← Aquifer AMM1 decision on this page
Audit log
Every state-changing event for Aquifer AMM: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-09-16 23:26:25ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 447,647,160
- sig
5F6wiEqhBgg8…k8H5Mhk7explorer ↗- hash
DgqnSXuoC9Mm…b4G5ndWCsha256 → base58
verifying row…full verify ↗canonical bytes (11003 B) ▸
{"actor":"system:backfill","investigation_id":"08cd862e-8f35-46e7-b1ce-3a7c78538fc9","kind":"publish","page_slug":"aquifer-amm","published_at":"2026-09-16T23:26:25.683Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Aquifer AMM","sections":[{"content":"Aquifer operates as a proprietary automated market maker (prop AMM) on Solana with a focus on stablecoin swaps. It is described as the second known prop AMM for stablecoin swaps on Solana, following a prior protocol called Obric. Prior to the August 2026 security incident, Aquifer reportedly handled approximately 30% of stablecoin swap volume routed through the Jupiter aggregator, according to on-chain observer Sharples on X. DefiLlama data cited in reporting placed Aquifer's total value locked at approximately $2.8 million before the exploit. The protocol's team and founders have not been publicly identified in available sources.","heading":"Protocol Overview","severity":"low","sources":[{"credibility":3,"name":"Sharples on X — Aquifer stablecoin swap volume observation","type":"social_media","url":"https://x.com/0xSharples/status/1973029282000892055"},{"credibility":2,"name":"Solana AMM Aquifer hit by $2.5 million exploit, offers 20% bounty — crypto.news","type":"news_article","url":"https://crypto.news/solana-amm-aquifer-hit-by-2-5-million-exploit-offers-20-bounty/"}]},{"content":"On August 31, 2026, blockchain security monitoring service Defimon reported that attacker-controlled wallets drained approximately $2.5 million from Aquifer across both Solana and Ethereum. The known attacker addresses are: Solana — 7fTe9pvrwXJRBHq9MaSyVPR4PgEuhqLiA93Dxf4gRk7J; Ethereum — 0x2Dfe9e969796e2797278b02761dd9Ad6aE922746. Aquifer characterized the incident as a wallet compromise rather than a smart contract exploit. The exact attack vector — whether involving private key theft, administrative credential leakage, or another form of operational infrastructure exposure — has not been publicly disclosed as of the time of this investigation. Available reporting has not established that Aquifer's smart contracts were directly exploited. The cross-chain involvement on both Solana and Ethereum is consistent with attacker fund movement and asset diversification following initial access, though the initial compromise point remains unclear.","heading":"August 31, 2026 Security Incident","severity":"critical","sources":[{"credibility":2,"name":"Solana AMM Aquifer hit by $2.5 million exploit, offers 20% bounty — crypto.news","type":"news_article","url":"https://crypto.news/solana-amm-aquifer-hit-by-2-5-million-exploit-offers-20-bounty/"},{"credibility":2,"name":"Aquifer Exploit Drains $2.5M as August Hacks Hit 50 — shattered.io","type":"news_article","url":"https://shattered.io/aquifer-solana-exploit-white-hat-bounty-2026/"},{"credibility":2,"name":"Aquifer Loses $2.5M in Solana Wallet Compromise — Phemex News","type":"news_article","url":"https://phemex.com/news/article/solana-amm-aquifer-suffers-25-million-exploit-after-wallet-compromise-95161"}]},{"content":"Following the incident, Aquifer's Solana upgrade authority published a cryptographically signed on-chain white-hat message offering the attacker the right to retain up to 20% of the stolen assets as a bounty, contingent on returning at least 80% of funds by September 3, 2026 at 14:00 UTC to designated recovery addresses on Solana and Ethereum. Aquifer committed not to pursue civil claims against the attacker if the terms were met, with explicit carve-outs preserving law enforcement and regulatory referral rights. As of September 4, 2026 — the earliest post-deadline reporting available — no public source had confirmed that any funds were returned to the designated recovery addresses. The September 3 deadline passed without a reported resolution. No subsequent public update from the Aquifer team confirming recovery has been identified in available sources.","heading":"White-Hat Bounty Offer and Outcome","severity":"high","sources":[{"credibility":2,"name":"Solana AMM Aquifer hit by $2.5 million exploit, offers 20% bounty — crypto.news","type":"news_article","url":"https://crypto.news/solana-amm-aquifer-hit-by-2-5-million-exploit-offers-20-bounty/"},{"credibility":2,"name":"Aquifer Exploit Drains $2.5M as August Hacks Hit 50 — shattered.io","type":"news_article","url":"https://shattered.io/aquifer-solana-exploit-white-hat-bounty-2026/"},{"credibility":2,"name":"Aquifer Exploit Drains $2.5M From Solana (SOL) Ecosystem AMM — COINOTAG","type":"news_article","url":"https://en.coinotag.com/aquifer-exploit-drains-2-5m-solana-sol-ecosystem-amm"}]},{"content":"As of mid-September 2026, Aquifer has not published a technical post-mortem explaining how the wallet compromise occurred. The attack vector remains undisclosed. There is no public accounting of what security controls were in place, whether multi-signature or hardware security modules were used to protect administrative keys, or how attacker-controlled wallets obtained authorization to move protocol-held assets. The absence of a post-mortem is notable given that the incident drained nearly the entirety of the protocol's reported TVL of approximately $2.8 million. Aquifer's team and founders have not been publicly identified in available reporting, which limits the accountability and ongoing transparency assessment of the protocol.","heading":"Transparency