-
Makina Finance suffered a suspected $5 million exploit
-
Attack used a 280 million USDC flash loan
-
Oracle manipulation drained a stablecoin pool
-
Team has not yet formally confirmed losses
Decentralized finance protocol Makina Finance has suffered a suspected smart contract exploit that drained roughly $5 million from one of its stablecoin pools, according to blockchain security firm CertiK.
The attacker reportedly used a 280 million USDC flash loan to manipulate an oracle tied to Makina’s DUSD/USDC Curve pool. By distorting price data, the exploiter was able to drain the pool’s assets in a single transaction sequence.
Security firms provided slightly different estimates of the damage, ranging from about $4.1 million to $5.1 million. CertiK reported that an MEV builder captured most of the stolen funds, seizing over $4 million during the exploit process.
Makina Finance, which launched in early 2025 and manages institutional-style strategy vaults, has not formally confirmed the exploit. In community messages, the team acknowledged reports of an incident and advised liquidity providers to withdraw funds from affected positions, but stopped short of confirming losses.
The incident adds to a growing list of DeFi exploits tied to oracle manipulation and flash loans. According to Chainalysis, total crypto theft exceeded $3.4 billion in 2025, highlighting ongoing security risks in decentralized finance.