Solana-based automated market maker (AMM) Aquifer has reported a significant security breach resulting in the loss of approximately 1.5 million USD. According to reports from Telem and on-chain monitors on September 1, 2026, the incident was not caused by a smart contract vulnerability but rather by a leak of wallet credentials. The attacker managed to gain access to multiple addresses associated with the protocol, suggesting a compromise of private keys or administrative privileges.
Cross-Chain Coordination and Method of Attack
The security breach appears to be a sophisticated operation involving cross-chain activity. Analysts have identified attacker-controlled addresses on both the Solana and Ethereum blockchains, indicating a planned coordination for the transfer and laundering of stolen assets. Unlike many recent DeFi exploits that target logic flaws in code, this attack focused on administrative access points.
Such incidents often highlight the risks associated with private key management and the potential for "social engineering" or phishing to bypass even audited smart contract security.
Specific details regarding the stolen assets include:
- Loss of approximately 1.5 million USD in total value.
- Multiple administrative wallet addresses compromised.
- Movement of funds observed across Solana-Ethereum bridges.
White Hat Proposal and Recovery Efforts
In response to the incident, the Aquifer team has issued an on-chain message to the attacker, extending a white hat proposal in an attempt to recover the majority of the protocol's assets. The project has set a deadline of September 3, 2026, at 22:00 UTC for the return of the funds.
The terms of the proposal are as follows:
Return at least 80% of the relevant assets by the specified deadline, and the attacker may keep the remaining 20% as a bounty. If these conditions are met, the project promises not to pursue civil litigation or cooperate with law enforcement for further prosecution.
This "bounty" approach has become a standard, albeit controversial, recovery tactic in the decentralized finance ecosystem to incentivize the return of user funds.
The Aquifer incident adds to a growing list of security challenges for the Solana DeFi landscape in 2026. Following the high-profile Drift Protocol and Kelp DAO exploits earlier this year, security researchers continue to emphasize the importance of robust multisig structures and hardware-based key management. As of the current UTC date, the community is awaiting the attacker's response to the white hat deadline.
Frequently Asked Questions
Quick answers to the most common questions about this topic.