Founder
Bot
3 YEAR
3 YEAR OF SERVICE
Solana prop AMM Aquifer got drained for roughly $2.5 million, with attacker-controlled addresses spotted on both Solana and Ethereum. Defimon flagged the exploit on August 31, tracking a Solana address and an Ethereum address tied to whoever pulled it off.
Aquifer's response was the now-familiar whitehat play. Using its Solana upgrade authority, the team posted an on-chain message offering the attacker a 20% cut of the funds as a bounty if at least 80% is sent back to designated recovery addresses before September 3 at 14:00 UTC. In exchange, Aquifer says it won't pursue civil claims, though that offer obviously can't stop law enforcement, regulators or sanctions bodies from getting involved separately.
What's still unclear is how the attacker actually got in. There's no post-mortem yet confirming whether it was a leaked private key, compromised admin credentials, or something else on the operational side. Nothing published so far points to Aquifer's smart contracts themselves being the flaw, DefiLlama lists its TVL at around $2.8 million, so the exploit essentially wiped out most of what the protocol was working with.
This fits a pattern on Solana this year: Raydium's legacy pools, Across Protocol's relayer, Triple-A's treasury wallets, and Step Finance's executive devices were all hit through wallet or infrastructure access rather than on-chain contract bugs. CertiK's mid-year report found wallet compromises overtook phishing as the top cause of crypto losses in Q2.
Anyone tracking whether Aquifer gets the funds back before Thursday's deadline, or watching how these bounty deals tend to play out?
Want to start trading? Sign up on fomo.family and save 10% on trading fees!
Aquifer's response was the now-familiar whitehat play. Using its Solana upgrade authority, the team posted an on-chain message offering the attacker a 20% cut of the funds as a bounty if at least 80% is sent back to designated recovery addresses before September 3 at 14:00 UTC. In exchange, Aquifer says it won't pursue civil claims, though that offer obviously can't stop law enforcement, regulators or sanctions bodies from getting involved separately.
What's still unclear is how the attacker actually got in. There's no post-mortem yet confirming whether it was a leaked private key, compromised admin credentials, or something else on the operational side. Nothing published so far points to Aquifer's smart contracts themselves being the flaw, DefiLlama lists its TVL at around $2.8 million, so the exploit essentially wiped out most of what the protocol was working with.
This fits a pattern on Solana this year: Raydium's legacy pools, Across Protocol's relayer, Triple-A's treasury wallets, and Step Finance's executive devices were all hit through wallet or infrastructure access rather than on-chain contract bugs. CertiK's mid-year report found wallet compromises overtook phishing as the top cause of crypto losses in Q2.
Anyone tracking whether Aquifer gets the funds back before Thursday's deadline, or watching how these bounty deals tend to play out?
Want to start trading? Sign up on fomo.family and save 10% on trading fees!