← Radar

Incident case file

Sign in to watch

Aquifer Solana Prop AMM Fake-Balance Exploit — $2.47M Drained in 40 Minutes

Incident date Aug 30, 2026Last updated Sep 24, 2026

0 views

ActiveSolanaEthereumFake token account / spoofed balance exploitCluster: AQUIFER-SOL-2026-08

Estimated loss

$2.5M

Affected users

1
Group joining is coming soon.

Investigation

65%

Facts and investigation

Ledger

Attacker

Solana wallet: 7fTe9pvrwXJRBHq9MaSyVPR4PgEuhqLiA93Dxf4gRk7J; Ethereum destination: 0x2Dfe9e969796e2797278b02761dd9Ad6aE922746

Funds moved to

Sold for SOL on Solana within the hour, bridged to Ethereum via Rango and a second cross-chain program; funds have sat unmoved at the Ethereum destination since September 1. Between Sept 4-6, converted to USDC and bridged onward to obscure the trail.

Linked

Aquifer program: AQU1FRd7papthgdrwPTTq5JacJh8YtwEXaBfKU3bTz45. Attacker (Solana): 7fTe9pvrwXJRBHq9MaSyVPR4PgEuhqLiA93Dxf4gRk7J. Attacker (Ethereum destination): 0x2Dfe9e969796e2797278b02761dd9Ad6aE922746. Protocol upgrade authority (legitimate multisig, NOT the attacker): 8pJhHxPQRiUGdtVSCNPyP9AH994zeyYEBGb5yZRzheSA.

Chronology

1 beat
  1. On August 31, 2026, between 03:41 and 04:21 UTC, an attacker deployed a custom Solana program disguised as the SPL Token Program, creating 45 forged token accounts with balances up to 18,446,744,073,709,551,615 (the field's maximum value) to falsely claim ownership of assets. Across 212 successful transactions, Aquifer's automated market maker paid out real tokens from 18 of its vaults while receiving nothing in return, draining $2,469,729 — effectively the entirety of the protocol's holdings. The stolen assets (dominated by USDC at $1,281,035 and USDT at $459,371) were converted to SOL and bridged to Ethereum via Rango within the same hour, landing at 0x2Dfe9e96... which held exactly 1,000.7956 ETH as of September 1 with zero outgoing transactions. At 16:43 UTC the same day, Aquifer's legitimate Solana upgrade authority published an on-chain whitehat offer: return at least 80% by September 3 at 14:00 UTC in exchange for a 20% bounty. The offer was ignored — the designated Solana return address had shown no activity as of the deadline. Between September 4 and 6, the attacker converted the funds to USDC and bridged them onward to obscure the trail. As of the most recent check, no funds have been returned and no reimbursement plan has been announced. The protocol's on-chain traffic fell approximately 99.9% following the exploit.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)