Solana AMM Aquifer Loses ~$2.5M in Exploit, Offers 20% White Hat Bounty
TREE NEWS reports: Solana-based automated market maker (AMM) Aquifer has suffered a security breach, resulting in losses of approximately $2.5 million. According to blockchain security firm Telem, the attacker’s funds have been traced across both Solana and Ethereum networks. In response, Aquifer has initiated on-chain negotiations, offering the attacker a 20% white hat bounty in exchange for the return of the stolen assets.
Incident Details
The exploit targeted Aquifer’s liquidity pools, draining funds in a coordinated manner that involved cross-chain transactions. While the exact vulnerability has not been fully disclosed, early analysis suggests a flaw in the protocol’s swap logic or price oracle integration. Aquifer’s team has paused the affected pools and is working with security partners to mitigate further risks.
Industry Implications
This incident underscores the persistent threat landscape facing DeFi protocols, particularly those on high-throughput chains like Solana. Despite the network’s growing popularity for its low fees and fast transactions, security remains a critical challenge. The decision to offer a 20% bounty aligns with a growing trend in DeFi where protocols attempt to negotiate with attackers rather than pursue legal action, aiming to recover funds and avoid prolonged uncertainty.
Cross-chain exploits are also becoming more common as interoperability solutions mature. Attackers are increasingly using bridges and multi-chain strategies to obfuscate fund movements, making recovery efforts more complex. This case highlights the need for robust cross-chain monitoring and incident response protocols.
Forward-Looking Perspective
Looking ahead, Aquifer’s response will be closely watched. If the bounty is accepted, it could set a precedent for similar negotiations in the Solana ecosystem. However, if the attacker refuses, the protocol may face a prolonged recovery process and potential loss of user trust. For the broader DeFi sector, this event serves as a reminder that security audits and bug bounty programs are not optional but essential components of protocol development. As the industry matures, we can expect more sophisticated security measures, including real-time threat detection and formal verification, to become standard practice.




