Skip to content
LIVE
Loading prices...
DeFi Disaster: $5M Drained in Oracle Nightmare

DeFi Disaster: $5M Drained in Oracle Nightmare

DeFi Disaster: $5M Drained in Oracle Nightmare

Makina Finance fell victim to a $5 million flash loan attack on January 20, 2026, draining its DUSD/USDC stablecoin pool via oracle manipulation. 

Ad

As it happens, CertiK and security firms flagged the exploit, with the attacker netting $4.14 million routed to an MEV builder. As decentralized finance (DeFi) inflows surge, this breach raises alarms over protocol vulnerabilities and user fund safety.

Security alerts from CertiK, TenArmor, and other platforms revealed the attack on Makina Finance on the Ethereum blockchain. The transaction, executed at 03:40 UTC, involved a flash loan of 280 million USDC. As CertiK explained:

The exploiter used 170 million USDC to manipulate the MachineShareOracle, inflating the prices in the DUSD/USDC Curve pool. Then, 110 million USDC was swapped to drain the pool of around $5 million, profiting from the discrepancy.

Internal traces show multiple add/remove liquidity calls on Curve and Aave, with USDC approvals and token exchanges across pools like DAI/USDC/USDT and MIM-3LP3CRV-f. Funds were converted to 1,299 ETH (~$4.13–$5.1 million) and sent to MEV builder 0xa6c2…387.

Ad

Makina confirmed the issue affects only DUSD LP positions on Curve, advising withdrawals. No other deployments impacted, per the statement.

Why This DeFi Hack Signals Bigger Risks Ahead

The exploit underscores oracle manipulation as the top DeFi threat, enabling flash loans to exploit pricing flaws without collateral. Losses hit $5 million, but the attacker’s profit was around $4.1 million after fees.

Meanwhile, DeFi hacks persist into 2026, with legacy platforms losing $27 million recently. Makina’s permissionless AUM refresh allowed mid-tx oracle tweaks, a design flaw.

For users, revoke approvals and avoid affected contracts. Protocols must audit oracles rigorously, and Chainlink or multi-source could mitigate. Amid $2.17 billion weekly inflows, such events could erode trust but highlight maturation needs.

More Must-Reads:

How do you rate this article?

Join our Socials

Briefly, clearly and without noise – get the most important crypto news and market insights first.