On August 31, 2026, the automated market maker (AMM) protocol Aquifer, deployed on the Solana chain, was suddenly attacked, with funds originally intended for on-chain trading and liquidity services being rapidly transferred away, resulting in a loss of approximately 2.5 million dollars. While the amount is not astonishing enough to rewrite the industry's landscape, it is significant enough to push this incident into the center of discussions about DeFi security: on one side are the direct losses faced by users and liquidity providers, while on the other, a still-expanding Solana ecosystem is once again forced to confront infrastructure risks. However, what truly sets the Aquifer incident apart from numerous attack cases is the unconventional response that the project team immediately threw out — they did not first angrily denounce the “hacker” on social media, but rather first sent an on-chain message offering a white hat bounty to the attacker, stating that if at least 80% of the stolen assets or equivalent assets were returned within a specified period, the attacker would be allowed to keep up to 20% as a “bounty.” From the occurrence of the attack to the deadline of September 3 at 22:00, this approximately three-day negotiation window left room for both sides to maneuver, also throwing a sharp question to onlookers: in the face of increasingly complex cross-chain and protocol attack surfaces, is this “reconciliation route” of exchanging a bounty for most of the funds a desperate measure or a new norm that is taking shape?
The Truth of the Attack Remains Unclear: From Wallet Compromise to Contract Doubts
Almost simultaneously with the white hat offer being made, the technical narrative surrounding the compromise of Aquifer quickly split into two distinctly different stories. On one side is a more intuitive version that is easier for non-technical readers to accept: some materials describe the incident as related to Aquifer's wallet address or credentials being compromised, with the attacker logically transferring the funds out of the pool after gaining control; on the other side is a more “core level” suspicion, with some on-chain analysis suggesting that the real issue may lie in the contract or program logic, involving the exploitation of some boundary condition, permission validation, or even specific call paths. Currently, neither of these claims has produced enough evidence to decisively outweigh the other.
It is worth noting that several Chinese crypto media outlets, in their reports, have almost exclusively cited Telem as the main initial source of information, along with the claim that “the suspected attacker is active on both Solana and Ethereum chains, and the incident may involve cross-chain fund transfers or multi-chain coordinated operations,” which has primarily been reiterated along this line. As of September 1, Aquifer has yet to publish a detailed and externally validated technical recap report, nor has there been an independent team disclosing a systematic evidence collection process on-chain. Under such an information structure, any “true cause conclusion” drawn from a single source, partial address activities, or even cross-chain transfer trajectories seems more like a subjective inference rather than a fact that has been repeatedly validated.
After a Loss of 2.5 Million, a White Hat Olive Branch is Offered
Shortly after the funds were misappropriated, Aquifer did not initially make a lengthy complaint on social media, but directly wrote a “public letter” on-chain to the suspected attacker: if, within a specified time, at least 80% of the stolen assets or equivalent assets were returned to a recovery address designated by the project team, then the remaining up to 20% could be legally retained as a bounty. This proportion was designed very straightforwardly, not only signaling to users and the community that the team would prioritize “recovering” the vast majority of funds, but also throwing a clear numerical anchor to the opponent — no longer getting tangled in whether the person is a “hacker” or a “white hat,” but to talk about getting the funds back first.
What is more dramatic is the timing. The white hat offer made by Aquifer set the deadline for 22:00 on September 3, 2026 (approximately 14:00 UTC on September 3), leaving only about a 3-day negotiation window from the occurrence of the event on August 31 until the deadline. The tight schedule made it difficult for the attackers to “stall” on whether to return the funds, also creating a psychological countdown pressure. Compared to immediately shouting for cross-border accountability or filing a police report, this path of first using economic incentives to recover assets has already been repeatedly used in previous DeFi security incidents: on the one hand, it often has a better chance of recovering losses in reality than lengthy and uncertain legal processes, and on the other hand, by setting a bounty cap and deadline, it narrows the attacker's options to the clear boundary of “returning now can allow keeping a portion, but crossing the line means completely standing on the opposite side.”
