Makina Finance suffers a $4.13 million exploit after its DUSD/USDC Curve pool is drained through an oracle manipulation attack.Makina Finance suffers a $4.13 million exploit after its DUSD/USDC Curve pool is drained through an oracle manipulation attack.

Makina suffers $4.13M exploit in DUSD/USDC Curve pool

4 min read

Makina, a decentralized finance protocol with automated execution, suffered an exploit early Tuesday morning that drained its DUSD/USDC liquidity pool on Curve, according to blockchain security firm PeckShield. 

Makina Finance has reportedly lost about 1,299 Ether from its Curve stablecoin pool to hackers. It was valued at about $4.13 million at the time. Per Peckshield’s analysis, attackers breached protocol’s non-custodial liquidity providers on the DUSD/USDC CurveStable pool, which uses an on-chain pricing data feed oracle. 

Oracles provide smart contracts with external information, such as asset prices, which the hackers exploited mid-transaction and withdrew the tokens at an artificially favorable rate.

Makina hacker used flash loans to snipe $5 million away

According to a security engineer at CertiK, the perpetrator began by borrowing 280 million USDC without upfront collateral, on the condition that the funds would be repaid in the same transaction.

Out of the borrowed amount, about 170 million USDC was used to interfere with the MachineShareOracle, which is responsible for reporting share prices to the pool. After injecting capital borrowed via a flash loan, they were able to temporarily skew the oracle’s price data and trick it into trusting inaccurate pricing information.

When the oracle began reporting inflated values, the attacker swapped approximately 110 million USDC against a pool that held only around $5 million in liquidity. Since the pool believed assets were worth more than they actually were, it paid out far more than it should have and emptied itself. 

“A share-price oracle was pushed mid-tx, letting a Curve pool pay out at an inflated rate. ~5.1M USDC left the DUSD/USDC pool, the attacker profits about 4.1M,” said the security engineer.

Makina Finance was launched last February, marketing itself as an institutional-grade DeFi execution engine. According to data from DeFiLlama, the protocol holds approximately $100.49 million in total value locked. 

MEV builder cut the Makina exploit numbers by $800k

The hacker took the DUSD proceeds and swapped them into ether, executing several transactions to consolidate and reposition the assets. However, according to CertiK, the exploit transaction was partially frontrun by an MEV builder. 

Maximal extractable value is the profit that either block builders and validators can maximize by reordering, injecting, and censoring transactions before being processed on-chain. In this case, an MEV entity identified by the address prefix 0xa6c2 racked up the majority of the value as the exploit played out. 

CertiK estimated that the MEV builder seized approximately $4.14 million out of the $5 million they had withdrawn from the stablecoin pool.

The MEV routing split the remaining ether between two addresses: the first (0xbed) held $3.3 million in ETH, and the other (0x573d) held roughly 276 ETH.

At around 6:42 AM UTC Tuesday, Makina Finance wrote a statement on X acknowledging the hack but insisted the issue did not affect the entire protocol’s infrastructure.

Makina also asked liquidity providers in the DUSD Curve pool to remove their liquidity as it determines “the appropriate next steps for affected users and LPs.” The team also promised to provide the community with more updates as soon as the incident review is complete.

The DeFi protocol’s flash loan attack spells doom for a year that crypto users had hoped to walk away from unscathed, after a dreadful 2025 that saw over $3 billion stolen from the market. 

A Web3 Security and Fraud Report from Cyvers documented 108 fraud and security-related incidents last year, and about $16 billion in crypto assets swindled from at least 140 exchanges and trading platforms.

Cyvers also reported more than 4.2 million fraudulent transactions from 780,000 addresses and nearly 19,000 active fraud networks, involving assets such as USDT, ETH, and USDC.

If you're reading this, you’re already ahead. Stay there with our newsletter.

Market Opportunity
4 Logo
4 Price(4)
$0.00938
$0.00938$0.00938
-4.67%
USD
4 (4) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

REX Shares’ Solana staking ETF sees $10M inflows, AUM tops $289M for first time

REX Shares’ Solana staking ETF sees $10M inflows, AUM tops $289M for first time

The post REX Shares’ Solana staking ETF sees $10M inflows, AUM tops $289M for first time appeared on BitcoinEthereumNews.com. Key Takeaways REX Shares’ Solana staking ETF saw $10 million in inflows in one day. Total inflows over the past three days amount to $23 million. REX Shares’ Solana staking ETF recorded $10 million in inflows yesterday, bringing total additions to $23 million over the past three days. The fund’s assets under management climbed above $289.0 million for the first time. The SSK ETF is the first U.S. exchange-traded fund focused on Solana staking. Source: https://cryptobriefing.com/rex-shares-solana-staking-etf-aum-289m/
Share
BitcoinEthereumNews2025/09/18 02:34
Verimatrix: Sale of Extended Threat Defense Assets (Mobile Application Protection) to Guardsquare

Verimatrix: Sale of Extended Threat Defense Assets (Mobile Application Protection) to Guardsquare

Completion of the sale of XTD assets (code and mobile application protection), including a portfolio of patents and a team of experts. The Group is refocusing on
Share
AI Journal2026/02/06 00:49
IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge!

IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge!

The post IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge! appeared on BitcoinEthereumNews.com. Crypto News 17 September 2025 | 18:00 Discover why BlockDAG’s upcoming Awakening Testnet launch makes it the best crypto to buy today as Story (IP) price jumps to $11.75 and Hyperliquid hits new highs. Recent crypto market numbers show strength but also some limits. The Story (IP) price jump has been sharp, fueled by big buybacks and speculation, yet critics point out that revenue still lags far behind its valuation. The Hyperliquid (HYPE) price looks solid around the mid-$50s after a new all-time high, but questions remain about sustainability once the hype around USDH proposals cools down. So the obvious question is: why chase coins that are either stretched thin or at risk of retracing when you could back a network that’s already proving itself on the ground? That’s where BlockDAG comes in. While other chains are stuck dealing with validator congestion or outages, BlockDAG’s upcoming Awakening Testnet will be stress-testing its EVM-compatible smart chain with real miners before listing. For anyone looking for the best crypto coin to buy, the choice between waiting on fixes or joining live progress feels like an easy one. BlockDAG: Smart Chain Running Before Launch Ethereum continues to wrestle with gas congestion, and Solana is still known for network freezes, yet BlockDAG is already showing a different picture. Its upcoming Awakening Testnet, set to launch on September 25, isn’t just a demo; it’s a live rollout where the chain’s base protocols are being stress-tested with miners connected globally. EVM compatibility is active, account abstraction is built in, and tools like updated vesting contracts and Stratum integration are already functional. Instead of waiting for fixes like other networks, BlockDAG is proving its infrastructure in real time. What makes this even more important is that the technology is operational before the coin even hits exchanges. That…
Share
BitcoinEthereumNews2025/09/18 00:32