Makina Finance Hit by Flash Loan Exploit as Roughly $5 Million Leaves Stablecoin Pool

Makina Finance Hit by Flash Loan Exploit as Roughly $5 Million Leaves Stablecoin Pool

N
News Editor 01
2026-07-22 23:10:14
Makina Finance suffered a smart-contract exploit tied to oracle manipulation and a flash loan. CertiK said roughly $5 million was drained from a DUSD/USDC Curve pool, while about $4.14 million was captured by MEV infrastructure during the transactions.
Makina Financeflash loan exploitDeFi securityoracle manipulationCurve

Makina Finance has been hit by a smart-contract security breach that drained about $5 million from one of its stablecoin pools. CertiK said the exploit relied on a large flash loan to distort the protocol’s pricing oracle before assets were pulled from the pool.

A 280 million USDC flash loan drove the exploit

CertiK said the attacker targeted Makina Finance’s DUSD/USDC Curve stablecoin pool. The sequence began with a 280 million USDC flash loan. Of that amount, around 170 million USDC was used to create a temporary imbalance in MachineShareOracle, the oracle tied to the pool’s pricing. After that distortion, the attacker swapped the remaining roughly 110 million USDC through the pool and drained most of its assets.

Loss estimates differ across security firms. GoPlus Security put the damage at about $5.1 million, while PeckShield said the withdrawn assets were worth roughly $4.13 million in ETH. CertiK pointed to another element in the transaction flow: an MEV builder intervened and captured a large share of the funds. According to its report, about $4.14 million was seized by MEV infrastructure rather than ending up with the attacker.

Discord carried the first response from the team

Makina Finance launched in February 2025 and describes itself as a DeFi execution engine with institutional-grade strategy vaults. DefiLlama data showed the platform had a total value locked of $100.49 million at the time of the incident.

After the exploit, Makina Finance did not immediately confirm the breach on its official X or Telegram channels. Its first public message appeared on Discord on Tuesday morning, saying the team was aware of the public discussion and was checking the details. Roughly two hours later, a second message said the issue appeared limited to DUSD liquidity provider positions on Curve and advised LPs to withdraw funds, though it still stopped short of directly stating the scale of losses.

Another oracle-linked DeFi exploit in 2025

The incident lands in a year already marked by heavy crypto theft. Chainalysis said crypto-related thefts in 2025 have exceeded $3.41 billion, with North Korea-linked actors accounting for a record $2.02 billion. In Makina Finance’s case, the exploit adds to the list of attacks showing how oracle-dependent DeFi systems remain exposed to large-scale flash loan operations.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.