Skip to content
Ajna Protocol Loses $775000 in ETH as Attacker Exploits Its Oracle

Ajna Protocol Loses $775000 in ETH as Attacker Exploits Its Oracle

Finance.Biggo • August 29, 2026

A lending platform built around the idea that removing external price feeds makes DeFi safer has lost roughly $775,000 in ETH after an attacker turned the protocol's own liquidation logic against it. Ajna Protocol, which operates without oracles or governance controls, was drained across multiple liquidity pools in an incident that raises uncomfortable questions the security assumptions underpinning its design.

Monitoring firm Defimon said it detected preparations for the attack more than an hour before the first exploit transaction landed and alerted the Ajna team through its Discord channel. The protocol had not been secured by the time the assault began.

The attacker moved through several pools, including syrupUSDC, wstETH, rETH, cbETH, WBTC, WETH/USDC, and sDAI. The syrupUSDC pool alone accounted for approximately $173,700 of the total losses.

Most decentralized lending protocols rely on external services such as Chainlink to determine collateral prices. Ajna took a different path. Its white paper describes the project as "a non-custodial, peer-to-peer, permissionless lending, borrowing and trading system that requires no governance or external price feeds to function."

In Ajna's framework, lenders set their own rates by depositing funds into fixed "buckets," while protocol contracts determine when liquidations occur. Anyone initiating a liquidation must post a bond, creating a financial penalty for unjustified actions.

Security firm MixBytes has explained the reasoning behind removing oracles: "A significant portion of attacks on DeFi protocols stem from oracle prices manipulations, errors in configuration and access control issues." By eliminating that attack surface, Ajna aimed to make its system more robust. The exploit shows how that decision created a different vulnerability.

Data from DefiLlama at the time of the incident showed Ajna V2's total value locked at around $206,000, with active loans of $418,000 and a 30-day TVL decline of 54.2%. The reported loss from the attack exceeded the protocol's entire TVL at that moment.

Note: Figures reflect live DefiLlama data after the attack; the reported exploit loss of $775,000 exceeded Ajna V2's total TVL at the time of the incident.

Active loans now stand at just 6.7% of reported TVL, a ratio that underscores how much capital has left the protocol.

Evidence suggests the attacker did not compromise Ajna's core code. Instead, the exploit manipulated internal accounting so the system accepted erroneous liquidation calculations. Ajna's published audit history includes past findings related to liquidation process computations and bucket state accounting errors. Those issues were marked as resolved, but they point to the same area of logic the attacker ultimately exploited.

The technique mirrors other recent incidents. Moonwell suffered a similar manipulation when an illiquid token was artificially lifted in value, allowing the attacker to extract millions in assets. Blockchain researchers at Nethermind have described how these exploits work: "They force the contract to calculate a distorted price and exploit it before the transaction ends."

Ajna removed external oracles in pursuit of security, but its contracts still depend on self-verifying calculations. That reliance created a new opening, one that did not require compromising a third-party price feed.

The $775,000 loss is modest compared with the largest crypto thefts of 2026, yet it fits a broader trend. TRM Labs counted 207 protocol hacks in the first half of the year, a record for any six-month period, with a median loss of $219,000 per incident. More than 100 involved smart contract vulnerabilities. Infrastructure and operational compromises accounted for only 15% of incidents but represented roughly 76% of total loss value.

Ajna's case illustrates a different part of the security problem: losses do not need to come from spectacular exchange breaches or compromised private keys. They can emerge from the assumptions buried inside increasingly complex DeFi lending logic. The incident highlights the difficulty of designing decentralized systems that are genuinely secure, even when they deliberately avoid the components that have failed elsewhere.

Once added, BigGo Finance appears first in Google Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.

Extracted Entities

Companies (2)