Solana Ecological Automated Market-Making Protocol Aquifer A security incident occurred recently, resulting in a loss of approximately $2.5 million. The project team has made a white-hat proposal to the relevant addresses on the chain: if the attacker returns at least 80% of the assets or equivalent funds by 14:00 on September 3rd ( UTC ), they may retain up to 20% of that amount as a bounty.
At present, the entry point of the attack has not been identified. Public information has not yet proven that there are vulnerabilities in the smart contract code of Aquifer. At this stage, the greater suspicion is focused on the possibility that access rights to the wallet or credentials on the operations and maintenance side have been obtained.
The project party has proposed the conditions for refund.
On August 31, the on-chain security monitoring service Defimon disclosed this incident and identified the Solana involved in the attack as well as the Ethereum address. Subsequently, Aquifer published a compensation plan through on-chain messages and provided the recovery addresses for each chain.
According to the conditions provided by the project party, the relevant assets can be returned on the Solana network or the Ethereum network. If the return ratio requirements are met, Aquifer indicates that no civil claims will be filed regarding this incident; however, this statement does not bind law enforcement agencies, regulatory authorities, or other government organizations.
- Return deadline: September 3, 14:00 ( UTC )
- Minimum return rate: 80%
- Reward percentage can be retained: up to 20%
Involves Solana and Ethereum addresses
Aquifer is an automated market-making protocol deployed on Solana, primarily providing liquidity for token exchanges. Current data from DefiLlama indicates that the total locked-up value of this protocol is approximately 2.8 million US dollars, which is close to the loss amount disclosed in this incident.
The suspicious addresses identified by Defimon are located in Solana and on the Ethereum network. This means that the flow of assets that were transferred is somewhat traceable, but it is not possible to directly determine how the attacker obtained control over the relevant wallets based solely on cross-chain address activities.
As of now, Aquifer has not released any technical review, nor has they clarified whether there was a private key leak, a loss of administrator privileges, or any other issues related to the exposure of internal infrastructure.
This year, several incidents have pointed to the loss of control over wallets.
Since the beginning of this year, there have been multiple instances of loss events related to Solana that were not directly triggered by smart contract logic. Previously, the old version of the Raydium liquidity pool suffered a loss of approximately $1.3 million due to historical AMM infrastructure issues; in July, Across Protocol also experienced losses due to a software defect in off-chain events.
More broadly speaking, the security of wallets and private keys is becoming one of the main sources of risk in the crypto industry. Security company CertiK previously stated that in the first half of 2026, digital asset losses amounted to approximately $1.32 billion. Although the total amount was lower than in the same period of the previous year, wallet breaches in the second quarter have replaced phishing attacks as the main source of loss.
Another Solana project, Step Finance, also lost control of its treasury and fee wallets due to a team device being compromised, and ultimately announced the cessation of operations. Whether this incident falls into a similar category still awaits more complete technical details to be disclosed by the project party in the future.










