Ajna Exploit: $775,400 Drained and No Pause Button in the DeFi Lending Protocol
Between August 28 and 29, 2026 roughly $775,400 drained out of seven Ethereum pools of the lending protocol Ajna v2. Because the contract is immutable and has no governance, there is no pause button: users have to withdraw themselves.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
If you have funds sitting in the DeFi lending protocol Ajna v2, withdraw them now. The development team itself called for exactly that on August 29, 2026 at 04:58 UTC: withdraw all quote tokens, repay outstanding loans and stop every further interaction with the protocol. Between August 28 and 29, roughly $775,400 drained out of seven pools on the Ethereum blockchain. Measured by the sum, this is a small incident. Measured by what it reveals about a particular way of building DeFi protocols, it is among the most instructive of this summer.
The reason lies in the construction. Ajna v2 is built to be immutable: no governance body, no upgrade path, no administrator key that could halt the contract. A security update while the protocol runs is therefore technically ruled out. The only party that can stop the outflow is the users, by taking their capital out. The team's call is consequently not one precaution among others. It is the only available response.
The Ajna exploit at a glance: $775,400 from seven Ethereum pools
A DeFi lending protocol is a set of smart contracts through which users can lend crypto assets and borrow against posted collateral, with no bank or company in between. At Ajna the lent capital sits in pools, each of which brings together one collateral asset and one loan asset.
The security firm Defimon published a per-pool breakdown on August 29 at 09:29 UTC. According to it, the damage is distributed as follows: the syrupUSDC pool lost the most at around $173,700, followed by wstETH at about $159,800 and rETH at roughly $143,000 in total across two transactions. cbETH accounted for around $136,900, likewise in two steps, the WBTC pool for around $101,800, WETH/USDC for around $42,000 and sDAI for around $18,000. Together that produces the $775,400 mentioned above. The outlet Cryptopolitan, citing DefiLlama, gives a slightly different figure of around $775,000; the difference lies in how the affected tokens are priced and is immaterial for the assessment.
The timeline is tight. On August 28 at 15:16 UTC the attack contracts were deployed on Ethereum. A good hour later, at 16:19 UTC, the first extraction ran through the cbETH pool, recorded in block 25854888. The team's public statement did not follow until the next morning. In the meantime the outflow continued.
That leaves marks on the size of the protocol. Total value locked, meaning the sum of all assets deposited in the protocol, stood at about $246,880 after the incident. Over the preceding thirty days that amounts to a decline of 71.3 percent. Ajna was already a small protocol before the attack. Now it is a very small one.
Liquidation math rather than an oracle: how the attack worked
According to the analysis by the trade publication The Crypto Times, this was a manipulation of the liquidation accounting rather than an attack on a price source. That distinction is the core of the case, and it calls for two short definitions.
What an oracle does in a lending protocol
An oracle is a service that feeds a smart contract with prices from the outside world, such as the current rate of Ether in US dollars. Almost every lending protocol needs something of the kind in order to decide when a position is undercollateralised. That is precisely why oracles are a favoured target: anyone who briefly bends the supplied price can have healthy positions liquidated or pass off worthless collateral as valuable.
Ajna deliberately does without oracles. Valuation follows from the bids of the lenders in the pool itself. This design rules out the most common class of attack, and in that respect it held up. The attacker had to take a different route.
Why the liquidation mathematics was the point of attack
A liquidation is the process in which a protocol realises a borrower's collateral because their position breaches the permitted limit. In doing so the contract calculates how much collateral is surrendered for how much debt and what happens to the remainder. In every lending protocol this calculation is the most demanding place in the code, because it has to keep interest, fees, partial liquidations and rounding straight all at once.
That is exactly where the attack came in. The attacker triggered liquidations and exploited how the protocol books the residual quantities that arise in the process, in order to have more value assigned to himself than he was owed. Repeated across seven pools, that produced the observed sum. What stands out is that no stolen keys and no compromised infrastructure were involved. The contract did precisely what its code provided for.
It is also worth noting that Ajna v2 had been audited. The case thus joins an observation that CoinGecko records in its report on the state of crypto security in 2026: of 245 incidents logged between January 2025 and July 2026, with total damage of $3.63 billion, 147 hit audited protocols, which accounted for 88.44 percent of the stolen capital. A passed audit is a quality signal. It is not a guarantee.

