Skip to main content

Shepley Capital

DEFI & WEB3
DeFi and Web3 - Cryptopedia by Shepley Capital

What Is a Flash Loan Attack in DeFi?

What Flash Loans Are

A flash loan is a type of uncollateralised loan available in DeFi that must be borrowed and repaid within a single blockchain transaction. Unlike traditional loans that require collateral and a creditworthiness assessment, flash loans require nothing except that the full borrowed amount plus fees is returned before the transaction block is finalised. If the borrower cannot return the funds by the end of the transaction, the entire transaction is reverted as if it never happened.

Flash loans are possible because of how smart contracts on Ethereum and other blockchains execute transactions atomically: all steps in a transaction either all succeed or all fail together. This atomicity property guarantees that the lender is never exposed to default risk. If any step fails (including the repayment), the entire sequence is unwound, returning all funds to their original state.

Legitimate uses of flash loans include arbitrage (profiting from price differences across exchanges within a single transaction), collateral swaps (replacing one form of collateral with another without needing capital to temporarily hold both), and self-liquidation (paying down a debt position to avoid liquidation using the collateral itself, temporarily). These uses create genuine economic efficiency by allowing complex multi-step financial operations without needing large amounts of upfront capital.

 

How Flash Loan Attacks Work

Flash loan attacks use the enormous temporary capital available from flash loans to manipulate vulnerable DeFi protocols in ways that would be impossible or prohibitively expensive without access to large amounts of uncollateralised capital. The attack sequence typically follows this pattern: borrow a very large amount (often tens or hundreds of millions of dollars worth of tokens), use that capital to manipulate a price, exploit a price-dependent protocol that relies on manipulated price data, extract profit, repay the flash loan, and keep the stolen funds.

 

Price Oracle Manipulation

The most common flash loan attack vector is price oracle manipulation. A price oracle is a data feed that a DeFi protocol uses to determine the current price of an asset. If a protocol uses the spot price on a single decentralised exchange as its oracle, an attacker can use a flash loan to temporarily move that price dramatically, causing the vulnerable protocol to act on the manipulated price.

The attack works like this: borrow a large amount of Token A via flash loan; use that Token A to buy enormous quantities of Token B on a DEX, dramatically inflating the DEX spot price of Token B; use Token B as collateral in a protocol that reads its price from that DEX spot price (now inflated); borrow against the inflated Token B collateral at the artificially high value; withdraw more than the actual value of the collateral; sell Token B back on the DEX (price drops back to normal); repay the flash loan; keep the borrowed excess as profit.

 

Governance Attacks

Flash loan governance attacks use temporary token borrowing to temporarily gain outsized voting power in DAO governance systems. If a governance system allows votes to be cast based on token holdings at the time of voting (rather than at a historical snapshot), an attacker can borrow a large amount of governance tokens via flash loan, vote on a malicious proposal that benefits the attacker, execute the proposal, and repay the loan. This attack requires that the governance system has no time delay between proposal submission and execution.

The Capital Nexus newsletter covers DeFi security, protocol risk analysis, and investment frameworks for Australian crypto investors each week: Capital Nexus Newsletter.

 

Major Flash Loan Attacks in History

Flash loan attacks have caused billions of dollars in losses across the DeFi ecosystem. Several landmark cases illustrate the range of attack techniques.

The bZx attacks in February 2020 were among the first widely publicised flash loan exploits. An attacker borrowed ETH via a flash loan on dYdX, used it to short WBTC on bZx, then used another loan to purchase WBTC and pump its price on a low-liquidity exchange that bZx used as its oracle. The inflated price triggered profits on the short position. Two separate attacks netted approximately USD 1 million combined.

The Harvest Finance attack in October 2020 used a USD 50 million USDC flash loan to repeatedly manipulate the USDC and USDT price in Curve Finance pools (which Harvest used as its price oracle), tricking the Harvest protocol into purchasing assets at inflated prices. The attacker extracted approximately USD 34 million in profit.

The Pancake Bunny exploit in May 2021 used a flash loan to pump the BUNNY token price, exploit a protocol mechanism that minted BUNNY based on BNB-BUNNY price ratios, mint enormous amounts of BUNNY, and sell them into the market. The BUNNY token price collapsed by 95% within hours. Similar mechanics were exploited in numerous subsequent attacks across multiple protocols. The biggest crypto exploits and hacks covers the full history of major DeFi losses.

