Ajna Protocol Loses $775K in Oracleless DeFi Exploit

1 hour ago 2 sources neutral

Key takeaways:

  • Ajna's oracle-free design shifted risk from price feeds to complex internal accounting logic.
  • Loss exceeding TVL highlights systemic vulnerability in DeFi's latest lending mechanisms.
  • Expect heightened scrutiny of peer-to-peer lending protocols' self-pricing mechanics after exploit.

Ajna Protocol, a non-custodial, peer-to-peer lending and borrowing platform that deliberately operates without external price feeds, has reportedly lost around $775,000 in ETH in a smart-contract exploit. According to on-chain monitoring and security reports, the attacker did not manipulate an external oracle; instead, the exploit targeted Ajna’s internal liquidation accounting and self-pricing mechanics.

Among the liquidity pools affected were syrupUSDC, wstETH, rETH, cbETH, WBTC, WETH/USDC and sDAI. The syrupUSDC pool alone accounted for roughly $173,700 of the total loss.

The attack raises difficult questions about Ajna’s design philosophy, which removes governance and price oracles. The project’s white paper states: “The Ajna protocol is a non-custodial, peer-to-peer, permissionless lending, borrowing and trading system that requires no governance or external price feeds to function.” Security firm MixBytes has previously argued that a significant portion of DeFi attacks stem from oracle price manipulations, configuration errors and access control issues, and Ajna removed that attack surface by trusting pool operations.

Blockchain security monitor Defimon said it detected a prepared attack more than one hour before the first exploit transaction and alerted the project via Discord, but the protocol was not secured in time. The attacker then moved across multiple pools. Early data showed Ajna V2 had total value locked of about $206,000 and active loans around $418,000, while its 30-day TVL variation was -54.2%. That meant the reported loss exceeded the protocol’s TVL at the time. Later snapshots showed Ajna V2 TVL around $449,783, down 17.1% over 30 days, with active loans of about $30,200 and Ethereum accounting for 94.7% of that TVL.

The exploit fits into a wider DeFi security pattern. TRM Labs counted 207 hacks in the first half of 2026, the highest six-month total it has recorded, with a typical incident costing about $219,000. More than 100 incidents involved smaller smart-contract exploits. Ajna’s case illustrates that losses can emerge from assumptions buried inside increasingly complex lending logic, rather than from exchange breaches or compromised private keys.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.