{"investigation":{"slug":"makina","entity_name":"Makina Finance","trust_score":35,"severity_base":null,"score_modifier":0,"confidence":0.75,"status":"published","content_type":"investigation","summary":"Makina Finance is a non-custodial DeFi execution engine that launched in late 2025 on Ethereum, enabling automated yield strategies via tokenized vaults called Machines. On January 20, 2026, the protocol suffered a $4.13 million oracle manipulation exploit targeting its DUSD/USDC Curve stableswap pool, despite having completed six independent security audits in the months prior. The team recovered approximately $3.65 million (89% of user losses) within one week and resumed operations on January 26, 2026, though a residual 11% shortfall remained subject to a revenue-share restitution plan.","sections":[{"content":"On January 20, 2026, at 03:40:35 UTC (Ethereum block 24,273,362), Makina Finance was exploited for approximately 1,299 ETH (~$4.13 million). The attacker borrowed approximately $280 million USDC via flash loans split between Morpho ($160.6 million) and Aave V2 ($119.4 million). Using $170 million of this capital, the attacker manipulated balances across three Curve pools — DUSD/USDC, DAI/USDC/USDT, and MIM-3LP3CRV-f — to artificially inflate the MachineShareOracle's reported asset-under-management (AUM) value. The share price was pushed from approximately 1.011771 to 1.331577 within a single transaction. The attacker then extracted profits via a DUSD-to-USDC swap at the distorted rate. The root vulnerability was the Caliber contract's reliance on external Curve pool outputs (specifically calc_withdraw_one_coin()) as AUM multipliers without input validation, rate limits, or flash-loan resistance. The permissionless updateTotalAum() function could be called within the same transaction as the manipulation, locking in inflated valuations before the swap. A MEV searcher front-ran the draining transaction, capturing the bulk of the stolen funds: approximately 1,023 ETH (~$3.3 million) ended up in address 0xbed26250Db2097318386F540fD546acEDf7bdE25, and 276.322 ETH was sent to a Rocket Pool node distributor at 0x573db3aed219efd4d2cdabc0d00366e7b80f910e. The original attacker address was 0x935bfb495E33f74d2E9735DF1DA66acE442ede48 and 0x2F934B0... (partial). The exploit affected only the DUSD Curve LP positions; other Machines and deployments were stated to be unaffected.","heading":"January 2026 Oracle Manipulation Exploit","sources":[{"url":"https://www.certik.com/resources/blog/makina-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://rekt.news/makina-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2026/01/20/makina-finance-exploit-drains-1299-eth-in-major-defi-hack/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://decrypt.co/355132/ethereum-defi-platform-makina-hit-by-flash-loan-exploit-loses-4m-in-eth","name":"decrypt.co","type":"other","credibility":3},{"url":"https://www.quillaudits.com/blog/hack-analysis/makina-4m-hack-explained","name":"quillaudits.com","type":"other","credibility":3},{"url":"https://medium.com/coinmonks/makinas-4m-hack-8afca700c00c","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Makina Finance completed six independent security audits between July and November 2025, prior to the January 2026 exploit. Firms engaged included Enigma Dark (July and September 2025), SigmaPrime (August 2025), ChainSecurity (September 2025, with a follow-on in January 2026), Cantina (October 2025), and OtterSec (November 2025). All auditors concluded the codebase provided a high level of security. However, a critical detail emerged after the exploit: the Cantina capture-the-flag assessment (September 18 – October 15, 2025) explicitly listed as out-of-scope: 'Losses caused by oracle price/liquidity pool manipulation, where an unchecked synchronous deposit is used.' This exact attack vector was the one exploited three months later. Security researchers subsequently confirmed the MachineShareOracle had no time-weighted average pricing, no access controls, and no transaction delays, and was 'fully manipulable in the same transaction.' The vulnerability was not introduced by a code change after audits but was present in the integration of the Dialectic operator's DUSD Curve deployment on October 27, 2025 — after audits on the core contracts were complete. The post-exploit ChainSecurity audit (January 26, 2026) was completed before