Immutable Protocol Ajna v2 Hit by $775,400 Drain, Users Left to Withdraw Funds
A DeFi lending protocol called Ajna v2 was targeted by an attacker between August 28 and 29, resulting in $775,400 being drained from seven Ethereum pools.
The team behind Ajna issued a statement on August 29 at 04:58 UTC, instructing users to withdraw all quote tokens, repay outstanding loans, and cease further interaction with the protocol. This was due to an exploit that allowed the attacker to manipulate liquidation mathematics and assign more value to themselves than they were owed.
The attack did not involve stolen keys or compromised infrastructure; instead, it relied on the contract's code executing as intended. The Ajna v2 protocol is designed to be immutable, with no governance body, upgrade path, or administrator key to halt the contract.
According to Defimon, a security firm that detected the prepared attack contracts more than an hour before the first extraction, the team did not respond to their warning. The incident highlights the importance of user vigilance and the need for clear emergency response procedures in DeFi protocols.