T
iTokenly

Makina Finance hack — January 2026

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJanuary 20, 2026
Target typeOther
Loss$4,130,000Price at time of incident
MethodOracle or price manipulationFlash-loan-driven manipulation of an internal assets-under-management calculation. Makina valued a Curve MIM-3CRV position via calc_withdraw_one_coin(); the attacker borrowed ~280 million USDC from Morpho and Aave and skewed the Curve pool balances so that call returned an inflated 3CRV amount. The inflated value propagated from position value to Caliber AUM to Machine AUM to the synchronous share-price oracle used by the DUSD/USDC Curve pool, which relays the exchange rate atomically with no time-weighting. The attacker bought DUSD at fair value, triggered the inflation, sold back at the inflated rate, and repeated the cycle before repaying the flash loans.
ChainsEthereum
OutcomeUsers reimbursed

What happened

On 20 January 2026 at 03:40:35 UTC, in Ethereum block 24273362, Makina Finance lost 1,299.17 ETH, valued by CertiK and Verichains at about $4.13 million, to an oracle manipulation attack.

Makina's Machine vaults price their shares from an internally computed assets-under-management figure. One input was a Curve MIM-3CRV position valued through calc_withdraw_one_coin(). The attacker borrowed roughly 280 million USDC — about 160.6 million from Morpho and 119.4 million from Aave, per CertiK — moved the Curve pool balances so that call returned an inflated number, and that value propagated up the chain: position value to Caliber AUM to Machine AUM to the synchronous oracle used by the DUSD/USDC Curve pool, which relays the exchange rate atomically with no time-weighting. The attacker bought DUSD at the fair rate, triggered the inflation, sold back at the inflated rate, repeated the cycle and drained the pool's USDC before repaying the flash loans.

The exploit contract was deployed by one party but the profit went to another. Makina's post-mortem states the original attacker was front-run by an MEV searcher, whose transaction paid almost all of the proceeds — 1,299.04 ETH — onward, of which about 1,023 ETH reached the block builder and 276.32 ETH the Rocket Pool block proposer, leaving the searcher 0.13 ETH. That routing is why most of the money came back. Within a week roughly 1,077.8 ETH was recovered through negotiation and white-hat agreements, including 920.7 ETH returned by the builder, which kept a 10% bounty, and 157.1 ETH from the Rocket Pool validator; further USDC was returned separately.

Makina began refunding affected liquidity providers on 23 January 2026 and shipped permissioned accounting and exchange-rate guards in version 1.1.

Sources

  1. MakinaPrimary · retrieved 2026-08-01
  2. CertiKSecondary · retrieved 2026-08-01
  3. VerichainsSecondary · retrieved 2026-08-01

Official post-mortem: https://makinafi.substack.com/p/post-mortem-january-20th-2026-incident

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Makina Finance hack — January 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/makina-finance
https://itokenly.com/hacks/makina-finance

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.