the protocol resumed operations.","heading":"Audit Failures and Pre-Exploit Warnings","sources":[{"url":"https://rekt.news/makina-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/makina-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://www.quillaudits.com/blog/hack-analysis/makina-4m-hack-explained","name":"quillaudits.com","type":"other","credibility":3},{"url":"https://docs.makina.finance/","name":"docs.makina.finance","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, Makina activated security mode on all smart vaults and advised liquidity providers to withdraw remaining liquidity from the DUSD Curve pool. The team engaged SEAL911, ChainSecurity, EnigmaDarkLabs, and Cantina in the incident response. A 10% whitehat bounty (102.3 ETH) was offered to the original attacker via an on-chain message, with a 24-hour deadline; no response was received. Under the SEAL Whitehat Safe Harbor framework, the MEV builder voluntarily returned 920 ETH (of the 1,023 ETH it received), net of the 10% bounty. The Rocket Pool validator returned 157.1 ETH. An additional 229,963 USDC was recovered from post-exploit arbitrage profits. In aggregate, over $3.65 million was recovered and distributed to affected users. Makina and its operator Dialectic committed to a revenue-share restitution plan for the remaining 11% of user shortfall. On January 22, 2026, Makina posted on X confirming that 920 ETH had been returned by the MEV builder under the SEAL Safe Harbor. The protocol resumed full operations on January 26, 2026, following a patch audit. Users whitelisted for AML/KYC were eligible for direct redemptions; non-whitelisted users were offered secondary market liquidity for DUSD.","heading":"Recovery Response and User Restitution","sources":[{"url":"https://x.com/makinafi/status/2014349539847573565","name":"x.com","type":"other","credibility":3},{"url":"https://coinheadlines.com/news/makinafi-starts-fund-recovery-process-after-exploit-here-is-how/article-26554/","name":"coinheadlines.com","type":"other","credibility":3},{"url":"https://www.quillaudits.com/blog/hack-analysis/makina-4m-hack-explained","name":"quillaudits.com","type":"other","credibility":3},{"url":"https://phemex.com/news/article/makina-finance-demands-return-of-513994-usdc-from-exploit-profits-55868","name":"phemex.com","type":"other","credibility":3},{"url":"https://medium.com/coinmonks/makinas-4m-hack-8afca700c00c","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Makina Finance is structured as an execution layer in which third-party 'Operators' deploy capital strategies into automated vaults called 'Machines.' Each Machine holds tokenized positions and routes capital through DeFi protocols including Curve, Aave, Pendle, and Spectra. The first and primary Operator at the time of the exploit was Dialectic, an institutional liquid fund, which deployed the DUSD (Dialectic USD) stablecoin vault on October 27, 2025. The architecture separates protocol risk from operator risk, but as the exploit demonstrated, oracle integration choices made at the operator deployment level — and not covered by core contract audits — can expose user funds. The protocol is non-custodial and the Machines are fully on-chain. Makina is incorporated in the Cayman Islands.","heading":"Protocol Architecture and Operator Risk","sources":[{"url":"https://app.makina.finance/strategy/DUSD","name":"app.makina.finance","type":"other","credibility":3},{"url":"https://makinafi.substack.com/p/operator-deep-dive-dialectic","name":"makinafi.substack.com","type":"other","credibility":3},{"url":"https://cyber.fund/content/makina-the-defi-execution-engine","name":"cyber.fund","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/makina-incident-analysis","name":"certik.com","type":"other","credibility":3}],"severity":"medium"},{"content":"In June 2025, Makina Finance raised $3 million in a strategic funding round. Investors included Hypernative Labs, Kiln, Bodhi Ventures, Cyber Fund, Interop Ventures, Steakhouse Financial, base DAO, and notable individual angels including Aleksander Leonard Larsen (co-founder of Sky Mavis/Axie Infinity), Ryan Zurrer, Adrian Brink, Yaoqi Jia, and ivangbi. The round preceded the protocol's public launch and the subsequent exploit. No Series A or follow-on funding activity has been publicly reported as of May 2026. The team's individual identities are not prominently disclosed in public