Ajna v2 hack — August 2026
Incident facts
| Date of incident | |
|---|---|
| Target type | Lending protocol |
| Loss | $775,400Price at time of incident |
| Method | Contract logic errorLiquidation accounting was chained so that LP minted by a bucket take could be redeemed for collateral that the settlement path then treated as already accounted for |
| Chains | Ethereum |
| Outcome | Unresolved |
What happened
Ajna v2 lost about $775,400 across seven Ethereum pools between 28 and 29 August 2026. The protocol is deliberately immutable: no governance body, no upgrade path, no administrator key. That design removed the usual response. There was no pause button, so the team's only option was to ask users to withdraw their quote tokens, repay outstanding loans and stop interacting with the contract, which it did at 04:58 UTC on 29 August.
The attack was in the liquidation arithmetic, not in a price feed — notable for a protocol that runs without oracles at all. The chain combined a bucket take, which mints LP to the taker, a collateral removal against that freshly minted LP, and a settlement path that moves leftover collateral when the quote repaid is zero. Under particular conditions of the lowest utilised price and auction timing, the sequence closes without looking wrong to anything reading only swap and transfer events.
Attack contracts were deployed at about 15:16 UTC on 28 August and the first extraction landed on the cbETH pool roughly an hour later. Security firm Defimon published a pool-by-pool table at 09:29 UTC on 29 August: syrupUSDC $173.7k, wstETH $159.8k, rETH $143.0k over two transactions, cbETH $136.9k over two, WBTC $101.8k, WETH/USDC $42.0k and sDAI $18.0k. Defimon said its detection stack had flagged the prepared attack more than an hour before the first exploit transaction and that its notification to the team went unactioned.
Sources
- The Crypto TimesSecondary · retrieved 2026-08-31
- CryptopolitanSecondary · retrieved 2026-08-31
- CryptoTickerSecondary · retrieved 2026-08-31
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Ajna v2 hack — August 2026", iTokenly, accessed 2026-08-31, https://itokenly.com/hacks/ajna-v2-liquidationhttps://itokenly.com/hacks/ajna-v2-liquidationPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.