Solana AMM Aquifer exploited for approximately $2.5M via compromised wallet addresses.
Security & Exploits ·
Solana-based automated market maker Aquifer was exploited for approximately $2.5 million through compromised wallet addresses. The attacker operated across multiple blockchains, maintaining addresses on both Ethereum and Solana, suggesting the incident may have involved coordination or fund movement across chains.
The breach appears to have centered on compromised wallet credentials rather than a smart contract vulnerability. The attacker's ability to access multiple addresses linked to the protocol indicates potential compromise of private keys or administrative controls. The timing and execution pattern point to an opportunistic extraction of liquidity held within the AMM's pools.
The scope of recovery and the exact mechanism by which wallet access was compromised remain unclear. Whether the vulnerability stems from a single point of failure in key management, a phishing campaign targeting administrators, or another vector has not been established in available public disclosures.