Don't want to trade it yourself?
Our desk runs DEX portfolios on profit share.
Add to Google Preferred Sources
Ajna Protocol, a DeFi lending platform that operates without external price oracles or governance, lost approximately $775,000 in ETH after an attacker exploited its internal liquidation accounting. The incident affected multiple liquidity pools, with syrupUSDC accounting for roughly $173,700 in losses. Monitoring firm Defimon said it warned the project more than an hour before the attack via Discord, but the protocol remained vulnerable. Evidence indicates the attacker manipulated internal calculations rather than hacking core code, turning Ajna’s oracle-free design into an attack vector. The loss exceeded the protocol’s total value locked at the time, which stood near $206,000. The incident fits a broader 2026 pattern: TRM Labs recorded 207 crypto protocol hacks in the first half of the year, a record six-month figure.
Key Elements

A lending platform built around the idea that removing external price feeds makes DeFi safer has lost roughly $775,000 in ETH after an attacker turned the protocol’s own liquidation logic against it. Ajna Protocol, which operates without oracles or governance controls, was drained across multiple liquidity pools in an incident that raises uncomfortable questions about the security assumptions underpinning its design.
Monitoring firm Defimon said it detected preparations for the attack more than an hour before the first exploit transaction landed and alerted the Ajna team through its Discord channel. The protocol had not been secured by the time the assault began.
The attacker moved through several pools, including syrupUSDC, wstETH, rETH, cbETH, WBTC, WETH/USDC, and sDAI. The syrupUSDC pool alone accounted for approximately $173,700 of the total losses.
The oracle Ajna deliberately removed
Most decentralized lending protocols rely on external services such as Chainlink to determine collateral prices. Ajna took a different path. Its white paper describes the project as “a non-custodial, peer-to-peer, permissionless lending, borrowing and trading system that requires no governance or external price feeds to function.”
In Ajna’s framework, lenders set their own rates by depositing funds into fixed “buckets,” while protocol contracts determine when liquidations occur. Anyone initiating a liquidation must post a bond, creating a financial penalty for unjustified actions.
Security firm MixBytes has explained the reasoning behind removing oracles: “A significant portion of attacks on DeFi protocols stem from oracle prices manipulations, errors in configuration and access control issues.” By eliminating that attack surface, Ajna aimed to make its system more robust. The exploit shows how that decision created a different vulnerability.
Warning signs and aftermath
Data from DefiLlama at the time of the incident showed Ajna V2’s total value locked at around $206,000, with active loans of $418,000 and a 30-day TVL decline of 54.2%. The reported loss from the attack exceeded the protocol’s entire TVL at that moment.
| Metric | Current figure | 30-day change |
|---|---|---|
| Ajna V2 TVL | $449,783 | -17.1% |
| Active loans | $30,198 | Not reported |
| Ethereum TVL | $425,825 | – |
Note: Figures reflect live DefiLlama data after the attack; the reported exploit loss of $775,000 exceeded Ajna V2’s total TVL at the time of the incident.
Active loans now stand at just 6.7% of reported TVL, a ratio that underscores how much capital has left the protocol.
Evidence suggests the attacker did not compromise Ajna’s core code. Instead, the exploit manipulated internal accounting so the system accepted erroneous liquidation calculations. Ajna’s published audit history includes past findings related to liquidation process computations and bucket state accounting errors. Those issues were marked as resolved, but they point to the same area of logic the attacker ultimately exploited.
A familiar pattern in DeFi
The technique mirrors other recent incidents. Moonwell suffered a similar manipulation when an illiquid token was artificially lifted in value, allowing the attacker to extract millions in assets. Blockchain researchers at Nethermind have described how these exploits work: “They force the contract to calculate a distorted price and exploit it before the transaction ends.”
Ajna removed external oracles in pursuit of security, but its contracts still depend on self-verifying calculations. That reliance created a new opening, one that did not require compromising a third-party price feed.
The $775,000 loss is modest compared with the largest crypto thefts of 2026, yet it fits a broader trend. TRM Labs counted 207 protocol hacks in the first half of the year, a record for any six-month period, with a median loss of $219,000 per incident. More than 100 involved smart contract vulnerabilities. Infrastructure and operational compromises accounted for only about 15% of incidents but represented roughly 76% of total loss value.
Ajna’s case illustrates a different part of the security problem: losses do not need to come from spectacular exchange breaches or compromised private keys. They can emerge from the assumptions buried inside increasingly complex DeFi lending logic. The incident highlights the difficulty of designing decentralized systems that are genuinely secure, even when they deliberately avoid the components that have failed elsewhere.
Once added, BigGo Finance appears first in Google Search Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.
Source: finance.biggo.com

1 Comment
Pingback: TOP 5 Altcoins to Watch for September 2026 | Editor’s Pick Cryptocurrency Market News – xpertsstudio