Solana-based automated market maker (AMM) protocol Aquifer recently lost approximately $2.5 million in an exploit. The attack, detected on August 31, drained nearly all liquidity from the platform, which operates as a prop AMM facilitating token swaps. Before the attacker’s wallet drained its assets, DefiLlama data showed Aquifer’s total value locked (TVL) was around $2.8 million.
Rather than immediately pursuing legal action against the perpetrator, Aquifer responded to the incident by offering a peaceful negotiation. The developer team introduced a “whitehat bounty” scheme, giving the hacker the opportunity to keep 20% of the stolen assets. The condition is clear: at least 80% of the remaining funds must be returned in full before September 3 at 14:00 UTC.
If the deadline and return agreement are met, the protocol promised not to pursue civil litigation in court. However, the Aquifer team emphasized that their offer of civil immunity does not prevent law enforcement agencies or official regulators from conducting criminal investigations.
Unanswered Vulnerabilities
As of the bounty offer’s release, there has been no official technical post-mortem report from Aquifer developers explaining how the protocol’s defenses were breached. The public and the DeFi community still do not know whether the exploit stemmed from a vulnerability in smart contract code, compromised user private keys, or hacked system admin credentials.
Blockchain security monitoring firm Defimon, which first reported the attack late last month, revealed the perpetrator’s wallet trails. They identified two primary wallet addresses used to transfer the funds: 7fTe9pvrwXJRBHq9MaSyVPR4PgEuhqLiA93Dxf4gRk7J on the Solana network and 0x2Dfe9e969796e2797278b02761dd9Ad6aE922746 on Ethereum.
Not the First Target on Solana
The Aquifer breach adds to the growing list of exploits targeting Solana ecosystem projects throughout 2026. Two months ago, in June, decentralized exchange (DEX) Raydium also lost $1.3 million from an older AMM pool.
A similar incident followed in July when Across Protocol lost nearly $4 million. In that theft, the attacker utilized a manipulative tactic by exploiting a fake Solana deposit feature to deceive the system.
Even as crypto attacks continue to claim victims, macro data shows a downward trend in aggregate losses. A CertiK report stated that total digital asset losses in the first half of 2026 stood at $1.32 billion, down 46.8% compared to the same period in 2025. The report also highlighted that wallet compromise methods were the most prevalent attack vector throughout the second quarter of 2026.
The final decision rests with the hacker. The 20% offer put forward by Aquifer will test whether the attacker chooses to return a portion of the stolen funds to avoid civil lawsuits or ignore the September 3 deadline. Reported by crypto.news.
Read also: North Korea’s Lazarus Launders $30 Million in Bitcoin on Hyperliquid - Right as Platform Lobbies US
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




