On January 20, 2026, the Makina DeFi protocol — an execution engine for on-chain yield and asset management — suffered a ~$4 million exploit targeting its DialecticOn January 20, 2026, the Makina DeFi protocol — an execution engine for on-chain yield and asset management — suffered a ~$4 million exploit targeting its Dialectic

Makina’s $4M Hack due to Oracle Manipulation

2026/01/24 19:49
3 min read

On January 20, 2026, the Makina DeFi protocol — an execution engine for on-chain yield and asset management — suffered a ~$4 million exploit targeting its Dialectic USD (DUSD)/USDC Curve stableswap pool. The attack stemmed from oracle manipulation via external Curve Finance integrations, where unvalidated pool data was used to calculate assets under management (AUM) and sharePrice.

By leveraging flash loans, the attacker artificially inflated AUM values, manipulated sharePrice calculations, and extracted profit in a single transaction. While the exploit impacted only the DUSD/USDC pool, it highlighted a broader and recurring DeFi risk: over-reliance on external liquidity data without adequate safeguards.

How the Exploit Worked?

The attacker executed a carefully orchestrated multi-step attack using large flash loans sourced from Morpho and Aave V2. These borrowed funds were temporarily injected into multiple Curve pools to distort liquidity balances and pricing assumptions.

First, the attacker added liquidity to Makina’s DUSD/USDC pool and swapped USDC for DUSD, positioning themselves to benefit from price manipulation. They then added substantial liquidity to Curve’s DAI/USDC/USDT and MIM-related pools, receiving LP tokens that were later partially withdrawn to skew pool balances.

These manipulated balances were critical. Makina’s Caliber contract relied on external Curve functions — such as calc_withdraw_one_coin() and pool balance readings—to compute positional AUM. With liquidity temporarily inflated, these calculations produced artificially high values.

Once the attacker called accountForPosition(), the inflated external data propagated through Makina’s accounting system. The protocol’s total AUM jumped significantly, pushing the sharePrice from ~1.01 to ~1.33 within the same transaction.

With the sharePrice distorted, the attacker arbitraged the DUSD/USDC pool, withdrew liquidity, and repeated the cycle until the pool’s USDC reserves were largely drained. After unwinding the flash loans, the attacker converted the stolen funds to ETH and transferred ~1,299 ETH to external addresses.

Notably, part of the transaction was front-run by an MEV bot, which captured a portion of the profit — further illustrating how composability amplifies loss surfaces during exploits.

Root Cause: Unchecked External Data

At its core, the vulnerability lay in Makina’s trust assumptions. External pool data was treated as reliable input for critical accounting logic, without sufficient sanity checks, rate limits, or flash-loan resistance. The use of upgradeable contracts and the absence of time-weighted or delayed AUM calculations compounded the issue.

This exploit reinforces a key DeFi lesson: external data should inform systems — not directly dictate their financial state.

Notably, many of the largest DeFi exploits in 2025 followed similar patterns, where untrusted external data and integration assumptions were repeatedly abused at scale. These recurring failure modes are analyzed in depth in our Web3 2025 Hack Report, which examines how such vulnerabilities continue to dominate real-world attacks.

Want the Full Technical Breakdown?

Aftermath and Response

Following the attack, Makina paused protocol operations, advised LPs on withdrawal options, and coordinated with multiple security firms for investigation and recovery. A 10% whitehat bounty was offered to the exploiter, though no funds had been returned at the time of writing.


Makina’s $4M Hack due to Oracle Manipulation was originally published in Coinmonks on Medium, where people are continuing the conversation by highlighting and responding to this story.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Cashing In On University Patents Means Giving Up On Our Innovation Future

