Ajna Exploit Drains $775,400 From Seven DeFi Pools
Ajna reported that its Ajna v2 protocol suffered a liquidation-accounting manipulation attack, with estimated losses initially reported at about $775,000 and later estimated at roughly $775,400. The attack drained seven Ethereum-based lending pools between August 28 and 29, 2026: syrupUSDC, wstETH, rETH, cbETH, WBTC, WETH/USDC and sDAI.
Security analysts said the Ajna exploit manipulated liquidation and residual-balance calculations rather than relying on an oracle failure or stolen private keys. The attacker repeatedly triggered liquidations and extracted excess value from multiple pools. Ajna’s total value locked fell to about $246,880, down 71.3% over 30 days.
Ajna urged users to withdraw all quote tokens, repay outstanding loans and stop interacting with the protocol. Because Ajna v2 is immutable and lacks governance, an upgrade mechanism and an emergency pause function, developers cannot patch or halt the contracts. Users must exit independently. The incident shows that audits do not eliminate smart-contract risk.
The Ajna exploit is bearish for exposed lenders, borrowers and the AJNA ecosystem. Traders should monitor further withdrawals, pool liquidity, debt repayment and possible contagion across related DeFi lending markets. The event may also increase caution toward immutable protocols and highlight the importance of liquidation logic, upgrade authority, pause controls and real-time monitoring.
Bearish
The incident is directly negative for Ajna and its associated AJNA ecosystem because users were advised to withdraw funds and repay loans, while the protocol cannot pause or upgrade its immutable contracts. In the short term, forced withdrawals, reduced liquidity and continued deleveraging can increase selling pressure and weaken confidence in the project. Traders may also avoid related lending pools until the investigation and fund-recovery process becomes clearer.
The broader effect on major assets such as ETH, BTC and stablecoins is likely to be limited because the reported losses are small relative to their total markets. However, the exploit could create wider caution toward immutable DeFi lending protocols and liquidation-based systems. Long-term sentiment will depend on whether Ajna identifies the full attack path, recovers funds and demonstrates safeguards for similar accounting vulnerabilities. Until then, the risk-reward profile remains negative for direct exposure.