documentation; the protocol's official docs do not name team members, though investor-facing materials describe an institutional-grade team background.","heading":"Funding and Investor Background","sources":[{"url":"https://www.cmointern.com/2025/06/makina-finance-raises-3m-to-power.html?m=1","name":"cmointern.com","type":"other","credibility":3},{"url":"https://www.cypherhunter.com/en/e/makina-finance-raised-funding-2025-06-25/","name":"cypherhunter.com","type":"other","credibility":3},{"url":"https://crypto-fundraising.info/projects/makina/","name":"crypto-fundraising.info","type":"other","credibility":3}],"severity":"medium"},{"content":"Makina Finance appears in ZachXBT-adjacent community monitoring, though no published ZachXBT investigation thread specifically targeting Makina was identified in available sources as of May 2026. The protocol's AVOID.NET trust score reflects the January 2026 exploit and the structural oracle risk identified post-incident. Community and media coverage flagged the Cantina audit's explicit exclusion of the exploited attack vector as a significant due diligence concern. The exploit occurred within three months of the protocol's live launch and affected a TVL of approximately $100 million at the time. No accusations of insider trading, rug pull, or intentional fraud have been publicly substantiated against the Makina team.","heading":"ZachXBT Flag and Community Concerns","sources":[{"url":"https://rekt.news/makina-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://coinalertnews.com/news/2026/01/20/defi-protocol-makinafi-4m-exploit","name":"coinalertnews.com","type":"other","credibility":3},{"url":"https://www.ainvest.com/news/rising-risks-defi-makina-finance-hack-implications-crypto-security-2601/","name":"ainvest.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2025-06-25","event":"Makina Finance raises $3 million in strategic funding from Hypernative Labs, Kiln, Bodhi Ventures, Cyber Fund, and other angels.","source":""},{"date":"2025-07","event":"Enigma Dark completes fuzz/invariant testing audit of Makina Core.","source":"","date_original":"2025-07-01"},{"date":"2025-08","event":"SigmaPrime completes audit of Makina Core and Makina Periphery.","source":"","date_original":"2025-08-01"},{"date":"2025-09","event":"ChainSecurity completes audits of Makina Core and Makina Periphery. Enigma Dark audits Makina Periphery and Machine Share Oracle.","source":"","date_original":"2025-09-01"},{"date":"2025-10-15","event":"Cantina capture-the-flag security assessment ends. Out-of-scope exclusion explicitly lists oracle price manipulation via unchecked synchronous deposit — the exact vector later used in the exploit.","source":""},{"date":"2025-10-27","event":"Dialectic (first Operator on Makina) deploys DUSD into Curve pools, introducing the oracle integration vulnerability into live production.","source":""},{"date":"2025-11","event":"OtterSec completes Makina security assessment.","source":"","date_original":"2025-11-01"},{"date":"2026-01-20","event":"At 03:40:35 UTC (block 24,273,362), attacker exploits MachineShareOracle via $280M flash loan to drain 1,299 ETH (~$4.13M) from the DUSD/USDC Curve pool. MEV searcher front-runs the transaction, capturing the majority of stolen funds.","source":""},{"date":"2026-01-20","event":"Makina activates security mode on all smart vaults and advises LPs to withdraw from the DUSD Curve pool. Team engages SEAL911 and security firms.","source":""},{"date":"2026-01-22","event":"MEV builder returns 920 ETH under SEAL Whitehat Safe Harbor framework (10% bounty retained). Rocket Pool validator returns 157.1 ETH. Makina posts confirmation on X.","source":""},{"date":"2026-01-26","event":"Protocol resumes full normal operations following post-exploit patch audit by ChainSecurity. 