Aquifer Exploited for $2.5M, Attacker Offered 20% Bounty
Aquifer, a Solana-based automated market maker, lost approximately $2.5 million to an exploit on August 31, 2026. The team behind Aquifer responded by offering the attacker a 20% bounty in exchange for returning at least 80% of the stolen funds by September 3, 2026.
The offer was made through an on-chain message addressed directly to the attacker's wallets, which included specific wallet addresses and a reference Solana transaction. This approach allowed Aquifer to prove that the offer genuinely came from the team rather than an impersonator.
Aquifer has stopped short of confirming a smart contract vulnerability, instead pointing to compromised wallet access as the likely root cause. This distinction is significant, as it suggests that the failure mode was related to operational security and key management rather than a faulty code flaw.