Aquifer hack — August 2026
Incident facts
| Date of incident | |
|---|---|
| Target type | Decentralised exchange |
| Loss | $2,470,000Published estimates range $2,470,000 to $2,500,000Price at time of incident |
| Method | Private key compromiseProtocol-controlled wallets on Solana and Ethereum were drained; no smart contract exploit has been established and the method of compromise is unknown |
| Chains | Solana, Ethereum |
| Outcome | Unresolved |
What happened
Aquifer, an automated market maker on Solana, lost roughly $2.5m on 31 August 2026 from wallets it controlled on both Solana and Ethereum. PeckShield's tally of the month puts the figure at $2.47m and it rounds out that firm's top ten August incidents; the range here carries both published numbers.
What happened to the wallets is not established. The available reporting does not show that Aquifer's smart contract code was exploited, and it does not explain how access to the wallets was obtained. The vector recorded reflects that the loss came through control of protocol wallets rather than through the contracts, which is the part the evidence supports; the method of compromise is unknown and the entry should not be read as asserting a leaked key specifically.
Aquifer responded by publishing a recovery offer on-chain, authorised through its Solana upgrade authority, with separate recovery addresses for each network. It offered the attacker a 20% white-hat bounty on condition that at least 80% of the assets were returned by 14:00 UTC on 3 September 2026, and said it would not pursue civil claims arising from the exploit if the attacker complied, subject to applicable law.
The outcome is recorded as unresolved because the deadline had not passed when this entry was written. If the assets are returned it becomes a bounty settlement, and the entry will be updated to say so.
Sources
- crypto.newsSecondary · retrieved 2026-09-01
- crypto.news (PeckShield tally)Secondary · retrieved 2026-09-01
Changes to this entry
- Recorded while the white-hat bounty deadline of 3 September 2026 was still open. If at least 80% of the assets are returned by then the outcome becomes a bounty settlement and the recovered amount will be added.
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Aquifer hack — August 2026", iTokenly, accessed 2026-09-02, https://itokenly.com/hacks/aquifer-ammhttps://itokenly.com/hacks/aquifer-ammPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.