web3: The Solana AMM protocol Aquifer suffered an attack resulting in a loss of $2.5 million
Cryptonews
09-01 15:24
Ai Focus
The Solana protocol and Aquifer suffered an attack resulting in losses of approximately $2.5 million. The project team has proposed a white-hat solution that allows for the return of 80% of the assets while retaining 20% of the bounty.
Helpful
No.Help

Solana Ecological Automated Market-Making Protocol Aquifer A security incident occurred recently, resulting in a loss of approximately $2.5 million. The project team has made a white-hat proposal to the relevant addresses on the chain: if the attacker returns at least 80% of the assets or equivalent funds by 14:00 on September 3rd ( UTC ), they may retain up to 20% of that amount as a bounty.

At present, the entry point of the attack has not been identified. Public information has not yet proven that there are vulnerabilities in the smart contract code of Aquifer. At this stage, the greater suspicion is focused on the possibility that access rights to the wallet or credentials on the operations and maintenance side have been obtained.

The project party has proposed the conditions for refund.

On August 31, the on-chain security monitoring service Defimon disclosed this incident and identified the Solana involved in the attack as well as the Ethereum address. Subsequently, Aquifer published a compensation plan through on-chain messages and provided the recovery addresses for each chain.

According to the conditions provided by the project party, the relevant assets can be returned on the Solana network or the Ethereum network. If the return ratio requirements are met, Aquifer indicates that no civil claims will be filed regarding this incident; however, this statement does not bind law enforcement agencies, regulatory authorities, or other government organizations.

  • Return deadline: September 3, 14:00 ( UTC )
  • Minimum return rate: 80%
  • Reward percentage can be retained: up to 20%

Involves Solana and Ethereum addresses

Aquifer is an automated market-making protocol deployed on Solana, primarily providing liquidity for token exchanges. Current data from DefiLlama indicates that the total locked-up value of this protocol is approximately 2.8 million US dollars, which is close to the loss amount disclosed in this incident.

The suspicious addresses identified by Defimon are located in Solana and on the Ethereum network. This means that the flow of assets that were transferred is somewhat traceable, but it is not possible to directly determine how the attacker obtained control over the relevant wallets based solely on cross-chain address activities.

As of now, Aquifer has not released any technical review, nor has they clarified whether there was a private key leak, a loss of administrator privileges, or any other issues related to the exposure of internal infrastructure.

This year, several incidents have pointed to the loss of control over wallets.

Since the beginning of this year, there have been multiple instances of loss events related to Solana that were not directly triggered by smart contract logic. Previously, the old version of the Raydium liquidity pool suffered a loss of approximately $1.3 million due to historical AMM infrastructure issues; in July, Across Protocol also experienced losses due to a software defect in off-chain events.

More broadly speaking, the security of wallets and private keys is becoming one of the main sources of risk in the crypto industry. Security company CertiK previously stated that in the first half of 2026, digital asset losses amounted to approximately $1.32 billion. Although the total amount was lower than in the same period of the previous year, wallet breaches in the second quarter have replaced phishing attacks as the main source of loss.

Another Solana project, Step Finance, also lost control of its treasury and fee wallets due to a team device being compromised, and ultimately announced the cessation of operations. Whether this incident falls into a similar category still awaits more complete technical details to be disclosed by the project party in the future.

Tip
$0
Like
0
Save
0
Views 267
WalletJYS reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
web3: Bitcoin Falls to $76,300 as Senate Crypto Bill Vote Approaches
Bitcoin falls to around $76,300; market focuses on the procedural vote on the Senate's crypto bill and the Federal Reserve's interest rate decision.
Coinpaper
·2026-09-15 23:25:28
16
Ethereum: Standard Chartered is bullish on the Arbitrum ecosystem, stating that ARB may benefit from tokenized assets
Standard Chartered expects that by ARB, it may rise to $10 by 2030. Robinhood Chain and tokenized assets are seen as the main drivers, and large-scale whale transactions on the chain are also heating up.
CoinPedia
·2026-09-15 22:28:18
19
web3: Binance will take offline 5 margin trading pairs
Binance will take offline 5 full-position margin trading pairs on September 18th, and will also stop the spot trading of USDP on September 24th.
U.Today
·2026-09-15 22:28:17
18
Foreign media: AI's slowdown commitment cannot withstand the pressure of business and Sino-US competition
Foreign media analysis suggests that if AI company lacks mandatory safety standards and independent supervision, its commitment to slowing down research and development may fail under the pressure of commercial competition and Sino-US tensions.
Coinpaper
·2026-09-15 22:28:15
15
AI Security Startup AIUC Completes $40 Million Series A Financing
AI Security startup completes $40 million Series A financing, focusing on enterprises AI Acting as third-party audit and certification.
TechCrunch
·2026-09-15 21:31:22
24
View More