Security

Flash Loan Attack

An exploit using an uncollateralized loan repaid in one transaction to manipulate prices and drain a protocol.

A flash loan lets anyone borrow huge sums with no collateral, provided the loan is repaid within the same transaction. Attackers weaponize that. They borrow millions, use the capital to skew a thin liquidity pool or oracle price, exploit a protocol that trusts that price, and repay—all atomically.

The 2020 bZx and 2022 Beanstalk hacks worked this way; Beanstalk lost about $182 million in seconds. Defenses center on robust price oracles, like time-weighted averages or Chainlink feeds, that a single transaction can't move. Code that reads spot prices from one pool is the usual hole.

Related terms