Incident case file
Sign in to watchAquifer Solana Prop AMM Fake-Balance Exploit — $2.47M Drained in 40 Minutes
0 views
Estimated loss
Affected users
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatOn August 31, 2026, between 03:41 and 04:21 UTC, an attacker deployed a custom Solana program disguised as the SPL Token Program, creating 45 forged token accounts with balances up to 18,446,744,073,709,551,615 (the field's maximum value) to falsely claim ownership of assets. Across 212 successful transactions, Aquifer's automated market maker paid out real tokens from 18 of its vaults while receiving nothing in return, draining $2,469,729 — effectively the entirety of the protocol's holdings. The stolen assets (dominated by USDC at $1,281,035 and USDT at $459,371) were converted to SOL and bridged to Ethereum via Rango within the same hour, landing at 0x2Dfe9e96... which held exactly 1,000.7956 ETH as of September 1 with zero outgoing transactions. At 16:43 UTC the same day, Aquifer's legitimate Solana upgrade authority published an on-chain whitehat offer: return at least 80% by September 3 at 14:00 UTC in exchange for a 20% bounty. The offer was ignored — the designated Solana return address had shown no activity as of the deadline. Between September 4 and 6, the attacker converted the funds to USDC and bridged them onward to obscure the trail. As of the most recent check, no funds have been returned and no reimbursement plan has been announced. The protocol's on-chain traffic fell approximately 99.9% following the exploit.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)