Highlights
- Decentralized lending protocol Ajna confirmed its v2 deployment was hit by an exploit and is investigating abnormal fund flows.
- Monitoring firm Defimon Alerts estimates the loss at roughly $775,000.
- Seven pools were affected, including syrupUSDC, wstETH, rETH, cbETH, WBTC, WETH/USDC and sDAI.
- Ajna advised users to withdraw all funds, repay outstanding loans, and stop interacting with the protocol.
Decentralized lending protocol Ajna disclosed on August 29 that its v2 deployment was hit by a vulnerability exploit, posting on X that it had noticed abnormal fund flows and was actively investigating. Monitoring firm Defimon Alerts pegged the damage at approximately $775,000, attributing the incident to a liquidation accounting manipulation attack that touched seven separate liquidity pools: syrupUSDC, wstETH, rETH, cbETH, WBTC, WETH/USDC and sDAI. Ajna’s own guidance to users was blunt — withdraw all funds, repay loans, and pause any further interaction with the protocol until the investigation concludes.
What a Liquidation Accounting Attack Looks Like
Unlike exploits that rely on a manipulated price oracle to force liquidations, a liquidation accounting attack targets the bookkeeping logic a protocol uses to calculate how much collateral and debt a position actually holds once a liquidation is triggered. Security researchers have documented this as a recurring class of DeFi vulnerability, where incorrect assumptions in collateral and debt accounting let an attacker structure a position so the protocol misjudges how much can be extracted during liquidation — effectively convincing the contract a position is healthier, or worth more to seize, than it really is. That the exploit hit seven distinct pools spanning staked-ETH derivatives, wrapped bitcoin and stablecoin pairs suggests the flaw sat in shared liquidation logic rather than a single pool’s configuration.
Scale in Context
At roughly $775,000, the Ajna incident is modest next to 2026’s larger DeFi exploits, but it lands in a year that has already produced a steady cadence of protocol-level breaches — from governance failures to accounting bugs — across the sector. Smaller, accounting-logic exploits like this one tend to be harder for users to anticipate than headline-grabbing bridge hacks, since the attack surface lives inside contract logic that looks correct under normal market conditions and only breaks under a specifically engineered sequence of transactions.
Related: MANTRA's Post-Mortem: Aug 20 Exploit Moved 720.9M Tokens, No Keys Compromised
Why This Matters for Lenders and Borrowers
For anyone with open positions on Ajna v2, the immediate risk isn’t just the funds already lost — it’s that the same accounting flaw could be re-triggered against remaining pools before a fix ships, which is why the protocol’s own advice skipped straight to full withdrawal rather than a wait-and-see posture. The incident is also a reminder that liquidation mechanisms, the exact feature designed to keep a lending protocol solvent, are themselves a frequent target: when that logic breaks, it can flip from a safety mechanism into the attack vector itself.
What to Watch Next
The next milestones are a formal post-mortem from the Ajna team detailing the exact mechanism exploited, confirmation of whether any funds can be recovered or the attacker identified, and whether affected pools reopen only after an audited patch. Users with positions in the seven named pools should treat Ajna’s withdrawal guidance as active until the team confirms otherwise.
FAQ
How much did Ajna v2 lose in the exploit?
Monitoring firm Defimon Alerts estimates the loss at approximately $775,000.
Which pools were affected?
Seven pools were involved: syrupUSDC, wstETH, rETH, cbETH, WBTC, WETH/USDC and sDAI.
What type of attack caused the loss?
The incident is attributed to a liquidation accounting manipulation attack, which exploits flaws in how a protocol calculates collateral and debt during liquidation rather than manipulating a price oracle.
What should users with funds on Ajna v2 do?
Ajna has advised all users to withdraw their funds, repay any outstanding loans, and pause interaction with the protocol until the investigation is complete.
