$775k Lost as Ajna Protocol's Oracle-Free Design Turns into Attack Vector
A DeFi lending platform called Ajna Protocol has suffered a significant loss after an attacker exploited its internal liquidation accounting, resulting in approximately $775,000 in ETH lost. The incident affected multiple liquidity pools, with the syrupUSDC pool alone accounting for around $173,700 of the total losses. Monitoring firm Defimon warned the project more than an hour before the attack via Discord, but Ajna remained vulnerable.
The attacker manipulated internal calculations rather than hacking core code, turning Ajna's oracle-free design into an attack vector. This exploit mirrors recent incidents such as Moonwell, where an illiquid token was artificially lifted in value to extract millions in assets.
Ajna removed external oracles in pursuit of security, but its contracts still depend on self-verifying calculations. This reliance created a new opening that did not require compromising a third-party price feed.