Crypto Currency Tracker logo Crypto Currency Tracker logo
Cryptopolitan 2026-08-29 12:57:37

$775K Ajna exploit exposes risks beyond DeFi price oracles

Ajna Protocol, a lending platform that operates without price oracles, reportedly lost around $775,000 in ETH. The exploiters used the internal liquidation accounting of the platform instead of using third-party price feeds in their attack. The assault impacted a number of liquidity pools, such as syrupUSDC, wstETH, rETH, cbETH, WBTC, WETH/USDC, and sDAI. However, it raises questions about an important aspect of Ajna’s philosophy – the absence of oracles and governance and the self-pricing market. The attacker profited from this very assumption. The oracle Ajna deliberately left out The majority of lending protocols make use of an external service such as Chainlink to establish the prices of collateral. Ajna, however, intentionally does not do this. In fact, its white paper describes the protocol as follows: “The Ajna protocol is a non-custodial, peer-to-peer, permissionless lending, borrowing and trading system that requires no governance or external price feeds to function.” Rather, lenders determine the rates at which they will lend by putting money into “buckets” of a fixed amount, and it is the contracts in the protocol that determine when the loan is to be liquidated. For the initiation of a liquidation process, a liquidation bond should also be paid by the person initiating the liquidation process, imposing a financial penalty in case there is a liquidation without any justification. MixBytes , a security company, explained the thinking behind the elimination of the oracle: “a significant portion of attacks on DeFi protocols stem from oracle prices manipulations, errors in configuration and access control issues.” Ajna’s remedy was to eliminate the attack surface and trust the pool’s operations. Defimon’s warning hints that the assailant zeroed in on this internal mechanism — stealing by way of liquidated accounting manipulation instead of compromising the external price oracle. An hour of warning that went unanswered Defimon claims that it was able to detect a “prepared attack more than one hour before the first exploit” transaction took place and let Ajna know via the project’s Discord chat. The protocol had not yet been secured when the assault started. Then, the hacker traversed numerous pools. As per the report, the syrupUSDC pool has incurred losses of approximately $173,700 from a total loss of about $775,000. The loss is quite huge for Ajna. As per the DefiLlama report at the time, the total value locked (TVL) for Ajna V2 stood at about $206,000. The active loans were pegged at around $418,000, while it registered a 30-day TVL variation of -54.2%. At the time, the reported loss due to the attack exceeded the TVL of Ajna. The live data of DefiLlama has changed since then. Break the code, or make it believe something impossible The larger question is whether the attacker hacked Ajna’s code or tricked the system into accepting false data as valid. The evidence suggests that the latter is the case. The audit history published by Ajna includes past findings related to “take” computations during the liquidation process and instances when accounting was done incorrectly for the bucket state, among others. Those issues have already been deemed to be fixed; nevertheless, they provide proof of issues related to liquidation and accounting logic. The pattern is a common one. Cryptopolitan has reported earlier about Moonwell, where the assailant used approximately $7 million in the process of lifting the illiquid MAMO token by eight times and then borrowing nearly $10 million of real assets and finally leaving with close to $6 million. According to Nethermind , these methods of attack work like this: “they force the contract to calculate a distorted price and exploit it before the transaction ends.” Ajna got rid of the oracle, but it still requires its contracts to trust its calculations. V2’s architecture becomes the real story Stage Data point Pre-attack Ajna V2 TVL / affected pool liquidity Trigger First anomalous transaction Exploit Contract function + assets manipulated Extraction Assets transferred from the protocol Conversion DEX swaps / stablecoins acquired Escape Bridges / CEXs / other protocols Residual exposure Remaining bad debt or impaired liquidity Recovery Frozen assets / white-hat recovery / protocol response Money Trail: Before → Exploit → After Metric Current figure 30-day change Why it matters Reported exploit loss TBD — Awaiting Ajna’s investigation/confirmed on-chain accounting TVL $449,783 -17.1% Measures capital still held in V2 contracts Active loans $30,198 Not reported Indicates outstanding borrower exposure Tracked pools 5 — Useful denominator for determining whether the incident is isolated or systemic Ethereum TVL $425,825 — 94.7% of V2 TVL Arbitrum TVL $8,552 — Smaller cross-chain exposure Base TVL $7,354 — Smaller cross-chain exposure Rari TVL $3,555 — Smaller cross-chain exposure OP Mainnet TVL $3,227 — Smaller cross-chain exposure Ajna V2 exposure snapshot l DeFiLlama Ajna V2 currently has about $450,000 in TVL against $30,200 in active loans, while TVL has fallen 17.1% over 30 days. One useful analytical statistic is that active loans equal only about 6.7% of reported TVL. That makes the key investigative question particularly interesting: is the suspected exploit affecting outstanding debt accounting, deposited liquidity, or both? So the question becomes, “What assumption did V2 introduce that an attacker could turn into money?” A small pool in a record year for exploits The $775,000 loss is modest beside the largest crypto hacks of 2026, but it fits a broader pattern. TRM Labs counted 207 hacks in the first half of the year, the highest number it has recorded in a six-month period, with the typical incident costing about $219,000. More than 100 involved smaller smart-contract exploits. Infrastructure and operational compromises represented only about 15% of incidents but accounted for roughly 76% of total losses. Ajna therefore illustrates a different part of the security problem: losses do not need to come from spectacular exchange breaches or compromised private keys. They can emerge from the assumptions buried inside DeFi’s increasingly complex lending logic. Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free .

Loe lahtiütlusest : Kogu meie veebisaidi, hüperlingitud saitide, seotud rakenduste, foorumite, ajaveebide, sotsiaalmeediakontode ja muude platvormide ("Sait") siin esitatud sisu on mõeldud ainult teie üldiseks teabeks, mis on hangitud kolmandate isikute allikatest. Me ei anna meie sisu osas mingeid garantiisid, sealhulgas täpsust ja ajakohastust, kuid mitte ainult. Ükski meie poolt pakutava sisu osa ei kujuta endast finantsnõustamist, õigusnõustamist ega muud nõustamist, mis on mõeldud teie konkreetseks toetumiseks mis tahes eesmärgil. Mis tahes kasutamine või sõltuvus meie sisust on ainuüksi omal vastutusel ja omal äranägemisel. Enne nende kasutamist peate oma teadustööd läbi viima, analüüsima ja kontrollima oma sisu. Kauplemine on väga riskantne tegevus, mis võib põhjustada suuri kahjusid, palun konsulteerige enne oma otsuse langetamist oma finantsnõustajaga. Meie saidi sisu ei tohi olla pakkumine ega pakkumine