Ajna, a lending protocol without external oracle and governance, was attacked and lost approximately US$775,000 ETH
The decentralized lending platform Ajna Protocol suffered a major security breach, resulting in the theft of approximately US$775,000 ETH. The platform does not rely on external price prophets or governance mechanisms. The attack used internal clearing accounting mechanisms to bypass loopholes in traditional third-party price-feeding systems.
The attack exploits the lack of oracle
Unlike most DeFi lending protocols that rely on external services such as Chainlink to determine collateral prices, Ajna relies entirely on its own internal mechanisms. The platform's white paper describes it as an unmanaged, point-to-point, permission-free system designed to run without external price feedings or governance measures.
"The Ajna protocol is an unmanaged, point-to-point, permission-free lending and trading system that operates without governance or external price feed."
In Ajna's framework, users specify the loan interest rate by depositing funds in a fixed "barrel", while agreement contracts automatically control the timing of clearing. Initiating liquidation requires the payment of a margin and penalties for unreasonable liquidation, which theoretically limits abuse.
Security company MixBytes commented on Ajna's reasons for removing the oracle, pointing out that most DeFi attacks stem from price manipulation, configuration errors, and access control issues related to external oracle.
"A significant proportion of attacks in the DeFi protocol stem from oracle price manipulation, configuration errors, and access control issues."
Ajna attempts to minimize the attack surface by omitting the oracle and relying on internal protocol calculations. However, this attack took advantage of this, allowing attackers to manipulate clearing accounting without targeting any third-party oracles.
Early warnings were ignored and multiple pools were affected
Defimon, the company that monitors DeFi systems, reported that it detected an imminent attack more than an hour before the first attack transaction occurred and alerted Ajna via the Discord channel. Despite warnings, the agreement remained fragile when the attack began.
The attacker targeted multiple mobility pools, including syrupUSDC, wstETH, rETH, cbETH, WBTC, WETH/USDC, and sDAI. The syrupUSDC pool alone caused approximately $173,700 in damage.
DeFi data aggregator DefiLlama showed that the total locked value (TVL) of Ajna V2 at the time of the incident was approximately US$206,000, active loans were US$418,000, and the 30-day TVL dropped by 54.2%. It is worth noting that the damage from this attack exceeded the entire TVL reported by Ajna at the time.
Related indicators:
Ajna V2 TVL (post-attack): US$449,783, 30-day change-17.1%
Active loans: US$30,198, changes not reported
Reported attack losses: US$775,000
Ethereum TVL: US$425,825
Ajna V2 currently manages approximately US$450,000 of TVL and US$30,200 of active loans, with TVL falling 17.1% in the past month. The current ratio of active loans to TVL is 6.7%, raising questions about the underlying vulnerability targeted by the attack.
Security issues and broader trends
Evidence suggests that the attacker did not breach Ajna's core code, but manipulated internal accounting, causing the system to accept erroneous clearing calculations. Previously published audit results had pointed out early problems in the calculations of the liquidation process, but at the time they were believed to have been resolved.
Such attacks are showing a growing trend in decentralized finance. In a noteworthy similar case, Moonwell suffered similar manipulation, when a illiquid token was inflated in value, extracting millions of dollars in assets from the agreement.
Analysts such as blockchain research institute Nethermind believe that such attacks usually temporarily distort on-chain price calculations and extract value before the protocol responds.
"They force contracts to calculate distorted prices and use them before the trade ends."
Ajna removed external oracles in pursuit of security, but its contracts still had to rely on self-verifying calculations-leaving a new breakthrough for attackers.
Broad background to the 2026 DeFi attack
Although Ajna's $775,000 loss was smaller than the largest cryptocurrency theft this year, it is in line with recent trends. TRM Labs reported that there were 207 cryptocurrency protocol hacking attacks in the first half of 2026, setting a six-month high, with a median loss of $219,000 per incident. More than 100 of these were related to smart contract vulnerabilities.
Operational and infrastructure vulnerabilities accounted for 15% of all attacks, but accounted for 76% of total losses.
The Ajna attack suggests that significant DeFi risks may arise not only from headline-style exchange vulnerabilities, but also from the complex and undertested logic of DeFi lending contracts. The incident highlighted the challenges of designing truly secure decentralized systems.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH
WBTC