89% of users fully recovered; 11% subject to revenue-share restitution plan.","source":""}],"sources_used":[{"url":"https://www.certik.com/resources/blog/makina-incident-analysis","name":"certik.com","type":"other","archive_url":"http://web.archive.org/web/20260129022336/https://www.certik.com/resources/blog/makina-incident-analysis","credibility":3,"archive_timestamp":"2026-01-29T02:23:36+00:00"},{"url":"https://rekt.news/makina-rekt","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260415163244/https://rekt.news/makina-rekt","credibility":3,"archive_timestamp":"2026-04-15T16:32:44+00:00"},{"url":"https://www.cryptotimes.io/2026/01/20/makina-finance-exploit-drains-1299-eth-in-major-defi-hack/","name":"cryptotimes.io","type":"other","archive_url":"http://web.archive.org/web/20260120065809/https://www.cryptotimes.io/2026/01/20/makina-finance-exploit-drains-1299-eth-in-major-defi-hack/","credibility":3,"archive_timestamp":"2026-01-20T06:58:09+00:00"},{"url":"https://decrypt.co/355132/ethereum-defi-platform-makina-hit-by-flash-loan-exploit-loses-4m-in-eth","name":"decrypt.co","type":"other","archive_url":"http://web.archive.org/web/20260825132703/https://decrypt.co/355132/ethereum-defi-platform-makina-hit-by-flash-loan-exploit-loses-4m-in-eth","credibility":3,"archive_timestamp":"2026-08-25T13:27:03+00:00"},{"url":"https://www.quillaudits.com/blog/hack-analysis/makina-4m-hack-explained","name":"quillaudits.com","type":"other","archive_url":"http://web.archive.org/web/20260727085628/https://www.quillaudits.com/blog/hack-analysis/makina-4m-hack-explained","credibility":3,"archive_timestamp":"2026-07-27T08:56:28+00:00"},{"url":"https://medium.com/coinmonks/makinas-4m-hack-8afca700c00c","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://docs.makina.finance/","name":"docs.makina.finance","type":"other","archive_url":"http://web.archive.org/web/20260608152221/https://docs.makina.finance/","credibility":3,"archive_timestamp":"2026-06-08T15:22:21+00:00"},{"url":"https://x.com/makinafi/status/2014349539847573565","name":"x.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://coinheadlines.com/news/makinafi-starts-fund-recovery-process-after-exploit-here-is-how/article-26554/","name":"coinheadlines.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:bad-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://phemex.com/news/article/makina-finance-demands-return-of-513994-usdc-from-exploit-profits-55868","name":"phemex.com","type":"other","archive_url":"http://web.archive.org/web/20260802123938/https://phemex.com/news/article/makina-finance-demands-return-of-513994-usdc-from-exploit-profits-55868","credibility":3,"archive_timestamp":"2026-08-02T12:39:38+00:00"},{"url":"https://app.makina.finance/strategy/DUSD","name":"app.makina.finance","type":"other","archive_url":"http://web.archive.org/web/20260417093652/https://app.makina.finance/strategy/dusd","credibility":3,"archive_timestamp":"2026-04-17T09:36:52+00:00"},{"url":"https://makinafi.substack.com/p/operator-deep-dive-dialectic","name":"makinafi.substack.com","type":"other","archive_url":"http://web.archive.org/web/20260218092809/https://makinafi.substack.com/p/operator-deep-dive-dialectic","credibility":3,"archive_timestamp":"2026-02-18T09:28:09+00:00"},{"url":"https://cyber.fund/content/makina-the-defi-execution-engine","name":"cyber.fund","type":"other","archive_url":"http://web.archive.org/web/20260420001931/https://cyber.fund/content/makina-the-defi-execution-engine","credibility":3,"archive_timestamp":"2026-04-20T00:19:31+00:00"},{"url":"https://www.cmointern.com/2025/06/makina-finance-raises-3m-to-power.html?m=1","name":"cmointern.com","type":"other","archive_url":"https://web.archive.org/web/20260829084513/https://www.cmointern.com/2025/06/makina-finance-raises-3m-to-power.html?m=1","credibility":3,"archive_timestamp":"2026-08-29T08:45:13+00:00"},{"url":"https://www.cypherhunter.com/en/e/makina-finance-raised-funding-2025-06-25/","name":"cypherhunter.com","type":"other","archive_url":"http://web.archive.org/web/20251103063436/https://www.cypherhunter.com/en/e/makina-finance-raised-funding-2025-06-25/","credibility":3,"archive_timestamp":"2025-11-03T06:34:36+00:00"},{"url":"https://crypto-fundraising.info/projects/makina/","name":"crypto-fundraising.info","type":"other","archive_url":"http://web.archive.org/web/20251210023504/https://crypto-fundraising.info/projects/makina/","credibility":3,"archive_timestamp":"2025-12-10T02:35:04+00:00"},{"url":"https://coinalertnews.com/news/2026/01/20/defi-protocol-makinafi-4m-exploit","name":"coinalertnews.com","type":"other","archive_url":"https://web.archive.org/web/20260829025606/https://coinalertnews.com/news/2026/01/20/defi-protocol-makinafi-4m-exploit","credibility":3,"archive_timestamp":"2026-08-29T02:56:06+00:00"},{"url":"https://www.ainvest.com/news/rising-risks-defi-makina-finance-hack-implications-crypto-security-2601/","name":"ainvest.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:13.920141+00:00","updated_at":"2026-08-30T03:54:57.370081+00:00"}}