 

Why Flash Loan Attacks Are So Difficult to Prevent

Flash loan attacks are structurally challenging to prevent because flash loans themselves are not malicious: they are a legitimate DeFi primitive that provides capital efficiency. The attack exploits vulnerabilities in other protocols that happen to be made easier by flash loan capital availability. Eliminating flash loans would remove legitimate uses without solving the underlying vulnerabilities in price oracles and governance systems.

The root cause of most flash loan exploits is not the flash loan itself but the protocol that relies on manipulable price data. A protocol that reads prices from a single low-liquidity DEX with no time-weighted average or aggregation is inherently vulnerable to manipulation, with or without flash loans. Flash loans simply reduce the capital barrier to executing the manipulation at scale.

Protocols are also complex enough that auditors miss vulnerabilities. The smart contract audit guide covers how audits work and their limitations. Even well-audited protocols have been exploited by novel attack vectors that were not anticipated in the audit. This is why bug bounties, which pay researchers to identify vulnerabilities before attackers do, are now standard practice for major DeFi protocols.

 

How Protocols Defend Against Flash Loan Attacks

 

Time-Weighted Average Prices

The most important defence against price oracle manipulation is using time-weighted average prices (TWAPs) rather than spot prices. A TWAP takes the average price over a specified time window (typically 30 minutes to several hours), making it extremely expensive to manipulate. Sustaining a manipulated price for 30 minutes would require holding the distorted trade open across many blocks, which means the attacker must maintain exposure to the manipulated price throughout, dramatically increasing the cost and risk.

 

Multiple Oracle Sources

Protocols that use multiple independent price oracle sources (such as aggregating from Chainlink, Uniswap TWAP, and a third source, then taking a median or weighted average) are far more resistant to manipulation than protocols relying on a single source. Manipulating three independent price feeds simultaneously to all show the same false price is prohibitively expensive.

 

Governance Time Locks

The fix for governance attacks is a time lock between proposal submission and execution. Most major DAOs now require at least 48 hours (often longer) between a governance vote passing and the proposal being executed. Flash loan attacks cannot sustain borrowed token balances for 48 hours: the loan must be repaid in the same transaction. A properly implemented time lock makes flash loan governance attacks structurally impossible.

 

What Happens to Users After an Exploit

The mechanics of these attacks are covered above. What happens to ordinary depositors afterwards is the part that determines your actual loss, and it varies enormously.

Four outcomes recur, and which one applies is largely decided in the first days.

The protocol reimburses from its treasury. Possible where the protocol holds substantial reserves and the loss is within them. This is the best case and it is not the common one.

Losses are socialised across depositors. Balances are reduced proportionally so the protocol continues operating. You did not choose this exposure and it is frequently the only way the protocol survives.

The token is diluted to recapitalise. New tokens are minted and sold to cover the shortfall, which transfers the loss to token holders rather than depositors. Anyone holding both takes it twice.

Some funds are returned by the attacker. Negotiated returns, sometimes with a bounty retained, have become a genuine pattern rather than an oddity, since attackers on transparent chains find laundering difficult.

The Australian tax position is where people get stuck, because the event does not fit neatly. A reduced balance is not obviously a disposal, and until the outcome is determinable there may be nothing to claim. Where value is genuinely and permanently gone, capital losses and crypto lost to an exploit or scam cover the routes, and both turn on evidence. Capture the position before and after, the transaction hashes, the protocol’s own statements and the dates, because the record is what any claim rests on and protocol communications disappear.

The practical conclusion is about sizing rather than about avoiding DeFi. Any single protocol can lose its deposits in a single block through no error of yours, which is an argument for spreading exposure across protocols and for treating an audit as a reduction in probability rather than a guarantee. An audited protocol has had a professional look for the classes of bug an auditor knows to look for, which is worth something and is not a warranty; the smart contract audit guide sets out the limits.

