Aquifer (2026) — Crypto Hack
OngoingSolana-based AMM Aquifer lost ~$2.5M after a protocol-linked wallet was compromised; funds moved across Solana and Ethereum. The protocol offered the attacker a 20% whitehat bounty.
Summary
Solana-based AMM Aquifer lost ~$2.5M after a protocol-linked wallet was compromised; funds moved across Solana and Ethereum. The protocol offered the attacker a 20% whitehat bounty.
How It Was Compromised — DeFi via Private Key Compromise (suspected)
On August 31, 2026, Solana-based automated market maker Aquifer (TVL ~$2.8M per DeFiLlama) lost ~$2.5M in an exploit involving attacker-controlled wallets on Solana and Ethereum. Defimon reported the attack, linking Solana address 7fTe9pvrwXJRBHq9MaSyVPR4PgEuhqLiA93Dxf4gRk7J and Ethereum address 0x2Dfe9e969796e2797278b02761dd9Ad6aE922746 to the attacker. The exact point of compromise remains unclear — no technical post-mortem has established whether private keys, admin credentials or other infrastructure was exposed, and no evidence shows Aquifer's smart contracts were exploited. Aquifer published an on-chain whitehat offer: the attacker may keep up to 20% if at least 80% of assets are returned to designated Solana and Ethereum recovery addresses by September 3, 14:00 UTC.
Fund Flow & Laundering Analysis
Funds were moved across Solana and Ethereum addresses controlled by the attacker; recovery is being negotiated via the on-chain whitehat offer.