$775K Loss Rocks Ajna V2 as Liquidation Accounting Exploit Exposes Oracle-Less Design Flaw
Ajna v2, an immutable, oracleless, no-governance lending protocol, suffered a significant loss of approximately $775K across seven Ethereum pools between August 28 and August 29. The incident appears to be a liquidation accounting exploit rather than an oracle attack.
The Ajna team acknowledged the situation publicly at 04:58 UTC on August 29, describing it as an ongoing investigation into 'unusual movements' and asked users to withdraw all quote tokens, repay loans, and stop interacting with the protocol. Security firm Defimon posted a full pool-by-pool loss table roughly four and a half hours later, claiming its detection stack had identified the prepared attack more than an hour before the first exploit transaction landed.
The incident highlighted vulnerabilities in oracle-less designs, raising concerns about broader systemic risk for crypto investors. The losses are small in absolute terms compared to recent DeFi incidents this month, but the incident carries outsized weight due to its implications on the design of lending protocols.