What Investors Should Know About Flash Loan Risk

For investors deploying capital into DeFi protocols, flash loan attack risk is one of the specific DeFi risks to assess before choosing which protocols to use. Key questions: Does the protocol use robust price oracles (TWAP, multi-source aggregation, or professional oracle networks like Chainlink)? Has the protocol been audited by multiple reputable security firms? Has the protocol been running without exploit for a significant period (track record matters)? Does the governance system have a time lock on execution?

Protocols with larger total value locked are both higher-value targets and generally better resourced for security. However, TVL is not itself a security signal: large protocols have also been exploited. A combination of multiple audits, a meaningful bug bounty program, long track record without exploit, and robust oracle design provides the strongest available security signal.

Diversifying across multiple DeFi protocols rather than concentrating all capital in one reduces the impact of any single exploit. Using protocols on separate networks (Ethereum mainnet, Solana, major Layer 2 networks) provides additional diversification against network-specific vulnerabilities. The risk management framework for DeFi capital should treat each protocol exposure as a separate risk position with appropriate position sizing.

Shepley Capital Black Emerald membership provides DeFi security analysis, protocol risk assessment, and investment frameworks for serious Australian crypto investors: View Membership Options.

Frequently Asked Questions

What is a flash loan in DeFi?

A flash loan is an uncollateralised loan available in DeFi that must be borrowed and repaid within a single blockchain transaction. If the loan is not repaid by the end of the transaction, the entire transaction reverts as if it never occurred. Flash loans are a legitimate DeFi innovation used for arbitrage, collateral swaps, and liquidations.

What is a flash loan attack?

A flash loan attack is when a malicious actor borrows a very large amount of crypto via a flash loan (often millions of dollars worth), uses that capital to manipulate prices or exploit a vulnerability in a DeFi protocol within the same transaction, profits from the manipulation, and repays the flash loan with the profits. The entire attack can happen in a single blockchain transaction.

How do flash loans enable price oracle manipulation?

Many DeFi protocols use on-chain price oracles that derive prices from exchange liquidity pools. A flash loan allows an attacker to temporarily distort a pool's price (by making a huge trade), interact with a protocol using the manipulated price (e.g. taking an undercollateralised loan), then restore the price and repay the flash loan, all within one transaction.

What are the most notable flash loan attacks in DeFi history?

The bZx protocol attacks in 2020 were among the first high-profile flash loan exploits. The Harvest Finance attack in 2020 drained $34 million through oracle manipulation. PancakeBunny lost $45 million in a flash loan attack in 2021. These attacks collectively drove significant improvements in oracle design and protocol security practices.

How do DeFi protocols protect against flash loan attacks?

Key protections include using time-weighted average price (TWAP) oracles (like Uniswap v3 TWAP) that cannot be manipulated in a single block, implementing per-block price change limits, using decentralised oracle networks like Chainlink that are independent of on-chain liquidity pools, and adding reentrancy guards that prevent protocol functions being called recursively within a transaction.

Does a flash loan attack require hacking skills?

Flash loan attacks require significant blockchain development knowledge and understanding of the target protocol's vulnerabilities. However, the barrier has lowered because previous attacks have been analysed and partially replicated. Sandwich attack bots and MEV searchers execute simpler flash loan strategies continuously without needing to discover new vulnerabilities.

Do flash loan attacks affect regular DeFi users directly?

When a flash loan attack successfully exploits a protocol, the stolen funds typically come from the protocol's liquidity pool, directly reducing the value of positions held by ordinary liquidity providers and depositors. The impact is felt immediately in token prices and protocol TVL, and affected protocols often require emergency patches that temporarily halt all user withdrawals.

How should investors evaluate DeFi protocol resilience to flash loan attacks?

Look for: use of time-weighted average price oracles rather than spot price oracles, successful third-party security audits that specifically address oracle manipulation risks, a history of withstanding flash loan attack attempts, active monitoring and emergency shutdown capabilities, and a bug bounty programme attracting security researchers to find vulnerabilities before attackers do.

WRITTEN & REVIEWED BY Chris Shepley

UPDATED: SEPTEMBER 2026

Choose your next topic from our Cryptopedia​

Grow your crypto portfolio with the latest insights, straight to your inbox!

Join 10,150+ CEOs, Business Owners, Parents, Students, & more receiving actionable crypto insights to grow their portfolios.