Invest1 distinct publisher3 min readPublished
Removing the price feed moved the number an attacker had to distort rather than deleting it. The $775,000 taken came to 3.8 times the TVL DefiLlama recorded for Ajna V2, and the loan book has since fallen 92.8%.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
Ajna does not remove the price function when it removes the oracle; it moves that function inside the contracts, into the pool's own bucket and take accounting. In Ajna, lenders deposit into buckets at prices they pick, and the contracts read that state to decide when a loan is liquidatable, with whoever starts a liquidation posting a bond so that calling a healthy loan carries a cost [5][6]. The design deletes a third-party feed, which is real, but it also promotes the pool's own take-and-bucket arithmetic into the price function, and Ajna's published audit history already contained findings on that surface: take computations during liquidation, and bucket state accounted for incorrectly, both since marked resolved [11]. Nethermind's summary of this class of attack, that they force the contract to calculate a distorted price and exploit it before the transaction ends [13], describes something that needs no external feed to be present.
The size is what argues against a one-off. Roughly $775,000 in ETH against the $206,000 of Ajna V2 TVL that DefiLlama showed at the time is 3.8 times the recorded deposit base [1][10][1], and the loss was spread: syrupUSDC gave up about $173,700, or 22.4% of the total [9][2], which leaves $601,300 across the six other named pools, near $100,200 each if it were even [2][3]. Repetition across pools reads as a procedure rather than a lucky transaction. (The at-the-time figures also sit oddly with each other: about $418,000 of active loans against $206,000 of TVL is 203% [10][4], a useful reminder that headline TVL is not the collateral pile a reader assumes it is.)
Defimon says it spotted a prepared attack more than an hour before the first exploit transaction and posted the warning in Ajna's Discord, and the protocol was still unsecured when the first one landed [8]. An hour is a long time if there is a lever and no time at all if there is not, and the white paper's promise of a system that requires no governance or external price feeds to function [4] is the reason to suspect the second. What is left afterwards is a loan book that has gone from about $418,000 to $30,200, down 92.8% [14][6], now standing at 6.7% of a $450,000 TVL [5], which is borrowers using one dollar in fifteen of the shelf.
This is probably wrong in one direction, or rather, the more interesting version of wrong. The MixBytes premise, that a significant share of DeFi attacks come out of oracle price manipulation, configuration errors and access control problems [7], is not refuted by a single incident, and the oracle-having comparison in the same account is Moonwell, where roughly $7 million pushed an illiquid token eight-fold, borrowed close to $10 million of real assets and left with about $6 million, an 86% return on capital deployed [12][7], which is an order of magnitude dearer than what happened here, so relocating an attack surface and worsening it remain separate claims. What would show me wrong is a post-mortem that names one arithmetic bug in the take path, patches it in a commit, and demonstrates no analogous invariant sitting unguarded elsewhere. What would confirm it is the next oracle-free lender losing money through accounting its contracts trusted because they computed it themselves.
Ranked by verification strength, evidence, and original report placement.
Ajna Protocol reportedly lost about $775,000 in ETH after an attacker exploited its internal liquidation accounting rather than a third-party price feed.
The attack targeted multiple pools, including syrupUSDC, wstETH, rETH, cbETH, WBTC, WETH/USDC and sDAI.
Security firm MixBytes said that "a significant portion of attacks on DeFi protocols stem from oracle prices manipulations, errors in configuration and access control issues."
In the earlier Moonwell case, an attacker used approximately $7 million to lift the illiquid MAMO token by eight times, borrowed nearly $10 million of real assets, and left with close to $6 million.
Ajna deliberately operates without external price oracles, relying instead on its own market and liquidation mechanisms; most lending protocols use an external service such as Chainlink to price collateral.
Ajna's white paper describes the protocol as "a non-custodial, peer-to-peer, permissionless lending, borrowing and trading system that requires no governance or external price feeds to function."
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 29, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
invest
Five curators, $11.29B: the vault market where diversifying buys the same risk twice1 distinct publisher
invest
A Solana DEX halted trading and says the loss stopped at its treasury. Nobody can check1 distinct publisher
invest
An attacker burned $3.8M in MAMO slippage to borrow $10M of Moonwell depositors' assets1 distinct publisher
invest
RWA collateral in DeFi nears $4B, and 88% of tokenized assets still do nothing1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One outlet, one detector, no post-mortem
Everything material traces to Defimon Alerts, relayed by a single publisher, with no transaction hash, no attacker address, no named function, and no word from Ajna. The strongest independently checkable item in the piece is the white paper quote and the protocol's own published audit findings — documents, not incident evidence. The exploit itself is asserted and characterised, never demonstrated.
A protocol smaller than the loss against it
Ajna V2 is reported holding roughly $450,000 in deposits against $30,200 in active loans — borrowing at 6.7% of TVL, down about 92.8% from the $418,000 outstanding when the attack hit. Whatever the oracle-free thesis is worth, almost nobody is currently borrowing against it, and the reported theft exceeded the locked value DefiLlama showed at the time.
Framing outruns the paper trail
The design argument — remove the oracle and you relocate the trusted number rather than removing it — is genuinely interesting, and the loss is presented as 3.8 times TVL, which sounds devastating. But that multiple is built from figures that do not reconcile: $775,000 taken, $206,000 locked, $418,000 lent, and a later TVL that is somehow higher while also falling 17.1%. The story is also stretched to fit a record-year-for-exploits frame it explicitly concedes it is modest against. The mechanism is oversold relative to what has actually been shown about this particular incident.
The detector supplies both the alarm and the timeline
Defimon is the origin of the loss figure and of the claim that it saw the attack coming an hour early and was ignored — a story that happens to be the best possible advertisement for a monitoring service. MixBytes and Nethermind are quoted as expert voices in a market where security firms compete on visibility. And the pattern-establishing precedent, Moonwell, is Cryptopolitan citing Cryptopolitan. None of that makes the account wrong; it does mean no disinterested party is on the record.
Enough to describe, not enough to settle
We can say with reasonable confidence what Ajna is by design — the white paper language, the buckets, the liquidation bond, the prior audit findings on take math and bucket accounting are all verifiable. What happened on the day is a different matter: one publisher, one detector, unreconciled balance-sheet figures, and silence from the protocol. Treat the architecture description as solid and the incident narrative as provisional.