An immutable protocol without governance: why the pause button is missing
An immutable smart contract is a contract whose code can no longer be changed after deployment. There is no address permitted to push new logic in, and no function that halts operation. In parts of the DeFi scene this construction is an explicit ideal, because it makes trust in a team unnecessary. Nobody can change the rules after the fact to their own advantage, the developers included.
The price of that shows up when damage occurs. With an upgradeable protocol, a team could have taken the affected pools offline around 16:30 UTC on August 28 and fixed the flaw. At Ajna v2 that route was not open. The Crypto Times puts it that a code patch during operation is not the usual response here and that users themselves take on the function of the pause button. This is not negligence on the team's part but the consequence of a deliberate design decision.
For you as an investor this leads to a question that comes before any thought about returns: who can halt this protocol in an emergency, and how quickly? The answer differs completely from provider to provider, and it rarely appears on the landing page. Our comparison of crypto lending providers shows which models work with custody and emergency mechanics and which leave you entirely on your own.
Crypto Lending Providers ComparedDefimon warned an hour beforehand: what the timeline says about response routes
The security firm Defimon states that its monitoring detected the prepared attack contracts more than an hour before the first extraction and notified the Ajna team through its Discord channel, and that no response to this message followed. This account comes from a provider that markets precisely such early detection, and it has so far not been independently confirmed. No public statement from the Ajna team on this point is available.
Even if the description is accurate in every detail, the decisive limitation remains. A warning only helps if its recipient can act. With an immutable contract and no governance, the team could not have switched anything off even with an immediate response. It could merely have warned earlier, and users would have had to withdraw earlier. In this building principle the warning chain always ends with you.
That sets the case apart from incidents in which a network can be stopped centrally. In the Maya Protocol exploit, for instance, operations were halted to prevent further damage. That option does not exist everywhere, and it is itself contested, because it presupposes that somebody has the power to stop an open system.
What Ajna users have to do right now
The team's instruction is brief and unambiguous. It consists of three actions, and the order is not arbitrary.
First: withdraw quote tokens. Quote token is Ajna's term for the asset in a pool that is being lent, meaning the side on which a lender contributes capital. Anyone standing as a lender in one of the pools should unwind that position. This explicitly applies to pools that do not appear in the Defimon breakdown: the breakdown documents where money has already drained out, not where it sits safely.
Second: repay outstanding loans. Anyone who has posted collateral as a borrower gets it back only through repayment. As long as the debt is open, the collateral stays in the contract and therefore in a system whose liquidation math is demonstrably open to attack.
Third: no new interactions. No new loan, no new deposit, no adjustment of existing bids. Every further transaction exposes capital to the open flaw once more.
For carrying this out, the same principle applies as to any emergency action in DeFi: call up addresses only from your own bookmarks and never from search results or from messages that reach you unsolicited. After an exploit becomes known, the number of fake rescue pages rises regularly, because fraudsters bank on precisely the urgency that has arisen.

How to check whether your lending protocol has an emergency exit
The question of the pause button can be settled in a few minutes once you know what to look for. Three points are enough for a first assessment.
Three questions to put to the documentation
First: is there a pause function, and who may trigger it? The documentation usually lists it under headings such as emergency pause, guardian or circuit breaker. If any reference to it is missing, assume an immutable design.
Second: is the contract upgradeable, and who holds the keys? An upgrade path means a flaw can be fixed. It also means somebody can change the rules while your money sits in the contract. The two belong together and form no contradiction, but a trade-off you should make deliberately.
Third: how does a warning reach you? If the only reporting chain is a Discord channel you do not read, it practically does not exist for you. A notification service for your own addresses costs nothing and buys you the head start that matters when it counts.
Anyone who shies away from this check will find the simpler answer with supervised providers: there a company is liable under supervision, and responding to an incident is part of the business model. This route costs return and takes control away from you. It also takes away the job of being the emergency switch yourself at 16:19 UTC.
Hardware Wallets ComparedAjna in context: a summer of many small incidents
The Ajna exploit does not stand alone. A day earlier, on August 28, 2026, the Solana-based card application Avici lost $500,859.22 in card balances by DefiLlama's count, affecting 1,685 users. Initial estimates had ranged between $600,000 and more than a million; the lower figure prevailed after the review. The cause, according to the card partner Rain, was a faulty version of a card contract that a few other programs also used. Avici has undertaken to reimburse all affected card balances in full.
The two cases differ in exactly the point at issue here. At Avici there is a company that can make an undertaking and whose partner names the flaw. At Ajna there is a contract that keeps running and a team asking people to withdraw. A reimbursement is not provided for in a protocol with no treasury and no governance.
To place the order of magnitude, the statistics help. The CoinGecko report already mentioned counts 245 incidents with $3.63 billion in damage for January 2025 through July 2026. Against that yardstick, $775,400 is a footnote. For those affected the sum is lost in full, and what decides its significance is its share of their own portfolio, not its share of the annual statistics.
Tax and evidence: what investors should document after an exploit
A loss through an exploit is not a straightforward matter for tax purposes, and this article is no substitute for tax advice. What is worth doing regardless is securing the evidence, and immediately, while the data is still within reach.
Save the transaction hashes of your deposits and withdrawals, the account balance of the affected position before August 28, 2026, the protocol's public statement with date and time, and proof of the outflows from a blockchain explorer. You will need these documents should a reimbursement, a settlement or a tax treatment come into play later. Anyone who only gathers them at that point is working against deleted web interfaces and archived Discord channels.
What matters is keeping two events apart: the outflow through the attack and the later sale of a rescued position are two different things for tax purposes. Record both separately, with date, quantity and value in your reporting currency.
Placing the Ajna exploit: what to take away
- If you are invested in Ajna v2, act today. Withdraw quote tokens, repay loans, stop interacting, in that order. Where to place your capital instead and on what terms is set out in our crypto lending comparison.
- Settle the emergency question for every protocol before you deposit. Pause function, upgrade path, reporting route. Anyone unwilling to carry out this check themselves is better served by supervised providers; which platforms are licensed is shown by our overview of regulated crypto exchanges.
- Separate trading balances from holdings. What you are not actively deploying belongs not in a smart contract but in your own custody. Which devices come into question and how they differ is covered in the hardware wallet comparison.
The per-pool breakdown and the timeline come from the analysis by The Crypto Times of August 29, 2026. The project published its call to users the same day at 04:58 UTC on its account @ajnafi on X.
(As of August 29, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- The Top NFT Lending Platforms of 2023
- What Is DeFi? – A Beginner’s Guide To 5 Core DeFi Protocols
- Cetus Hack on Sui Network: What Happened and Why SUI Price Is Crashing
- Can Ethereum Price Crash to $0? Analyzing Ethereum Blockchain
- Cronos chain halt: how a Tectonic exploit emptied the chain's largest lending market
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
August 30, 2026 10:30 PM

