Logo
My Crypto News AI

Three DeFi Exploits in 48 Hours Expose a Deeper Problem: Even Oracle-Free Protocols Aren't Safe

Three separate decentralized finance (DeFi) exploits hit the blockchain ecosystem within 48 hours, draining nearly $10 million combined and exposing a troubling pattern: even protocols designed to avoid traditional price oracle vulnerabilities remain vulnerable to sophisticated attacks. The incidents suggest that as DeFi platforms become more complex, the attack surface shifts from obvious weak points to hidden assumptions buried deep inside lending logic and token contracts.

What Happened to Ajna Protocol's Oracle-Free Design?

Ajna Protocol, a lending platform that deliberately operates without external price feeds, lost approximately $775,000 in Ethereum (ETH) after an attacker exploited its internal liquidation accounting system. The attack targeted multiple liquidity pools, including syrupUSDC, wstETH, rETH, cbETH, WBTC, and WETH/USDC.

Ajna's core philosophy was to eliminate a major attack vector: oracle manipulation. Most lending protocols rely on external services like Chainlink to determine collateral prices. Ajna rejected this approach entirely. Instead, lenders deposit funds into fixed-rate "buckets," and the protocol's own smart contracts determine when liquidations occur. The whitepaper explicitly states the protocol "requires no governance or external price feeds to function".

The exploit revealed a critical flaw in this reasoning. Rather than attacking an external oracle, the attacker manipulated Ajna's internal liquidation accounting. Security firm Defimon detected the prepared attack more than one hour before the first exploit transaction and alerted Ajna through its Discord channel, but the team failed to respond in time.

"A significant portion of attacks on DeFi protocols stem from oracle prices manipulations, errors in configuration and access control issues," explained MixBytes, a security company, regarding Ajna's design rationale.

MixBytes, Security Firm

The largest single loss came from the syrupUSDC pool, which lost approximately $173,700 of the total $775,000. At the time of the attack, Ajna V2's total value locked (TVL), a measure of capital deposited in the protocol, stood at only about $206,000, meaning the exploit loss exceeded the entire protocol's TVL.

How Did Moonwell Lose $8.7 Million to Price Manipulation?

One day earlier, Moonwell, a decentralized lending protocol on the Base blockchain, suffered an $8.7 million exploit through a different but related mechanism: price manipulation of a low-liquidity collateral token. The attacker artificially inflated the price of MAMO, a relatively illiquid Base ecosystem token, to increase the collateral value Moonwell assigned to MAMO deposits.

By artificially boosting MAMO's quoted price, the attacker was able to borrow substantially more valuable assets, including Coinbase Wrapped Bitcoin (cbBTC), USDC, wrapped staked Ether, and ETH, than the collateral could realistically support. Blockchain security firms PeckShield and CertiK both estimated the loss at approximately $8.7 million. The stolen value was eventually consolidated into DAI, a stablecoin, at an attacker-controlled address.

Moonwell responded by sharply restricting its Base lending markets. The protocol reduced borrow caps for all Base Core Markets to 1 wei, effectively preventing users from initiating additional borrowing. Supply caps for MAMO and Moonwell's WELL governance token were also reduced to 1 wei.

This was not Moonwell's first pricing-related incident. A November 2025 oracle issue involving wrsETH generated approximately $3.7 million in bad debt, while a February 2026 cbETH pricing error produced another approximately $1.78 million in losses. The February incident resulted from an incorrect scaling calculation that caused cbETH, then worth around $2,200, to be valued at approximately $1.12.

What Went Wrong With the CCC Token on Binance Smart Chain?

On the same day as the Moonwell exploit, security firm TenArmorAlert detected a $117,000 drain from a CCC token liquidity pool on Binance Smart Chain (BSC). The attacker exploited a flaw in the token contract's sell() function to burn CCC tokens held directly in the liquidity pool, rather than withdrawing assets outright.

This attack method was subtler than a straightforward drain. By burning tokens inside the pool, the attacker distorted the price ratio the pool relies on to value the token. The burn triggered abnormal price movement in CCC but left the pool structurally intact, making the attack harder to detect in real time.

TenArmorAlert identified the affected function but did not disclose the complete attack sequence or explain how the attacker gained the ability to trigger the sell() function. Critical questions remain unanswered: whether access controls were bypassed, whether the exploit required interaction with another contract, or whether the vulnerability stemmed from a permission flaw in the code itself.

As of the alert's publication, the CCC team had not announced a recovery plan, fund restitution, or compensation for affected liquidity providers. No confirmation emerged regarding whether the contract was paused or whether permissions were altered.

Why Are DeFi Protocols Still Getting Hacked Despite Security Audits?

The three exploits reveal a pattern that extends beyond individual protocol failures. Each attack exploited a different technical angle, yet all three succeeded despite the protocols' stated security measures. The common thread is that vulnerabilities often hide inside the assumptions protocols make about how their own code will behave.

Ajna's loss illustrates this principle directly. The protocol eliminated external oracle risk but still required its contracts to trust their own liquidation calculations. Moonwell accepted thinly traded tokens as collateral, assuming external price feeds would accurately reflect their value. CCC's token contract contained a sell() function that could be weaponized against the liquidity pool it was designed to support.

The broader context makes these incidents more concerning. Blockchain security firm TRM Labs counted 207 hacks in the first half of 2026, the highest number recorded in a six-month period, with the typical incident costing about $219,000. More than 100 involved smaller smart-contract exploits. Infrastructure and operational compromises represented only about 15% of incidents but accounted for roughly 76% of total losses.

How to Assess DeFi Protocol Risk Before Depositing Funds

  • Collateral Quality: Check whether the protocol accepts low-liquidity tokens as collateral. Thinly traded tokens are easier to manipulate in price, even if external price feeds are used. Moonwell's MAMO exploit demonstrates how limited liquidity can enable artificial price inflation.
  • Liquidation Mechanics: Understand how the protocol determines when a loan becomes unsafe and how it calculates collateral value during liquidation. Ajna's exploit targeted internal liquidation accounting, suggesting that even oracle-free designs require scrutiny of how liquidations are priced and executed.
  • Incident History: Research whether the protocol has suffered previous pricing-related losses or oracle failures. Moonwell's three significant pricing incidents since November 2025 indicate a pattern of collateral valuation problems that may not be fully resolved.
  • Response Time: Assess how quickly the protocol team responds to security alerts. Defimon detected Ajna's attack more than one hour before it occurred and notified the team, but the protocol failed to pause or secure itself in time.
  • Recovery Transparency: Look for clear communication about losses, bad debt, and recovery plans. The CCC exploit resulted in no announced recovery plan or compensation, leaving liquidity providers without clarity on their exposure.

The August 2026 exploit surge highlights that lending-protocol security depends not only on secure smart-contract code but also on whether the prices used to value collateral can withstand deliberate market manipulation and whether the protocol's internal accounting logic can resist creative exploitation.

For liquidity providers and borrowers, the lesson is clear: no protocol design, no matter how innovative, eliminates all attack vectors. The shift from oracle manipulation to internal accounting manipulation to token contract flaws suggests that attackers are becoming more sophisticated at finding hidden assumptions in increasingly complex DeFi systems.