Cross-Chain Roaming Attackers and Tracking Challenges
Almost at the same time as the white hat offer was revealed, on-chain analysis provided another clue: the suspected attacker was not only active on Solana, as a group of related addresses also had activity records on Ethereum. These materials purportedly outline a possible cross-chain route, believing that this fund outflow may not have been simply “local liquidation” on a single chain, but was accompanied by cross-chain transfers or multi-chain coordinated operations. However, it needs to be emphasized that this assertion primarily comes from a single analysis source, and although several media outlets mentioned the “cross-chain dimension” in subsequent reports, they did not provide independent evidence collection or a complete disclosure of the fund path.
Once the stage is expanded from a single chain to include both Solana and Ethereum, the difficulty of tracking and recovering increases exponentially: the tools, permissions, and partners on different chains are all different, and synchronously freezing or intercepting often requires more complex collaboration. Meanwhile, as long as the attackers transport or split chips back and forth between chains, they can increase the time difference and obfuscation for their escape routes. In previous DeFi incidents, such cross-chain attacks and transfers have repeatedly proven to be persistent issues in security protection and tracking. In the case of Aquifer, the currently visible cross-chain details remain at the stage of speculation from a single source, and all parties involved must wait for more on-chain cross-validation to piece together this crucial yet still undecided fund map before taking further actions.
DeFi Hackers and Negotiations: The Industry is Getting Used to It
In the window period where the flow of funds still awaits further cross-validation, Aquifer first put the conditions into an on-chain message: within hours of the attack, they made a white hat offer requiring at least 80% of the stolen assets or equivalent assets to be returned before 22:00 on September 3, 2026, allowing the attackers to keep up to 20% as a “bounty.” Formally, this is an economic contract with a clear division ratio and time window, and Aquifer is using it to hedge against the risk of suffering a loss of about 2.5 million dollars expanding further, also positioning itself swiftly on the path of “prioritizing negotiations.”
This stance is not isolated. In past DeFi attacks, victim protocols have provided white hat bounties to attackers in exchange for the return of most funds, which has been repeatedly practiced as a tool of “negotiating first, pursuing accountability or not pursuing accountability later.” The reasons behind this are not complex: cross-border legal accountability takes a long time, costs are high, and execution is uncertain; even launching legal processes may not recover assets at the moment of liquidity that the protocol and users need the most. For the project team, the white hat offer is a pragmatic choice under real constraints, yet it also places the industry on a new moral gray line — on one hand, the rapid return of funds helps restore user confidence and reduce panic and bank runs; on the other hand, frequent payment of bounties may be seen by some attackers as a “predictable exit mechanism,” weakening legal deterrence and raising future psychological tolerance for attacks. White hat offers are gradually transitioning from emergency measures to accustomed options, and whether they repair or condone industry norms depends on where project teams stand firm on certain boundaries.
The Ongoing Game: What’s Next for Aquifer
At this current juncture, the facts that can be confirmed are not complex: on August 31, Aquifer was attacked on Solana, suffering a loss of about 2.5 million dollars; the project team subsequently threw out a white hat offer through on-chain messages, requiring the return of at least 80% of the stolen assets by 22:00 on September 3, with the attacker permitted to keep up to 20% as a “bounty.” According to publicly available reports, this information primarily stems from a few channels such as Telem and lacks multi-source on-chain evidence support. As of September 1, there is still no widely recognized on-chain evidence indicating that the attacker has clearly accepted or rejected the offer. In contrast, the key variable that genuinely determines the direction of the event remains shrouded in uncertainty — whether the technical root cause is a compromised wallet or credential, or if there are flaws in the contract logic remains inconclusive; how the suspected attacker migrated assets cross-chain between Solana and Ethereum, and where the funds ultimately settled has not been systematically sorted out, and the identity and motivation of the attacker remain unaddressed. Going forward, the most critical points to watch are whether there will be any fund return or new on-chain actions before and after the white hat offer deadline, how Aquifer will unveil its technical review and user compensation arrangements and implement security enhancements, and whether this incident will spur stricter security practices and cross-chain risk protection within the Solana ecosystem. These unresolved points will collectively determine whether this game is ultimately written as a lesson, a compromise, or a new industry security boundary.
Join our community to discuss and grow stronger together!
Exclusive Hyperliquid benefits for AiCoin: https://app.hyperliquid.xyz/join/AICOIN88
Exclusive Aster benefits for AiCoin: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。



