In March 2023, an attacker borrowed $200M in a flash loan, manipulated the Euler Finance protocol, and walked away with $197M in profit — all in one transaction, all on-chain, all completely permissionless. Flash loan attacks are the most capital-efficient exploit in DeFi.
A flash loan lender (like Aave or dYdX) lets you borrow any amount with zero collateral, as long as you repay it within the same transaction. If you don't repay, the entire transaction reverts — the lender has zero risk. This creates a window where an attacker can wield enormous capital to manipulate protocols.
Most protocols that read spot prices from AMMs (like Uniswap V2/V3) can have their prices manipulated within a single transaction. If your protocol makes a lending decision, minting decision, or liquidation decision based on a spot price, it may be vulnerable.
A flash loan attack uses uncollateralized loans (borrowed and repaid within a single transaction) to amplify an exploit. Attackers borrow millions, use them to manipulate prices, drain collateral, or exploit arithmetic bugs, then repay the loan — all in one atomic transaction. The protocol loses funds even though the loan is repaid.
Step 1: Borrow a large amount from a flash loan provider (Aave, dYdX, Uniswap). Step 2: Use funds to manipulate a price oracle, liquidity pool, or exploit a contract vulnerability. Step 3: Extract profit from the exploited protocol. Step 4: Repay the flash loan plus fee. If any step fails, the entire transaction reverts — so it's risk-free for the attacker.
Yes — flash loans are widely used for arbitrage (equalizing prices across DEXes), collateral swaps (replacing one collateral type with another in a single transaction), and self-liquidations (closing underwater positions without needing upfront capital). The loan itself isn't malicious — it's the target protocol's vulnerability that enables the attack.
Flash loan attacks are among the most damaging in DeFi: Euler Finance ($197M, 2023), Cream Finance ($130M, 2021), PancakeBunny ($45M, 2021), bZx ($8M, 2020), and Harvest Finance ($34M, 2020). Most exploited price oracle vulnerabilities or reentrancy bugs — the flash loan just provided the capital to make them profitable.
Use TWAP oracles instead of spot prices, add reentrancy guards on all state-changing functions, implement per-block or per-transaction value limits, and use checks-effects-interactions everywhere. SmartContractAuditor.ai simulates flash loan attack vectors on your contract, identifying which functions could be exploited with borrowed capital.