Cashing In On University Patents Means Giving Up On Our Innovation Future

The post Cashing In On University Patents Means Giving Up On Our Innovation Future appeared on BitcoinEthereumNews.com. “It’s a raid on American innovation that would deliver pennies to the Treasury while kneecapping the very engine of our economic and medical progress,” writes Pipes. Getty Images Washington is addicted to taxing success. Now, Commerce Secretary Howard Lutnick is floating a plan to skim half the patent earnings from inventions developed at universities with federal funding. It’s being sold as a way to shore up programs like Social Security. In reality, it’s a raid on American innovation that would deliver pennies to the Treasury while kneecapping the very engine of our economic and medical progress. Yes, taxpayer dollars support early-stage research. But the real payoff comes later—in the jobs created, cures discovered, and industries launched when universities and private industry turn those discoveries into real products. By comparison, the sums at stake in patent licensing are trivial. Universities collectively earn only about $3.6 billion annually in patent income—less than the federal government spends on Social Security in a single day. Even confiscating half would barely register against a $6 trillion federal budget. And yet the damage from such a policy would be anything but trivial. The true return on taxpayer investment isn’t in licensing checks sent to Washington, but in the downstream economic activity that federally supported research unleashes. Thanks to the bipartisan Bayh-Dole Act of 1980, universities and private industry have powerful incentives to translate early-stage discoveries into real-world products. Before Bayh-Dole, the government hoarded patents from federally funded research, and fewer than 5% were ever licensed. Once universities could own and license their own inventions, innovation exploded. The result has been one of the best returns on investment in government history. Since 1996, university research has added nearly $2 trillion to U.S. industrial output, supported 6.5 million jobs, and launched more than 19,000 startups. Those companies pay…
Share
BitcoinEthereumNews2025/09/18 03:26
VectorUSA Achieves Fortinet’s Engage Preferred Services Partner Designation

VectorUSA Achieves Fortinet’s Engage Preferred Services Partner Designation

TORRANCE, Calif., Feb. 3, 2026 /PRNewswire/ — VectorUSA, a trusted technology solutions provider, specializes in delivering integrated IT, security, and infrastructure
Share
AI Journal2026/02/05 00:02
Top Solana Treasury Firm Forward Industries Unveils $4 Billion Capital Raise To Buy More SOL ⋆ ZyCrypto

Top Solana Treasury Firm Forward Industries Unveils $4 Billion Capital Raise To Buy More SOL ⋆ ZyCrypto

The post Top Solana Treasury Firm Forward Industries Unveils $4 Billion Capital Raise To Buy More SOL ⋆ ZyCrypto appeared on BitcoinEthereumNews.com. Advertisement &nbsp &nbsp Forward Industries, the largest publicly traded Solana treasury company, has filed a $4 billion at-the-market (ATM) equity offering program with the U.S. SEC  to raise more capital for additional SOL accumulation. Forward Strategies Doubles Down On Solana Strategy In a Wednesday press release, Forward Industries revealed that the 4 billion ATM equity offering program will allow the company to issue and sell common stock via Cantor Fitzgerald under a sales agreement dated Sept. 16, 2025. Forward said proceeds will go toward “general corporate purposes,” including the pursuit of its Solana balance sheet and purchases of income-generating assets. The sales of the shares are covered by an automatic shelf registration statement filed with the US Securities and Exchange Commission that is already effective – meaning the shares will be tradable once they’re sold. An automatic shelf registration allows certain publicly listed companies to raise capital with flexibility swiftly.  Kyle Samani, Forward’s chairman, astutely described the ATM offering as “a flexible and efficient mechanism” to raise and deploy capital for the company’s Solana strategy and bolster its balance sheet.  Advertisement &nbsp Though the maximum amount is listed as $4 billion, the firm indicated that sales may or may not occur depending on existing market conditions. “The ATM Program enhances our ability to continue scaling that position, strengthen our balance sheet, and pursue growth initiatives in alignment with our long-term vision,” Samani said. Forward Industries kicked off its Solana treasury strategy on Sept. 8. The Wednesday S-3 form follows Forward’s $1.65 billion private investment in public equity that closed last week, led by crypto heavyweights like Galaxy Digital, Jump Crypto, and Multicoin Capital. The company started deploying that capital this week, announcing it snatched up 6.8 million SOL for approximately $1.58 billion at an average price of $232…
Share
BitcoinEthereumNews2025/09/18 03:42