Solana-Based Aquifer Loses $2.5M in Major DeFi Exploit

Solana-Based Aquifer Loses $2.5M in Major DeFi Exploit

Key Insights:

  • Aquifer is up against a huge challenge to recover the estimated $2.5 million it has lost, through Solana and Ethereum together.
  • The leak could raise issues about the security of wallets, but it is unclear how it penetrated the system.
  • The 20% bounty raises recovery prospects while giving the attacker until September 3 to return funds.

Aquifer lost about $2.5 million on August 31 after an attack involving wallets on Solana and Ethereum. The incident has raised questions about wallet security because investigators have not linked the loss to a confirmed smart contract flaw.

Blockchain security monitoring service Defimon reported the attack after identifying separate Solana and Ethereum addresses tied to the suspected exploiter. The incident affected assets associated with Aquifer, an automated market maker operating on Solana.

But the exact way to the control is unknown. Aquifer has not released a technical post-mortem to explain how the transfers could have been made possible, whether via private keys, administrative credentials or otherwise.

The uncertainty makes the incident different from attacks where researchers can quickly identify vulnerable contract code. So far, available information does not establish that Aquifer’s smart contracts served as the entry point.

Source: X

Whitehat offer sets a recovery deadline

After the attack, Aquifer published an on-chain white hat offer aimed at recovering most of the missing assets. The proposal gives the attacker until September 3 at 10 PM to return at least 80%.

The recovery deadline corresponds to 7 PM UTC on September 3. If the conditions are met the attacker keeps up to 20% of the recovered amount as a bounty.

Aquifer created unique recovery addresses for assets on both the Solana and Ethereum networks. Aquifer set up individual recovery addresses for various assets on Solana and Ethereum. This means that the suspect attacking the cardholder can be given a clear path to return money associated with the incident.

The project also undertook not to prosecute the attacker if they do what they have agreed. That commitment remains subject to applicable law and does not restrict government agencies. Aquifer’s message received authorization through the protocol’s Solana upgrade authority. Its publication on-chain provides a public record of the recovery proposal and its conditions.

The attack follows a wider security shift

Aquifer operates as a proprietary automated market maker, while DefiLlama lists its total value locked at about $2.8 million. The reported loss therefore represents a substantial amount relative to the protocol’s recorded liquidity.

Recent incidents also show that attackers increasingly target infrastructure surrounding blockchain applications. Smart contracts do not always represent the weakest point in a crypto operation. Raydium suffered about $1.3 million in losses from five legacy liquidity pools in June. Investigators said the attacker exploited validation weaknesses in retired AMM infrastructure.

Across faced another incident in July involving fabricated Solana deposit events. The attacker generated false deposits and triggered payouts across multiple destination chains. Across later attributed the incident to an issue in its off-chain event-reading software. The protocol said its smart contracts and the Solana network itself were not responsible.

The pattern suggests that security risks can emerge from supporting systems rather than blockchain code alone.

Wallet compromises raise the industry stakes

Aquifer also follows several incidents involving compromised wallets and operational infrastructure. Triple-A confirmed in July that unauthorized access to treasury wallets led to digital asset theft.

Researchers initially tracked suspicious transactions across several networks. Triple-A later said customer funds remained protected because client assets stayed separate from compromised treasury infrastructure.

Meanwhile, CertiK reported $1.32 billion in digital asset losses during the first half of 2026. The security firm said wallet compromises became the leading attack method during the second quarter.

Step Finance faced another major wallet security incident earlier this year. Attackers accessed devices used by executives and moved about 261,854 SOL from treasury and fee wallets.

Important points for the Aquifer investigation.

  • Entry points are as important as the amount stolen.
  • Cross-chain activity potentially muddies the trail for assets recovery and tracing.
  • A whitehat bounty can facilitate recovery without spawning on-the-spot litigation.

Forensic evidence to help in the recovery process.

Aquifer’s top priority is the return of the stolen assets before the September 3 deadline. The project has yet to determine how the attacker got in and if there are other wallets that are vulnerable.

Further forensic analysis could determine the cause of the transactions, such as compromised credentials, private keys, operational devices, or some other vulnerability. That is a finding that will have impact on aquifer and other DeFi projects, when they evaluate the potential for such risks.

The whitehat proposal is the most obvious recovery plan at this time. The results will be based on the willingness of the suspected attacker to accept the terms and to return the necessary amounts of money.

The incident also highlights a larger message for Solana’s DeFi sector. A robust contract security can’t shield protocols from weaknesses in other parts of their operation infrastructure.

Scroll to Top