$775K Loss for Ajna Protocol as Attackers Exploit Internal Mechanisms
The lending platform Ajna Protocol suffered a $775,000 loss in Ethereum due to an exploit. The attackers used the internal liquidation accounting of the platform instead of relying on third-party price feeds.
Ajna's whitepaper describes the protocol as non-custodial, peer-to-peer, and permissionless, requiring no governance or external price feeds. However, MixBytes explained that eliminating the oracle was a way to reduce the attack surface and trust the pool's operations.
The attacker targeted internal mechanisms instead of compromising the external price oracle. The assault affected various liquidity pools, including syrupUSDC, wstETH, rETH, cbETH, WBTC, WETH/USDC, and sDAI. The losses were approximately $173,700 for the syrupUSDC pool.
The incident raises questions about Ajna's philosophy of not relying on oracles and governance. The attackers may have exploited this assumption by tricking the system into accepting false data as valid. This is consistent with previous attacks on DeFi protocols that involved manipulating prices and exploiting vulnerabilities in liquidation logic.