Ajna.finance exploited for $775K via liquidation accounting manipulation; attackers bypassed early warnings despite Defimon alerting the team an hour before the first tx.
Security & Exploits ·
Ajna.finance suffered a loss of approximately $775,000 following an exploit that manipulated liquidation accounting on Ethereum. The attack affected multiple asset pools, including syrupUSDC ($173.7K), wstETH ($159.8K), rETH ($127.4K and $15.6K across separate instances), cbETH ($124.8K and $12.1K), WBTC ($101.8K), WETH/USDC ($42.0K), and sDAI ($18.0K). According to Ajna's announcement, the protocol advised immediate withdrawal of all user funds.
The vulnerability centered on how the protocol calculated liquidation mechanics. Defimon's monitoring systems identified a prepared attack more than an hour before the first transaction executed and notified Ajna's team through Discord, but the protocol did not take preventive action before the exploit proceeded. Multiple addresses participated in the attack, as evidenced by on-chain activity.
The incident highlights a gap between early warning detection and incident response timing. While the specific technical details of how the liquidation accounting was manipulated remain a subject for deeper analysis, the fact that an advance alert failed to prevent the loss raises questions about coordination protocols and incident response procedures among lending platforms and their security monitoring partners.