Solana AMM Aquifer Loses $2.47 Million in Exploit, Offers 20% Bounty

  • Aquifer lost $2.47 million from 18 vaults in a 40-minute exploit on Aug. 31.
  • Attacker used fake balance data in custom program; funds converted to 24,082 SOL then 1,000 ETH on Ethereum.
  • Protocol offers 20% bounty for returning 80% by Sept. 3 at 14:00 UTC.

Solana-based automated market maker Aquifer lost approximately $2.47 million from 18 token vaults in a 40-minute exploit on Aug. 31. The attacker used a custom program disguised as a token program with fake balance data to withdraw real assets, including $1.28 million in USDC and $459,000 in USDT. After draining the funds, the attacker converted approximately 24,082 SOL into about 1,000 ETH on Ethereum. Aquifer published an on-chain whitehat offer through its Solana upgrade authority, allowing the attacker to keep 20% if at least 80% is returned to recovery addresses by Sept. 3 at 14:00 UTC. The exploit caused protocol traffic to drop 99.9% and left total value locked at around $2.8 million. SlowMist classified the incident as a wallet access compromise, noting that smart contracts were not exploited and no post-mortem has been published.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.