallet breach at stablecoin payments company Triple-A.
According to blockchain security firm CertiK, wallet compromises became the leading cause of crypto-related losses during the second quarter of 2026, overtaking phishing attacks. The trend highlights the increasing importance of operational security as attackers continue targeting private keys, credentials, and treasury infrastructure.
Aquifer has yet to disclose how the attacker gained access to the affected funds. For now, the protocol’s recovery efforts remain focused on its whitehat proposal and the Sept. 3 deadline for the return of the assets.







