Ajna Protocol, a non-custodial, peer-to-peer lending and borrowing platform that deliberately operates without external price feeds, has reportedly lost around $775,000 in ETH in a smart-contract exploit. According to on-chain monitoring and security reports, the attacker did not manipulate an external oracle; instead, the exploit targeted Ajna’s internal liquidation accounting and self-pricing mechanics.
Among the liquidity pools affected were syrupUSDC, wstETH, rETH, cbETH, WBTC, WETH/USDC and sDAI. The syrupUSDC pool alone accounted for roughly $173,700 of the total loss.
The attack raises difficult questions about Ajna’s design philosophy, which removes governance and price oracles. The project’s white paper states: “The Ajna protocol is a non-custodial, peer-to-peer, permissionless lending, borrowing and trading system that requires no governance or external price feeds to function.” Security firm MixBytes has previously argued that a significant portion of DeFi attacks stem from oracle price manipulations, configuration errors and access control issues, and Ajna removed that attack surface by trusting pool operations.
Blockchain security monitor Defimon said it detected a prepared attack more than one hour before the first exploit transaction and alerted the project via Discord, but the protocol was not secured in time. The attacker then moved across multiple pools. Early data showed Ajna V2 had total value locked of about $206,000 and active loans around $418,000, while its 30-day TVL variation was -54.2%. That meant the reported loss exceeded the protocol’s TVL at the time. Later snapshots showed Ajna V2 TVL around $449,783, down 17.1% over 30 days, with active loans of about $30,200 and Ethereum accounting for 94.7% of that TVL.
The exploit fits into a wider DeFi security pattern. TRM Labs counted 207 hacks in the first half of 2026, the highest six-month total it has recorded, with a typical incident costing about $219,000. More than 100 incidents involved smaller smart-contract exploits. Ajna’s case illustrates that losses can emerge from assumptions buried inside increasingly complex lending logic, rather than from exchange breaches or compromised private keys.