TLDR Makina Finance suffered a $5 million loss due to a sophisticated flash loan exploit. The attack manipulated the DUSD/USDC stablecoin pool’s oracle, drainingTLDR Makina Finance suffered a $5 million loss due to a sophisticated flash loan exploit. The attack manipulated the DUSD/USDC stablecoin pool’s oracle, draining

$5 Million Stolen from Makina Finance in Flash Loan Attack, CertiK Finds

3 min read

TLDR

  • Makina Finance suffered a $5 million loss due to a sophisticated flash loan exploit.

  • The attack manipulated the DUSD/USDC stablecoin pool’s oracle, draining the funds.

  • CertiK reported that the exploit involved a flash loan of 280 million USDC.

  • An MEV bot front-ran the exploit, capturing the majority of the stolen funds.

  • Makina Finance assured users that other assets were not affected by the breach.

Makina Finance, a decentralized finance (DeFi) protocol, has been exploited in a sophisticated attack. Blockchain security firm CertiK reported that the exploit resulted in the theft of approximately $5 million from one of its stablecoin pools. The attack involved a flash loan of 280 million USDC and a manipulation of the protocol’s oracle, causing a loss for the DeFi platform.

Flash Loan Exploit Drains $5 Million

The exploit occurred on the DUSD/USDC Curve stablecoin pool, where the attacker borrowed 280 million USDC. They used 170 million USDC to manipulate the MachineShareOracle, which the pool relies on for pricing. Once the oracle was manipulated, the attacker swapped 110 million USDC, draining the pool of around $5 million in value.

Security firms offered varying estimates of the loss. GoPlus Security estimated the damage at $5.1 million, while PeckShield reported a loss of about $4.13 million in ether. CertiK’s analysis revealed that an MEV (Maximum Extractable Value) bot played a crucial role in executing the exploit, front-running the transaction and draining the funds. The bot, operating from the address 0xa6c2, captured the majority of the stolen assets.

Makina Finance’s Response

Makina Finance has addressed the situation through its Discord channels, confirming that the issue only affected its DUSD liquidity provider positions on Curve. The firm has assured users that no other assets or deployments were compromised. To mitigate further risk, Makina Finance activated security mode across all its machines while it continues to investigate the situation.

The team advised liquidity providers in the affected pool to withdraw their funds. Despite the ongoing investigation, Makina Finance has not officially confirmed the exploit or provided specific details on the recovery process. The firm has been in contact with CertiK and other security teams to assess the full scope of the attack.

Rising Threats in DeFi

This breach follows a year marked by heightened crypto theft, with over $3.41 billion stolen in 2025. North Korea was identified as the most active threat actor, responsible for over $2 billion in stolen assets. The Makina Finance exploit highlights the growing concerns around DeFi security, especially the risks associated with flash loans and oracle manipulation.

Other recent exploits include the Truebit Protocol attack, which resulted in the loss of $26.5 million. As DeFi platforms continue to evolve, security experts warn that vulnerabilities in smart contracts, such as outdated Solidity versions, remain a major concern. In response, experts recommend using tools like the SafeMath library to protect systems from logic vulnerabilities and integer overflows.

The post $5 Million Stolen from Makina Finance in Flash Loan Attack, CertiK Finds appeared first on CoinCentral.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Once Upon a Farm Announces Pricing of Initial Public Offering

Once Upon a Farm Announces Pricing of Initial Public Offering

BERKELEY, Calif.–(BUSINESS WIRE)–Once Upon a Farm today announced the pricing of its initial public offering of 10,997,209 shares of its common stock, 7,631,537
Share
AI Journal2026/02/06 08:15
Forward Industries Bets Big on Solana With $4B Capital Plan

Forward Industries Bets Big on Solana With $4B Capital Plan

The firm has filed with the U.S. Securities and Exchange Commission to launch a $4 billion at-the-market (ATM) equity program, […] The post Forward Industries Bets Big on Solana With $4B Capital Plan appeared first on Coindoo.
Share
Coindoo2025/09/18 04:15
332M accounts and $28B TVL,

332M accounts and $28B TVL,

The post 332M accounts and $28B TVL, appeared on BitcoinEthereumNews.com. PayPal USD debuts on TRON as a permissionless token PYUSD0, enabled by LayerZero’s OFT standard and the Stargate Hydra extension. The announcement on September 18, 2025 (Geneva) introduces native interoperability between chains and transfers without manual steps for users; the news echoes elements already communicated by PayPal at the launch of PYUSD PayPal Newsroom. The move concerns an ecosystem that includes 332 million accounts and over $28 billion in TVL. In this context, the fungibility of a stablecoin regulated across multiple networks and the use of TRON as a settlement layer for payments and remittances is at stake. According to the data collected by TRONSCAN updated as of September 18, 2025, the network metrics confirm the cited volumes and highlighted traffic patterns. Our editorial team has verified the transaction logs and monitored the public chain metrics to corroborate the reported figures; the observations on daily flows and TVL are consistent with the network dashboards. Industry analysts observe that the entry of a regulated issuer like PayPal tends to increase institutional interest, provided there is transparency on reserves and compliance checks. What is PYUSD0 on TRON and why is it relevant PYUSD0 is the representation of PayPal USD on TRON. It is pegged one-to-one to PYUSD through the OFT standard: the two tokens remain a single stablecoin, fungible and reconciled across chains. The integration is made possible by Stargate Hydra, now operational through LayerZero. According to the founder of TRON, Justin Sun, the extension on TRON expands access and trust for users and institutions. For Bryan Pellegrino (CEO of LayerZero Labs), stablecoins represent a pillar of global payments and remittances, as the native compatibility between chains enables their operational scalability. It must be said that the alignment between issuer, cross-chain infrastructure, and settlement network is a key element. Key Numbers: TRON…
Share
BitcoinEthereumNews2025/09/19 08:18