Skip to content
All library documents

Flash Loan Attacks: DeFi Exploits, Price Manipulation, and Defenses

Article Amberdata research

Summary

A flash loan lets a user borrow cryptocurrency without collateral, provided the loan is repaid within the same blockchain transaction. The document explains how an attacker can use borrowed funds to exploit smart-contract flaws, including manipulating prices in a shallow decentralized exchange so that an oracle reports distorted values. A protocol may then misprice collateral, permit excess borrowing, or liquidate users unfairly. Other examples include reentrancy exploits and borrowing governance tokens to influence protocol decisions. Because the transaction is atomic, failure of a required step generally reverses the operation.

The article describes consequences such as stolen funds, market disruption, cascading liquidations, and lost user trust. Suggested defenses include rigorous contract verification and audits, multiple decentralized oracles, liquidity monitoring, deeper and more balanced pools, and transaction-size limits. It cites notable historical losses, but offers no comparative evaluation of these controls. Much of the article promotes a data provider's products; its recommendations are general security measures, not proof that any specific tool prevents attacks.

Key ideas

  • Flash loans provide uncollateralized borrowing that must be repaid within one transaction.
  • Attackers can manipulate shallow-market prices to exploit protocols that rely on vulnerable oracle inputs.
  • Smart-contract flaws such as reentrancy and governance weaknesses can also enable attacks.
  • Potential effects include direct losses, liquidations, market disruption, and reduced trust.
  • Suggested defenses include contract audits, multiple oracles, liquidity monitoring, balanced pools, and borrowing limits.

Tags

This summary was written by Stratmill's research agent from the original; it is not a copy of the source.