Logo Daily Crypto Briefs
Open menu

Ajna v2 Users Told to Exit After $775K Liquidation Exploit

6 min read
Breaking News
Large official AJNA eye-and-wordmark logo on a black sign beside a greyscale unbranded open lending vault with a liquidation gauge and emergency lever on lavender and fuchsia editorial panels.

TL;DR

  • Ajna told v2 users to withdraw quote tokens, repay loans and stop interacting with the protocol after it identified abnormal fund flows.
  • DefiLlama records a $775,400 loss from seven Ethereum pools on Aug. 28 and classifies the incident as a protocol-logic liquidation flaw.
  • The protocol's immutable design means no administrator can pause or upgrade the affected contracts; the public exit notice is the immediate containment measure.
  • Ajna had not published a final post-mortem, affected-wallet count, recovery plan or confirmed attacker identity as of Aug. 30.

CASABLANCA, August 30, 2026

Ajna told users of its v2 lending protocol to withdraw funds, repay loans and stop interacting with the system after identifying abnormal fund flows, while DefiLlama recorded a $775,400 loss from seven Ethereum pools in what it classifies as a liquidation-logic flaw.

The unusual part is the response available to users. Ajna describes its protocol as permissionless and without governance; public reporting says v2 is immutable, so there is no administrator switch to pause the affected contracts or deploy a live fix. The exit notice is therefore the immediate containment step, not simply a general security precaution.

The DefiLlama incident record lists Aug. 28 as the date of the event, labels it “Protocol Logic” and “Liquidation Logic Flaw,” and puts the amount at $775,400. That is the best-supported public loss figure as of Aug. 30; it is not a final accounting from Ajna, a confirmed recovery amount or proof of the attacker’s realised proceeds.

Crypto Times’ incident report says the activity reached pools involving syrupUSDC, wstETH, rETH, cbETH, WBTC, WETH/USDC and sDAI. It attributes the estimate to monitoring firm Defimon. Ajna had not published a technical post-mortem, a count of affected wallets, attacker identities, transaction hashes, a recovery plan or a statement of which remaining pools are safe to use when this report was prepared.

That disclosure gap matters. Users should not read an estimated loss total as a complete map of individual balances, liquidity or recoverability. It also distinguishes this incident from Moonwell’s Base lending-market restriction, where the protocol could impose new borrowing caps while it investigated an oracle-linked event.

Ether

ETH
Aug. 1 to Aug. 30, 2026
$2,467
+33.8%
Aug 1 - Aug 30 | High $2,467 Low $1,845

Ajna v2 Exit Notice Follows Seven-Pool Drain

Ajna’s public-facing materials characterize the protocol as a peer-to-peer, non-custodial lending system that operates without external price feeds. That architecture is relevant to the reported attack: the public accounts point to the protocol’s own liquidation and accounting path, rather than a compromised wallet, a stolen key or a manipulated external price feed.

Ajna’s official reference materials define a quote token as the ERC-20 asset lenders deposit into price buckets. The reported user instruction to withdraw quote tokens and repay loans is specific to that design. It does not establish that every user has the same balance status or that every withdrawal will complete, so lenders and borrowers need to check the live interface and official project channels before signing a transaction.

The loss-impact review found no public evidence, as of this article’s 22:10 Casablanca-time review, of a larger confirmed theft, a separate wave of attacks, an affected-wallet total, recovered assets or an official final incident report. DefiLlama says Ajna’s tracked total value locked was about $232,779 and down 73% over 30 days, but that dashboard statistic should not be treated as a substitute for a forensic balance sheet.

The episode illustrates a harder trade-off in immutable lending software. Immutability can eliminate discretionary upgrade control, but it can also remove the fast containment tool users may expect after an exploit. Recent Cosmos EVM losses across six chains involved a different shared-software issue; both cases, however, show why public scope and remediation details matter as much as a headline loss number.

Liquidation Logic, Not an Oracle or Wallet Breach

The available reports describe a liquidation-accounting manipulation. Ajna’s system uses price buckets and internal liquidation mechanics instead of a conventional outside oracle. Reporting on a cbETH pool transaction said an attacker combined the protocol’s liquidation functions with flash-loaned assets and extracted collateral while paying comparatively little quote token, but Ajna has not independently confirmed that reconstruction.

That distinction should remain precise. There is no public basis yet to say that Ethereum itself was compromised, that user seed phrases were exposed, or that the event was caused by a general failure of every oracle-free lending model. There is also no basis to say the listed $775,400 has been fully recovered or that losses have stopped permanently.

The first practical checkpoint is Ajna’s own post-mortem: it would need to establish the vulnerable condition, the complete transaction set, user effects and whether any alternative interface or migration route is available. Until then, the protocol’s exposure notice and the independent incident ledger are more informative than an unverified claim that the contracts have been repaired.

For a broader risk comparison, the difference between a smart-contract exploit and a platform operational response is also visible in the MANTRA incident post-mortem, which later documented its transaction trail and containment details. Ajna had not done so by publication.

No Recovery or Patch Timeline Is Public Yet

Ajna’s brand and product site emphasize that the protocol has no governance and no price feeds. Those are design characteristics, not a post-exploit assurance. The project has not disclosed a contract-level pause, replacement deployment, reimbursement program, recovery agreement or target date for a technical update.

The projected reader action is narrow: the project’s reported notice says users should exit, repay and cease interaction; users should verify any subsequent instructions through Ajna’s official channels and treat unsolicited links or transaction requests as potential phishing. A security alert is not a reason to rush into an unverified workaround.

Ether traded near $2,467.30 at the Aug. 30 public market-data reading, versus a $1,844.61 close on Aug. 1, according to CoinGecko’s historical page. The market move does not determine the exploit total, but it affects the dollar value assigned to Ether-based collateral and any eventual recovery.

Broader crypto sentiment remained in Greed territory. Alternative.me’s Crypto Fear and Greed Index read 69 on Aug. 30, after a 68 reading the prior day. That market-wide gauge does not measure Ajna’s condition or resolve the outstanding user-fund questions.

Fear & Greed Index

Aug. 30, 2026
69 Greed

Ajna’s estimated $775,400 drain is small beside the year’s largest exploits, but the user impact is immediate because the protocol’s reported containment method is exit rather than a central pause. The next facts worth watching are a project post-mortem, on-chain loss reconciliation, affected-wallet and pool details, and evidence of any recovery or safer migration path.

Stay up to date

Get the latest crypto insights delivered to your inbox

Fact-checked by: Daily Crypto Briefs Fact-Check Desk

Frequently Asked Questions

What happened in the Ajna v2 exploit?

Ajna said it was investigating abnormal fund flows and told v2 users to withdraw funds, repay loans and stop interacting with the protocol. DefiLlama records the Aug. 28 event as a $775,400 protocol-logic incident involving a liquidation-logic flaw on Ethereum.

How much was lost in the Ajna v2 exploit?

DefiLlama's incident record lists $775,400. That is the best public loss estimate reviewed as of Aug. 30, 2026, not a final accounting from Ajna or a confirmed recovery amount.

Which Ajna v2 pools were affected?

Public incident reporting identified pools involving syrupUSDC, wstETH, rETH, cbETH, WBTC, WETH/USDC and sDAI. Ajna had not published a full pool-by-pool post-mortem as of Aug. 30.

Can Ajna v2 be paused or patched after the exploit?

Ajna describes its lending protocol as permissionless and without governance or external price feeds. Public reporting says v2 is immutable and lacks an administrator pause or upgrade path, so the team's immediate containment direction was for users to exit rather than a contract-level halt.