LATEST NEWS
SELECTED FOR YOU

$775K Ajna exploit exposes risks beyond DeFi price oracles

ByAshish KumarAshish Kumar 4 mins read
Ajna Protocol loses $775K as attacker exploits liquidation accounting
  • Ajna Protocol reportedly lost about $775,000 in ETH after an attacker exploited its internal liquidation accounting.
  • The attack targeted multiple pools, including syrupUSDC, wstETH, rETH, cbETH, WBTC and WETH/USDC.
  • Ajna deliberately operates without external price oracles, relying instead on its own market and liquidation mechanisms.

Ajna Protocol, a lending platform that operates without price oracles, reportedly lost around $775,000 in ETH. The exploiters used the internal liquidation accounting of the platform instead of using third-party price feeds in their attack.

The assault impacted a number of liquidity pools, such as syrupUSDC, wstETH, rETH, cbETH, WBTC, WETH/USDC, and sDAI. However, it raises questions about an important aspect of Ajna’s philosophy – the absence of oracles and governance and the self-pricing market.

The attacker profited from this very assumption.

The oracle Ajna deliberately left out

The majority of lending protocols make use of an external service such as Chainlink to establish the prices of collateral. Ajna, however, intentionally does not do this. In fact, its white paper describes the protocol as follows:

“The Ajna protocol is a non-custodial, peer-to-peer, permissionless lending, borrowing and trading system that requires no governance or external price feeds to function.”

Rather, lenders determine the rates at which they will lend by putting money into “buckets” of a fixed amount, and it is the contracts in the protocol that determine when the loan is to be liquidated. For the initiation of a liquidation process, a liquidation bond should also be paid by the person initiating the liquidation process, imposing a financial penalty in case there is a liquidation without any justification.

MixBytes, a security company, explained the thinking behind the elimination of the oracle:

“a significant portion of attacks on DeFi protocols stem from oracle prices manipulations, errors in configuration and access control issues.”

Ajna’s remedy was to eliminate the attack surface and trust the pool’s operations. Defimon’s warning hints that the assailant zeroed in on this internal mechanism — stealing by way of liquidated accounting manipulation instead of compromising the external price oracle.

An hour of warning that went unanswered

Defimon claims that it was able to detect a “prepared attack more than one hour before the first exploit” transaction took place and let Ajna know via the project’s Discord chat. The protocol had not yet been secured when the assault started.

Then, the hacker traversed numerous pools. As per the report, the syrupUSDC pool has incurred losses of approximately $173,700 from a total loss of about $775,000.

The loss is quite huge for Ajna. As per the DefiLlama report at the time, the total value locked (TVL) for Ajna V2 stood at about $206,000. The active loans were pegged at around $418,000, while it registered a 30-day TVL variation of -54.2%. At the time, the reported loss due to the attack exceeded the TVL of Ajna. The live data of DefiLlama has changed since then.

Break the code, or make it believe something impossible

The larger question is whether the attacker hacked Ajna’s code or tricked the system into accepting false data as valid.

The evidence suggests that the latter is the case. The audit history published by Ajna includes past findings related to “take” computations during the liquidation process and instances when accounting was done incorrectly for the bucket state, among others. Those issues have already been deemed to be fixed; nevertheless, they provide proof of issues related to liquidation and accounting logic.

The pattern is a common one. Cryptopolitan has reported earlier about Moonwell, where the assailant used approximately $7 million in the process of lifting the illiquid MAMO token by eight times and then borrowing nearly $10 million of real assets and finally leaving with close to $6 million.

According to Nethermind, these methods of attack work like this:

“they force the contract to calculate a distorted price and exploit it before the transaction ends.”

Ajna got rid of the oracle, but it still requires its contracts to trust its calculations.

