Ajna Protocol, a decentralized lending platform that operates without external price oracles or governance controls, has suffered a major security breach resulting in the loss of approximately $775,000 in ETH. The attack exploited internal liquidation accounting, bypassing traditional third-party price feed vulnerabilities.
Attack exploits lack of oracles
Unlike most DeFi lending protocols that use external services such as Chainlink to determine collateral prices, Ajna relies solely on its own internal mechanisms. The platform’s white paper describes it as a non-custodial, peer-to-peer, permissionless system designed to require no external price feeds or governance measures for its operation.
“The Ajna protocol is a non-custodial, peer-to-peer, permissionless lending, borrowing and trading system that requires no governance or external price feeds to function.”
In Ajna’s framework, users specify lending rates by depositing funds into fixed “buckets,” while protocol contracts automatically control when liquidations occur. Initiating a liquidation requires the payment of a bond, penalizing unjustified liquidations and theoretically limiting misuse.
Security firm MixBytes commented on Ajna’s rationale for removing oracles, noting that a majority of DeFi attacks arise from price manipulations, configuration errors, and access control issues associated with external oracles.
“A significant portion of attacks on DeFi protocols stem from oracle prices manipulations, errors in configuration and access control issues.”
Ajna aimed to minimize attack vectors by omitting oracles and relying on the protocol’s internal calculations. However, the breach exploited exactly this feature, allowing the attacker to manipulate liquidation accounting without targeting any third-party oracle.
Mini dictionary: Chainlink is a widely used decentralized oracle network that supplies smart contracts with real-world data, such as asset prices, enabling DeFi protocols to perform key functions based on reliable external information.
Early warning ignored, multiple pools affected
Defimon, a firm monitoring DeFi systems, reported that it detected an imminent attack more than one hour before the first exploit transaction occurred and alerted Ajna via its Discord channel. Despite the warning, the protocol remained vulnerable when the attack began.
The exploiter targeted several liquidity pools including syrupUSDC, wstETH, rETH, cbETH, WBTC, WETH/USDC, and sDAI. The syrupUSDC pool alone accounted for roughly $173,700 of the total losses.
DeFi data aggregator DefiLlama showed that at the time of the incident, Ajna V2’s total value locked (TVL) was around $206,000 with active loans of $418,000, and a 30-day TVL decline of -54.2%. Notably, the losses from the attack exceeded the entire TVL reported for Ajna at that moment.
| Metric | Value | 30-day change |
|---|---|---|
| Ajna V2 TVL (post-attack) | $449,783 | -17.1% |
| Active loans | $30,198 | Not reported |
| Reported exploit loss | $775,000 | — |
| Ethereum TVL | $425,825 | — |
Ajna V2 now manages about $450,000 in TVL and $30,200 in active loans, with TVL dropping by 17.1% over the last month. The current ratio of active loans to TVL stands at 6.7%, raising questions about the underlying vulnerabilities targeted in the exploit.
Security questions and broader trends
Evidence indicates the attacker did not hack Ajna’s core code but manipulated internal accounting, leading the system to accept erroneous liquidation calculations. Previously published audit findings highlighted earlier concerns regarding liquidation process computations, though those issues were considered resolved.
Such attacks fit a growing pattern in decentralized finance. In a notable comparable incident, Moonwell suffered a similar manipulation, where an illiquid token was lifted in value to extract millions in assets from the protocol.
Analysis by blockchain researchers such as Nethermind explains that these exploits often distort on-chain price calculations momentarily and extract value before the protocol can respond.
“They force the contract to calculate a distorted price and exploit it before the transaction ends.”
Ajna removed external oracles in pursuit of security, but its contracts still have to rely on self-verifying calculations—leaving a new kind of opening for attackers.
Wider context in 2026 DeFi exploits
While Ajna’s $775,000 loss is smaller than the largest crypto thefts this year, it is consistent with recent trends. TRM Labs reported 207 crypto protocol hacks in the first half of 2026, a record six-month figure, with a median loss of $219,000 per incident. Over 100 were tied to smart contract vulnerabilities.
Operational and infrastructure compromises accounted for 15% of all attacks but made up 76% of total loss value.
Ajna’s exploit demonstrates that significant DeFi risks can arise not just from headline-making exchange breaches but also from complex, untested logic in DeFi lending contracts. The incident highlights the challenges of designing truly secure decentralized systems.





USDT
AAPL
