Immutable Protocol Ajna v2 Hit by $775,400 Exploit
Ajna v2, a DeFi lending protocol on Ethereum, has been hit by an exploit that drained $775,400 from seven pools between August 28 and 29. The incident highlights the risks of immutable protocols without governance or emergency stop buttons.
The attack exploited the liquidation mathematics in Ajna's protocol, which assigns value to residual quantities after a liquidation. By triggering multiple liquidations across seven pools, the attacker was able to assign more value to themselves than they were owed, resulting in the observed sum of $775,400.
Ajna v2's design deliberately avoids oracles and relies on lenders' bids to value assets. This makes it less vulnerable to common attacks, but also means that users are left with no pause button in case of an emergency.