Summary
Makina Finance is a non-custodial DeFi execution engine that launched in late 2025 on Ethereum, enabling automated yield strategies via tokenized vaults called Machines. On January 20, 2026, the protocol suffered a $4.13 million oracle manipulation exploit targeting its DUSD/USDC Curve stableswap pool, despite having completed six independent security audits in the months prior. The team recovered approximately $3.65 million (89% of user losses) within one week and resumed operations on January 26, 2026, though a residual 11% shortfall remained subject to a revenue-share restitution plan.
Connected Entities
2 entities- + 1 more
Community submissions
- Under reviewincriminatingWayback pending6/2/2026, 5:46:47 PM
“CertiK incident analysis confirming $4.13M flash loan attack on MakinaFi's DUSD/USDC Curve pool on January 20, 2026”
— avoid-scout
Timeline(11 events)
2025-06-25
Makina Finance raises $3 million in strategic funding from Hypernative Labs, Kiln, Bodhi Ventures, Cyber Fund, and other angels.
2025-07-01
Enigma Dark completes fuzz/invariant testing audit of Makina Core.
2025-08-01
SigmaPrime completes audit of Makina Core and Makina Periphery.
2025-09-01
ChainSecurity completes audits of Makina Core and Makina Periphery. Enigma Dark audits Makina Periphery and Machine Share Oracle.
2025-10-15
Cantina capture-the-flag security assessment ends. Out-of-scope exclusion explicitly lists oracle price manipulation via unchecked synchronous deposit — the exact vector later used in the exploit.
2025-10-27
Dialectic (first Operator on Makina) deploys DUSD into Curve pools, introducing the oracle integration vulnerability into live production.
2025-11-01
OtterSec completes Makina security assessment.
2026-01-20
At 03:40:35 UTC (block 24,273,362), attacker exploits MachineShareOracle via $280M flash loan to drain 1,299 ETH (~$4.13M) from the DUSD/USDC Curve pool. MEV searcher front-runs the transaction, capturing the majority of stolen funds.
2026-01-20
Makina activates security mode on all smart vaults and advises LPs to withdraw from the DUSD Curve pool. Team engages SEAL911 and security firms.
2026-01-22
MEV builder returns 920 ETH under SEAL Whitehat Safe Harbor framework (10% bounty retained). Rocket Pool validator returns 157.1 ETH. Makina posts confirmation on X.
2026-01-26
Protocol resumes full normal operations following post-exploit patch audit by ChainSecurity. 89% of users fully recovered; 11% subject to revenue-share restitution plan.
Decision Log
- hash: 2ESJnK2tK5NeQ5ydisPNwCBRhQGhJKAztz9tqEtBXdaP
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:13 AM
last updated: 5/26/2026, 7:42:44 PM
avoid.net — verified advice for a post-truth world