A deadline set on-chain by Solana-based AMM Aquifer expires today: the protocol's white-hat offer — return at least 80% of the roughly $2.5 million drained on August 31, keep up to 20% as a bounty — closes at 14:00 UTC on September 3, 2026. As of publication, no on-chain confirmation of returned funds has been publicly reported.
What Happened
Aquifer, a proprietary automated market maker operating on Solana, was exploited on August 31 for approximately $2.5 million, according to SlowMist's incident ledger and alerts from on-chain monitoring firm Defimon. Public reporting has pointed to compromised protocol-linked wallets or admin credentials rather than a confirmed smart-contract vulnerability — a distinction that matters for both the post-mortem and any recovery effort, since credential compromise leaves the on-chain programs intact but the keys that control them in hostile hands.
Blockchain data cited in monitoring reports shows the attacker operating addresses on both Solana and Ethereum, moving stolen assets across the two chains after the initial drain.
The Offer
The same day as the exploit, Aquifer's Solana upgrade authority posted a white-hat proposal on-chain: the attacker would return no less than 80% of the stolen assets to designated recovery addresses by September 3, 2026, 14:00 UTC, and could retain up to 20% as a bounty. In exchange, the project committed to no civil claims. The offer was reported by crypto.news on September 1 under the headline "Solana AMM Aquifer hit by $2.5 million exploit, offers 20% bounty."
The structure follows a pattern that has become common in mid-size DeFi incidents: a public, time-boxed amnesty with a percentage bounty, posted before any law-enforcement referral is announced. It converts a negotiation into a deadline — and, for the project, creates a clear factual record that recovery was attempted on stated terms.
What Happens at Expiry
If the deadline passes without recovery, the project's stated options narrow: tracing and freezing efforts across the two chains where the attacker operated, exchange-level freezes on deposited funds, and potential legal action — none of which are guaranteed to recover assets that have already been swapped or fragmented.
Whether the funds move back before 14:00 UTC is, for now, the only open question that matters. TrustGrade will update this story if the recovery window produces an on-chain result.
TrustGrade tracks the security posture of DeFi protocols and infrastructure. Security scans with verified, registry-backed scores arrive with TrustGrade Code Scoring in December 2026.