EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Ajna vulnerability caused US$775,000 in damage, exposing hidden dangers beyond DeFi price oracle

2026-08-30 00:23:14
Bookmark

Ajna Protocol was attacked and lost approximately US$775,000 in ETH.

Ajna Protocol, a lending platform that does not require a price oracle, reportedly lost approximately US$775,000 in ETH. Instead of using third-party price feeds, the attacker used clearing accounting mechanisms within the platform. The attack affected multiple liquidity pools, including syrupUSDC, wstETH, rETH, cbETH, WBTC, WETH/USDC, and sDAI. However, this raises questions about an important aspect of Ajna's core philosophy-no oracle, no governance, self-priced markets. Attackers exploit this assumption to profit.

Ajna deliberately abandoned oracle

Most lending agreements rely on external services like Chainlink to determine the price of collateral. But Ajna deliberately did not do so. In fact, its white paper describes the protocol as: "The Ajna protocol is an unmanaged, point-to-point, permission-free lending, borrowing and trading system that operates without governance or external price feeds." Instead, lenders determine their loan interest rates by putting money into fixed amounts of "buckets", while contracts in the agreement determine when the loan is liquidated. In order to initiate the liquidation process, the person initiating the liquidation also needs to pay a liquidation bond. If the liquidation is not justified, financial penalties will be imposed.

Security company MixBytes explains the thinking behind eliminating oracles: "A large proportion of the attacks on the DeFi protocol stem from oracle price manipulation, configuration errors and access control issues." Ajna's solution is to eliminate the attack surface and trust the pool to operate. Defimon's warning suggested that the attackers were targeting this internal mechanism-theft by manipulating clearing accounting, rather than disrupting external price prophets.

Warning not responded to for an hour

Defimon claimed that it detected a "prepared attack" more than an hour before the first attack transaction occurred and notified Ajna through the project's Discord chat. However, when the attack began, the protocol was not yet protected. Subsequently, the hacker traversed multiple pools. Of the total damage of approximately $775,000, the syrupUSDC pool reportedly lost approximately $173,700.

For Ajna, this loss is quite huge. According to the DefiLlama report at the time, the total locked value (TVL) of Ajna V2 was approximately US$206,000, active loans were approximately US$418,000, and the 30-day TVL change was-54.2%. The amount of losses reported at the time exceeded Ajna's TVL. DefiLlama's real-time data has changed since then.

Is it to crack the code or convince the system that it is impossible?

The bigger question is: Did the attacker crack Ajna's code or trick the system into accepting fake data? Evidence points to the latter. The audit history released by Ajna includes issues discovered in the past related to the "take" calculation during the liquidation process, as well as accounting errors in barrel status. These issues have been marked as fixed, but they demonstrate flaws in liquidation and accounting logic.

This pattern is common. Cryptopolitan has previously reported on the Moonwell incident, where the attacker used approximately $7 million to raise the price of illiquid MAMO tokens eightfold, then borrowed nearly $10 million in real assets, eventually taking away approximately $6 million. According to Nethermind, how such attack methods work: "They force contracts to calculate distorted prices and exploit them before the transaction ends." Ajna got rid of the oracle, but its contracts still need to trust their own calculations.

The architecture of V2 is the real story

Data before and after the attack

Phase: Pre-attack -Data point: Ajna V2TVL/Affected pool Liquidity-Trigger: First abnormal transaction-Utilization: Contract function + asset manipulated-Extraction: Asset transferred out of protocol-Conversion: DEX conversion/acquisition of stablecoin-Escape: Cross-chain Bridge/ CEX /Other Agreements-Residual Risk: Residual Bad Debt or Impaired Liquidity-Recovery: Frozen Assets/White Hat Rescue/Agreement Response

Fund Flow: Before → Exploit → After

Key Indicators

Reported Loss: Pending (Pending Ajna Investigation/On-Chain Confirmation)

TVL: $449,783, 30-day change-17.1%, measure of capital still held in V2 contracts

Active loans: $30,198, no change reported, indicating the risk of outstanding loans

Tracking pool number: 5, a useful denominator for determining whether an event is isolated or systematic

Ethereum TVL: $425,825, accounting for 94.7% of V2 TVL

Arbitrum TVL: $8,552, smaller cross-chain risks

Base TVL: $7,354, smaller cross-chain risks

Rari TVL: $3,555, smaller cross-chain risks

OP Mainnet TVL: $3,227, smaller cross-chain risk

(Source: DefiLlama)

Currently, the TVL of Ajna V2 is approximately US$450,000, while active loans are only US$30,200, and TVL has dropped by 17.1% in 30 days. A useful analytical statistic is that active loans only account for approximately 6.7% of the reported TVL. This makes the core investigative question particularly interesting: Did the suspected attack affect accounting for outstanding debt, liquidity deposited, or both? So the question becomes: "What assumptions does V2 introduce so that attackers can convert them into money?"

In a record-setting attack year, a small pool

The $775,000 loss is not huge compared to the largest cryptocurrency hack of 2026, but it fits a broader pattern. TRM Labs statistics show that there were 207 hacking attacks in the first half of this year, the highest number recorded in a six-month period, with typical incident losses of approximately $219,000. More than 100 of these involve smaller smart contract vulnerabilities. Infrastructure and operational level intrusions accounted for only about 15% of incidents, but caused about 76% of total damage. So Ajna shows the flip side of the security issue: Losses don't necessarily come from earth-shattering exchange breaches or private key leaks, they can stem from assumptions buried deep in DeFi's increasingly complex lending logic.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP