The decentralized lending protocol Ajna v2 has lost approximately $775,400 in a sophisticated exploit that manipulated its internal liquidation accounting across seven Ethereum pools. Unlike many DeFi hacks that target price oracles or steal private keys, this attack exploited the protocol’s own code logic, and because Ajna is built as an immutable contract with no governance, there was no way to pause operations or patch the flaw mid-attack.
What Happened: Timeline and Loss Breakdown

The attack unfolded over a tight window on August 28–29, 2026. Attack contracts were deployed on Ethereum at 15:16 UTC on August 28, and the first funds were drained just over an hour later at 16:19 UTC from the cbETH pool. The Ajna team did not issue its public warning until the next morning, at 04:58 UTC on August 29, by which time the exploit had already affected multiple pools.
Security firm Defimon Alerts reported that it detected the prepared attack more than an hour before the first exploit transaction and notified the Ajna team via Discord, but no public response or mitigation followed. By the time the team urged users to withdraw, roughly $775,400 had been siphoned from seven liquidity pools.
Defimon’s per-pool breakdown shows the damage was spread as follows:c
- syrupUSDC: ~$173,700 (largest single pool loss)
- wstETH: ~$159,800
- rETH: ~$143,000 (across two transactions)
- cbETH: ~$136,900 (across two transactions)
- WBTC: ~$101,800
- WETH/USDC: ~$42,000
- sDAI: ~$18,000
After the incident, Ajna’s total value locked (TVL) fell to around $246,880, representing a 71.3% drop over the preceding 30 days.
How the Attack Worked: Liquidation Math, Not Oracle Manipulation

Ajna v2 is designed to operate without external price oracles. Instead of relying on third-party price feeds, the protocol determines asset valuations based on lender bids within each pool. This oracle-free design eliminates a common attack vector but shifts risk to other parts of the system.
In this case, the attacker did not manipulate price data. Instead, they triggered liquidations and exploited how the protocol calculates and books residual quantities during the liquidation process. By manipulating the liquidation accounting, the attacker was able to extract more value than they were owed, repeating the process across multiple pools to accumulate the total loss.
Notably, Ajna v2 had undergone security audits, yet the vulnerability still existed. This aligns with broader 2026 data showing that a majority of major DeFi exploits hit audited protocols, underscoring that audits reduce risk but do not guarantee safety.
Why There Was No Pause Button: The Cost of Immutability

Ajna v2 is built as an immutable smart contract, meaning its code cannot be changed after deployment. There is no governance body, no admin key, and no upgrade mechanism that could halt operations or apply a fix. This design philosophy is intentional: it removes trust in a central team and prevents rule changes that could disadvantage users.
However, when a vulnerability is discovered, immutability leaves the team with only one option: ask users to withdraw their funds. Unlike protocols with emergency pause functions or upgradable contracts, Ajna could not be stopped mid-attack, even if the team had responded immediately to Defimon’s warning.
This incident highlights a critical trade-off in DeFi design: immutability enhances trustlessness but removes the ability to respond quickly to emergencies.
What Ajna Users Must Do Now

The Ajna team issued a clear, three-step instruction for all users on August 29:
- Withdraw quote tokens immediately. Quote tokens are the assets being lent in each pool. Lenders should unwind their positions in all pools, even those not listed in the Defimon breakdown, as the flaw affects the entire protocol.
- Repay outstanding loans. Borrowers must repay their debts to retrieve collateral, which remains at risk as long as it is locked in the compromised contract.
- Stop all further interactions. No new deposits, loans, or bid adjustments should be made until the situation is fully resolved.
Users are also warned to access the protocol only through trusted bookmarks, as phishing sites often emerge after exploits to target panicked users.
Broader Lessons for DeFi Users and Investors
The Ajna exploit is part of a pattern of DeFi incidents in 2026, including a separate $500,000+ breach at Solana-based card app Avici just one day earlier. While $775,400 is a relatively small sum compared to multi-million dollar hacks, it serves as a stark reminder of the risks inherent in immutable, governance-free protocols.
For investors, the key takeaway is to assess emergency mechanisms before depositing funds. Critical questions include:
- Does the protocol have a pause function or emergency guardian?
- Is the contract upgradable, and who controls the upgrade keys?
- How will security warnings reach you (e.g., email, dashboard alerts, Discord)?
Protocols without these safeguards place the entire burden of risk management on users, who must act as their own emergency switch.
What’s Next for Ajna and DeFi Security

As of now, Ajna has not announced a reimbursement plan, which is consistent with its immutable, treasury-less design. The protocol’s future depends on whether the community can coordinate a response or migrate to a safer version.
For the broader DeFi ecosystem, the incident reinforces the need for balanced design: trustlessness is valuable, but so is the ability to respond to crises. As DeFi matures, protocols may need to incorporate limited, transparent governance or emergency controls to protect users without sacrificing decentralization.

