$775K Ajna Exploit Exposes Risks in Self-Price Markets
Ajna Protocol, a lending platform without price oracles, lost around $775,000 in ETH due to an exploit. The attackers used internal liquidation accounting instead of external price feeds.
The attack impacted several liquidity pools, including syrupUSDC, wstETH, rETH, cbETH, WBTC, WETH/USDC, and sDAI. However, it raises questions about Ajna's philosophy of not using oracles or governance in its self-pricing market.
Ajna intentionally does not use external price feeds, unlike most lending protocols that rely on services like Chainlink. The protocol's white paper describes itself as a non-custodial, peer-to-peer, permissionless lending system without external price feeds. MixBytes explained the reasoning behind this approach: 'a significant portion of attacks on DeFi protocols stem from oracle prices manipulations, errors in configuration and access control issues.'
Defimon claims to have detected the prepared attack over an hour before it happened but Ajna did not take action to secure its protocol. The hacker then traversed multiple pools, with the syrupUSDC pool suffering losses of approximately $173,700 out of a total loss of about $775,000.