and Post-Mortem Disclosure","severity":"high","sources":[{"credibility":2,"name":"Solana AMM Aquifer hit by $2.5 million exploit, offers 20% bounty — crypto.news","type":"news_article","url":"https://crypto.news/solana-amm-aquifer-hit-by-2-5-million-exploit-offers-20-bounty/"},{"credibility":2,"name":"Aquifer Exploit Drains $2.5M as August Hacks Hit 50 — shattered.io","type":"news_article","url":"https://shattered.io/aquifer-solana-exploit-white-hat-bounty-2026/"}]},{"content":"The Aquifer incident occurred during what reporting described as a record month for DeFi hacking activity. According to shattered.io, August 2026 recorded 50 major crypto hack incidents — a 67% increase from July 2026's 30 incidents. Total losses across August 2026 were reported at approximately $136.3 million, down roughly 49.5% from July's approximately $270 million, reflecting a higher frequency but lower average severity per incident. Aquifer's $2.5 million loss represented approximately 1.8% of August's total reported losses and was close to the month's reported average incident size of approximately $2.7 million. The largest single incident in August 2026 was a $74 million breach at TectonicFi. Other notable incidents during the same period included a governance takeover at Term Labs, a price oracle flaw at Moonwell, and a forged cross-chain message at Allbridge.","heading":"Broader Context: August 2026 DeFi Hack Environment","severity":"medium","sources":[{"credibility":2,"name":"Aquifer Exploit Drains $2.5M as August Hacks Hit 50 — shattered.io","type":"news_article","url":"https://shattered.io/aquifer-solana-exploit-white-hat-bounty-2026/"},{"credibility":2,"name":"Crypto Hacks Hit Record 50 in August 2026: Losses Fall — shattered.io","type":"news_article","url":"https://shattered.io/crypto-hacks-record-50-august-2026/"}]}],"sources_used":[{"credibility":2,"name":"Solana AMM Aquifer hit by $2.5 million exploit, offers 20% bounty — crypto.news","type":"news_article","url":"https://crypto.news/solana-amm-aquifer-hit-by-2-5-million-exploit-offers-20-bounty/"},{"credibility":2,"name":"Aquifer Exploit Drains $2.5M as August Hacks Hit 50 — shattered.io","type":"news_article","url":"https://shattered.io/aquifer-solana-exploit-white-hat-bounty-2026/"},{"credibility":2,"name":"Aquifer Exploit Drains $2.5M From Solana (SOL) Ecosystem AMM — COINOTAG","type":"news_article","url":"https://en.coinotag.com/aquifer-exploit-drains-2-5m-solana-sol-ecosystem-amm"},{"credibility":2,"name":"Aquifer Loses $2.5M in Solana Wallet Compromise — Phemex News","type":"news_article","url":"https://phemex.com/news/article/solana-amm-aquifer-suffers-25-million-exploit-after-wallet-compromise-95161"},{"credibility":2,"name":"Crypto Hacks Hit Record 50 in August 2026: Losses Fall — shattered.io","type":"news_article","url":"https://shattered.io/crypto-hacks-record-50-august-2026/"},{"credibility":3,"name":"Sharples on X — Aquifer stablecoin swap volume observation","type":"social_media","url":"https://x.com/0xSharples/status/1973029282000892055"},{"credibility":2,"name":"Aquifer TVL — DefiLlama","type":"research","url":"https://defillama.com/protocol/aquifer"}],"summary":"Aquifer is a proprietary automated market maker (AMM) on Solana focused on stablecoin swaps, which had accumulated approximately $2.8 million in total value locked prior to a security incident on August 31, 2026. Attacker-controlled wallets on both Solana and Ethereum drained approximately $2.5 million from the protocol in what Aquifer attributed to a wallet compromise rather than a smart contract vulnerability. A 20% white-hat bounty offer with a September 3, 2026 deadline passed without any publicly confirmed return of funds, and no technical post-mortem has been released.","timeline":[{"date":"2026-08-31","event":"Attacker-controlled wallets on Solana and Ethereum drained approximately $2.5 million from the Aquifer AMM protocol. Blockchain security monitoring service Defimon reported the attack. Aquifer attributed the incident to a wallet compromise rather than a smart contract exploit.","source":"crypto.news","source_url":"https://crypto.news/solana-amm-aquifer-hit-by-2-5-million-exploit-offers-20-bounty/"},{"date":"2026-08-31","event":"Aquifer's Solana upgrade authority published a cryptographically signed on-chain white-hat message offering the attacker a 20% bounty in exchange for returning at least 80% of stolen funds by September 3, 2026 at 14:00 UTC. Separate Solana and Ethereum recovery addresses were supplied. Aquifer committed not to pursue civil claims if terms were met.","source":"crypto.news","source_url":"https://crypto.news/solana-amm-aquifer-hit-by-2-5-million-exploit-offers-20-bounty/"},{"date":"2026-09-01","event":"Multiple crypto news outlets including crypto.news, Phemex News, and COINOTAG published coverage of the Aquifer exploit and bounty offer.","source":"Phemex News","source_url":"https://phemex.com/news/article/solana-amm-aquifer-suffers-25-million-exploit-after-wallet-compromise-95161"},{"date":"2026-09-03","event":"White-hat bounty deadline of 14:00 UTC passed. No public confirmation of fund return was reported.","source":"shattered.io","source_url":"https://shattered.io/aquifer-solana-exploit-white-hat-bounty-2026/"},{"date":"2026-09-04","event":"Post-deadline reporting confirmed no public source had verified that stolen funds were returned to the designated recovery addresses. No technical post-mortem published by Aquifer.","source":"shattered.io","source_url":"https://shattered.io/aquifer-solana-exploit-white-hat-bounty-2026/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 50e25360-4f45-40ab-b6a3-58aa427000af
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.