Moonwell Exploit on Base: How a MAMO Oracle Manipulation Drained $8.7 Million From the Lending Market
An attacker drove the price of the thinly traded MAMO token fortyfold and borrowed $11.03 million against it from the Moonwell lending protocol on Base. Around $9.13 million remains open and falls on depositors who never touched MAMO.
August 31, 2026 4:27 PM

More Markets Exploit: How a Liquid Staking Token and E-Mode Pulled $9.3 Million Out of a Lending Market
Around 15.5 million WFLOW drained from the lending market More Markets on August 31, 2026, roughly $9.3 million by Blockaid's estimate. The route ran through a liquid staking token used as collateral and through E-Mode, and both building blocks sit in protocols you know.
November 27, 2022 9:22 PM

Top 3 Ethereum Use Cases that will NEVER let Ethereum Die!
Ethereum is the biggest smart-contract blockchain hosting many ecosystems. Here are 3 reasons why Ethereum will not die and reach 0$.
December 22, 2021 12:16 AM

Top Emerging Platforms for Crypto Loans
If you are looking for a quick loan and want to explore the best platforms, this is the right place. Let's see which are the top 3 crypto loans platforms!
February 13, 2020 4:18 PM

Top 3 Ethereum Mining Pools
Ethereum is one of the most popular cryptocurrencies. There are many advanced features which make this coin as one of the best coins to invest. The Ethereum miner is a person that dedicates time and power to classifying through blocks. […]
August 14, 2019 2:21 PM

What is Ethereum Virtual Machine?
The Ethereum Virtual Machine (EVM) is a robust, sandboxed virtual implicit enclosed within each complete Ethereum node, capable of performing contract bytecode. Contracts are normally inscribed in higher-level languages, like Solidity, then gathered to EVM bytecode. Virtual machines are actually […]
August 6, 2026 1:00 PM

$42 Million in Eight Days: Why ‘Decentralised’ Stopped Protecting Perp DEX Traders
Ostium and AFX were drained inside eight days – both times through keys, not smart contracts. The seven questions you must answer before any deposit.
July 24, 2026 1:25 PM

AFX Trade Hack: Arbitrum Perp DEX Loses $24M as Bridge Keys Are Compromised
AFX Trade lost $24.15M USDC after attackers compromised its bridge validator keys. The perp DEX offered the hacker a 30% bounty to return it.
July 24, 2026 1:09 PM

Ostium Hack: Perp DEX Loses $23.75M in Oracle Key Exploit, Resumes Trading July 23
Ostium lost $23.75M USDC after a compromised oracle signer key let attackers fake prices. The Arbitrum perp DEX reopened trading on July 23.
April 21, 2026 2:00 PM

LayerZero Security Alert: Is Your Crypto Safe After the $292M KelpDAO Exploit?
A $292M exploit on KelpDAO exposes a massive LayerZero vulnerability. With 47% of apps at risk, are your assets still safe in the crypto space?
April 20, 2026 9:52 AM

