Aquifer, an automated market maker on Solana, lost about $2.5 million in an attack after a wallet address linked to the protocol was compromised. The attacker used addresses on both Ethereum and Solana, pointing to possible cross-chain coordination or asset transfers. The incident appears to have stemmed from leaked wallet credentials rather than a smart contract flaw. Multiple protocol-linked addresses were reportedly accessed, suggesting a private key or administrative privilege leak. Aquifer has since sent an on-chain white-hat proposal offering the attacker up to 20% of the assets as a bounty if at least 80% is returned before 22:00 on September 3, and said it would not pursue a civil lawsuit if the terms are met.