V2’s architecture becomes the real story

StageData point
Pre-attackAjna V2 TVL / affected pool liquidity
TriggerFirst anomalous transaction
ExploitContract function + assets manipulated
ExtractionAssets transferred from the protocol
ConversionDEX swaps / stablecoins acquired
EscapeBridges / CEXs / other protocols
Residual exposureRemaining bad debt or impaired liquidity
RecoveryFrozen assets / white-hat recovery / protocol response
Money Trail: Before → Exploit → After
MetricCurrent figure30-day changeWhy it matters
Reported exploit lossTBDAwaiting Ajna’s investigation/confirmed on-chain accounting
TVL$449,783-17.1%Measures capital still held in V2 contracts
Active loans$30,198Not reportedIndicates outstanding borrower exposure
Tracked pools5Useful denominator for determining whether the incident is isolated or systemic
Ethereum TVL$425,82594.7% of V2 TVL
Arbitrum TVL$8,552Smaller cross-chain exposure
Base TVL$7,354Smaller cross-chain exposure
Rari TVL$3,555Smaller cross-chain exposure
OP Mainnet TVL$3,227Smaller cross-chain exposure
Ajna V2 exposure snapshot l DeFiLlama

Ajna V2 currently has about $450,000 in TVL against $30,200 in active loans, while TVL has fallen 17.1% over 30 days.

One useful analytical statistic is that active loans equal only about 6.7% of reported TVL. That makes the key investigative question particularly interesting: is the suspected exploit affecting outstanding debt accounting, deposited liquidity, or both? So the question becomes, “What assumption did V2 introduce that an attacker could turn into money?”

A small pool in a record year for exploits

The $775,000 loss is modest beside the largest crypto hacks of 2026, but it fits a broader pattern.

TRM Labs counted 207 hacks in the first half of the year, the highest number it has recorded in a six-month period, with the typical incident costing about $219,000. More than 100 involved smaller smart-contract exploits.

Infrastructure and operational compromises represented only about 15% of incidents but accounted for roughly 76% of total losses.

Ajna therefore illustrates a different part of the security problem: losses do not need to come from spectacular exchange breaches or compromised private keys. They can emerge from the assumptions buried inside DeFi’s increasingly complex lending logic.

 

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.

FAQs

How much did Ajna Protocol lose and where?

Ajna lost roughly $775,000 on Ethereum, according to Defimon Alerts, with about $173,700 of that drained from its syrupUSDC pool.

Did the attacker exploit an oracle?

No. Ajna runs without external price feeds by design, per its whitepaper, and Defimon characterized the attack as "liquidation accounting manipulation," meaning the protocol's own internal accounting was bent rather than an outside oracle.

Was Ajna warned before the attack?

Yes. Defimon says it detected the prepared attack more than an hour before the first exploit transaction and notified Ajna in its Discord, but the team failed to react in time.

What is liquidation accounting manipulation?

Liquidation accounting manipulation is an attack that exploits how a lending protocol calculates collateral, debt, liquidation prices or losses. An attacker may manipulate those calculations to borrow more than they should, avoid a loss, or extract value from lenders.

What is Ajna’s current TVL?

Ajna’s current total value locked (TVL) should be checked against a live on-chain dashboard because the figure can change rapidly during an exploit. For this report, distinguish Ajna-wide TVL from the liquidity actually exposed to the affected V2 pools.

Is my money safe if I lent on Ajna?

Not necessarily. If you supplied assets to an affected Ajna V2 pool, your exposure depends on the specific pool, asset and transactions involved in the incident. Until Ajna completes its investigation, lenders should check the protocol’s official incident updates before assuming their funds are unaffected.

Share this article

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Ashish Kumar

Ashish Kumar

Ashish Kumar is a crypto and financial journalist with eight years of newsroom experience. He covers what’s happening with crypto markets, regulation, DeFi, and exchange ecosystems. He has worked with Coingape, Todayq, and Newsroompost. Ashish holds a PGDP in English Journalism from the IIMC. He has also interviewed industry figures including Arthur Hayes, Yat Siu, Austin Federa, and more.

MORE … NEWS