DeFi Hack: Aave and LayerZero Hit by Sophisticated DPRK Attack
DeFi confidence hits a new low as Aave freezes markets following a sophisticated $293M exploit on Kelp DAO’s rsETH, linked to North Korea's Lazarus Group.
September 16, 2026 4:19 AM

Check Your Safe Wallet Modules: How One Module Moved $7.7 Million Without a Signature
On September 15, 2,882 rsETH drained out of a Safe multisig without a single owner signing. An enabled module was to blame, and this is how you check your own wallet in five minutes.
September 14, 2026 4:10 AM

Foreign Code on Your Ethereum Address: How to Check Your EIP-7702 Delegation
Since the Pectra upgrade, a single signature can be enough for your Ethereum address to run the code of someone else's contract. Our own measurement across 200 blocks shows what these delegations mostly point to today, and how to check your own address in a few minutes.
August 30, 2026 10:38 PM

Crypto Cards: Where Your Card Balance Really Sits and What the August 28 Solana Exploit Reveals About It
An attack on a card balance contract on Solana took the loaded balance from 1,685 users while their wallets stayed untouched. The case shows why it matters whether your crypto card holds funds as e-money at a licensed institution or in a smart contract.
December 16, 2023 4:33 PM

BREAKING NEWS: NFT Trader Hit in Largest NFT Hack to Date?
NFT Trader Hit in Largest NFT Hack. Let's take a look at this in more detail as the NFT community is grappling with the profound impact.
October 29, 2023 1:47 AM

Exploring ERC-4337 on Etherscan: A Comprehensive Guide to Enhanced Ethereum Transactions
Unlock the potential of Ethereum with our comprehensive guide to ERC-4337 on Etherscan. Learn about smart contract wallets, User Ops, and Paymasters in this groundbreaking update.
September 11, 2023 1:50 AM

Exploring the Leading DeFi Tokens: A Comprehensive Guide
A comprehensive dive into the top five DeFi tokens. From Dai's stability to Uniswap's transformative approach, explore the giants shaping the decentralized finance realm.
April 16, 2023 7:08 AM

How the Ethereum Shanghai Upgrade Could Affect Top Ethereum Layer 2 Coins: A Comprehensive Guide
Let's take a look at the top Ethereum layer 2 coins and how they might be impacted by the Ethereum Shanghai Upgrade.
November 28, 2022 7:47 AM

Aave Review 2022 – Is Aave Worthwhile?
This article is all about Aave review 2022 and whether Aave is worthwhile or not. Let’s take a look at it in more detail.
October 18, 2022 4:51 AM

Top 5 Decentralized Exchanges (DEX) on Ethereum in 2022 – An Overview
What are the top 5 Decentralized Exchanges (DEX) on the Ethereum Blockchain in 2022 after the merge? Let's take a look at it in more detail.
January 18, 2021 3:45 PM

DeFi News Ticker – CryptoTicker
Decentralized finance (better known as DeFi) is a set of peer-to-peer financial services running on decentralized blockchains, most commonly Ethereum. It includes financial services such as lending and borrowing, decentralized exchanges, interest generation (yield farming), synthetic assets, insurances, etc… DeFi offers very high interest rates, […]
January 7, 2021 11:10 PM

Ethereum Has Surpassed It’s Previous ATH Market Capitalization At $144B!
Ethereum - the largest smart contract platform in the world smashed a new record today by surpassing it's previous All Time High (ATH) market capitalization of $136B. The premier asset is currently trading in a range of $1250-$1270, which gives it a market capitalization of $144B. It's momentum appears intact and the previous ATH price record is also likely to be broken in the next couple of hour!
October 6, 2020 6:16 PM

How To Build A Passive Income With DeFi on EOS
The DeFi world is growing from day to day. Ethereum is the leading blockchain when it comes to the amount of developers, DApps, and users. But DeFI is also growing on other blockchains, which have the privilege of picking successful […]
August 4, 2020 11:32 PM

Top 5 DeFi Coins – DeFi Closes In On $4.5 Billion in TVL!
The relatively nascent, but incredibly growing and highly rewarding field of Decentralized Finance (DeFi) is currently closing in on $4.5B total value locked (TVL). At the time of this writing, the DeFi TVL has reached $4.27B and the biggest DeFi […]
July 23, 2020 9:31 AM

Argent v1 Smart Wallet – 1-Click Comprehensive DeFi On The Go
The Argent team announced the release of the first version of their crypto wallet with built-in comprehensive DeFi functionality on May 18. According to the release notes – “Argent is now the easiest way to access DeFi, starting with TokenSets, […]
February 2, 2020 12:01 AM

Future Best Investment Returns Will Be From Ethereum DApps: Burton
Richard Burton – designer of DeFi protocols and advisor for Zenith Ventures said in a tweet on Jan 30 that Ethereum was one of the best investments of the last decade and he believes that things built on Ethereum will […]
More from CryptoTicker

