On January 20, 2026, the Makina DeFi protocol — an execution engine for on-chain yield and asset management — suffered a ~$4 million exploit targeting its DialecticOn January 20, 2026, the Makina DeFi protocol — an execution engine for on-chain yield and asset management — suffered a ~$4 million exploit targeting its Dialectic

Makina’s $4M Hack due to Oracle Manipulation

2026/01/24 19:49
3 min read

On January 20, 2026, the Makina DeFi protocol — an execution engine for on-chain yield and asset management — suffered a ~$4 million exploit targeting its Dialectic USD (DUSD)/USDC Curve stableswap pool. The attack stemmed from oracle manipulation via external Curve Finance integrations, where unvalidated pool data was used to calculate assets under management (AUM) and sharePrice.

By leveraging flash loans, the attacker artificially inflated AUM values, manipulated sharePrice calculations, and extracted profit in a single transaction. While the exploit impacted only the DUSD/USDC pool, it highlighted a broader and recurring DeFi risk: over-reliance on external liquidity data without adequate safeguards.

How the Exploit Worked?

The attacker executed a carefully orchestrated multi-step attack using large flash loans sourced from Morpho and Aave V2. These borrowed funds were temporarily injected into multiple Curve pools to distort liquidity balances and pricing assumptions.

First, the attacker added liquidity to Makina’s DUSD/USDC pool and swapped USDC for DUSD, positioning themselves to benefit from price manipulation. They then added substantial liquidity to Curve’s DAI/USDC/USDT and MIM-related pools, receiving LP tokens that were later partially withdrawn to skew pool balances.

These manipulated balances were critical. Makina’s Caliber contract relied on external Curve functions — such as calc_withdraw_one_coin() and pool balance readings—to compute positional AUM. With liquidity temporarily inflated, these calculations produced artificially high values.

Once the attacker called accountForPosition(), the inflated external data propagated through Makina’s accounting system. The protocol’s total AUM jumped significantly, pushing the sharePrice from ~1.01 to ~1.33 within the same transaction.

With the sharePrice distorted, the attacker arbitraged the DUSD/USDC pool, withdrew liquidity, and repeated the cycle until the pool’s USDC reserves were largely drained. After unwinding the flash loans, the attacker converted the stolen funds to ETH and transferred ~1,299 ETH to external addresses.

Notably, part of the transaction was front-run by an MEV bot, which captured a portion of the profit — further illustrating how composability amplifies loss surfaces during exploits.

Root Cause: Unchecked External Data

At its core, the vulnerability lay in Makina’s trust assumptions. External pool data was treated as reliable input for critical accounting logic, without sufficient sanity checks, rate limits, or flash-loan resistance. The use of upgradeable contracts and the absence of time-weighted or delayed AUM calculations compounded the issue.

This exploit reinforces a key DeFi lesson: external data should inform systems — not directly dictate their financial state.

Notably, many of the largest DeFi exploits in 2025 followed similar patterns, where untrusted external data and integration assumptions were repeatedly abused at scale. These recurring failure modes are analyzed in depth in our Web3 2025 Hack Report, which examines how such vulnerabilities continue to dominate real-world attacks.

Want the Full Technical Breakdown?

Aftermath and Response

Following the attack, Makina paused protocol operations, advised LPs on withdrawal options, and coordinated with multiple security firms for investigation and recovery. A 10% whitehat bounty was offered to the exploiter, though no funds had been returned at the time of writing.


Makina’s $4M Hack due to Oracle Manipulation was originally published in Coinmonks on Medium, where people are continuing the conversation by highlighting and responding to this story.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Horror Thriller ‘Bring Her Back’ Gets HBO Max Premiere Date

Horror Thriller ‘Bring Her Back’ Gets HBO Max Premiere Date

The post Horror Thriller ‘Bring Her Back’ Gets HBO Max Premiere Date appeared on BitcoinEthereumNews.com. Jonah Wren Phillips in “Bring Her Back.” A24 Bring Her Back, a new A24 horror movie from the filmmakers of the smash hit Talk to Me, is coming soon to HBO Max. Bring Her Back opened in theaters on May 30 before debuting on digital streaming via premium video on demand on July 1. The official logline for Bring Her Back reads, “A brother and sister uncover a terrifying ritual at the secluded home of their new foster mother.” Forbes‘South Park’ Season 27 Updated Release Schedule: When Do New Episodes Come Out?By Tim Lammers Directed by twin brothers Danny Philippou and Michael Philippou, Bring Her Back stars Billy Barratt, Sora Wong, Jonah Wren Philips, Sally–Anne Upton, Stephen Philips, Mischa Heywood and Sally Hawkins. Warner Bros. Discovery announced on Wednesday that Bring Her Back will arrive on streaming on HBO Max on Friday, Oct. 3, and on HBO linear on Saturday, Oct. 4, at 8 p.m. ET. Prior to the debut of Bring Her Back on HBO on Oct. 4, the cable outlet will air the Philippou brothers’ 2022 horror hit Talk to Me. ForbesHit Horror Thriller ’28 Years Later’ Is New On Netflix This WeekBy Tim Lammers For viewers who don’t have HBO Max, the streaming platform offers three tiers: The ad-based tier costs $9.99 per month, while an ad-free tier is $16.99 per month. Additionally, an ad-free tier with 4K Ultra HD programming costs $20.99 per month. The Success Of ‘Talk To Me’ Weighed On The Minds Of Philippou Brothers While Making ‘Bring Her Back’ During the film’s theatrical run, Bring Her Back earned $19.3 million domestically and nearly $19.8 million internationally for a worldwide box office tally of $39.1 million. Bring Her Back had a production budget of $17 million before prints and advertising, according to The Numbers.…
Share
BitcoinEthereumNews2025/09/18 09:23
TRM Labs Becomes Unicorn with 70M$: BTC Fraud Risk

TRM Labs Becomes Unicorn with 70M$: BTC Fraud Risk

The post TRM Labs Becomes Unicorn with 70M$: BTC Fraud Risk appeared on BitcoinEthereumNews.com. TRM Labs Reaches 1 Billion Dollar Valuation Blockchain intelligence
Share
BitcoinEthereumNews2026/02/05 03:33
XRP Plunges: Historic MACD Signal Sparks Alarm

XRP Plunges: Historic MACD Signal Sparks Alarm

This week, XRP depreciated by 17.94 per cent with a historic MACD indicator sitting on the market; the traders are keeping a keen eye on the support mark of 1.30
Share
LiveBitcoinNews2026/02/05 03:30