Market Abuse Crypto & Digital Assets

Flash Loan Attacks

Borrowing large uncollateralized sums within a single transaction to manipulate prices or drain DeFi protocols.

1 Introduction

A flash loan attack exploits a feature unique to decentralized finance: the ability to borrow a very large, uncollateralized sum that must be borrowed and repaid within a single atomic blockchain transaction. Because the loan only needs to be solvent at the end of the transaction, an attacker can command tens of millions of dollars for a few milliseconds. The attacker uses that temporary capital to skew the price in a thin automated market maker (AMM) pool or a price oracle, tricks a victim protocol into trusting the manipulated price, extracts value, and repays the loan in the same transaction. If any step fails, the entire transaction reverts and the attacker simply loses gas.

1 tx

Borrow, manipulate and repay in a single atomic transaction

$0

Collateral required to borrow the loan

Tens of millions

Drained from DeFi protocols in single transactions

2 Interactive Atomic Transaction Walkthrough

Phase: Loan Requested

Single Atomic Transaction

AMM Pool Price vs. True Market Price

Step 1 - Loan Requested: The attacker calls a lending pool and borrows $100M with no collateral. The pool releases the funds on the condition that they are returned before this same transaction ends. Nothing has been manipulated yet.

3 Detailed Analysis

Why Atomicity Is the Weapon

The Flash Loan

An uncollateralized loan that only has to be solvent at the end of one transaction. It grants an attacker enormous, risk-free capital for the duration of a few function calls, with no credit check and no down payment.

The Price Oracle

Protocols that read a price directly from a single AMM pool can be fooled. A large trade temporarily moves the spot price, and any contract that trusts that instantaneous figure values collateral incorrectly.

Detection Methodology

Because the attack lives inside one transaction, traditional account-monitoring is too slow. Defenders instead analyze transaction traces and mempool activity for the tell-tale shape: a large borrow from a lending pool, an immediate outsized swap against a low-liquidity pool, an interaction with a separate protocol at a skewed valuation, and a repayment, all in the same block. On-chain analytics also watch for instantaneous price deviations between an AMM spot price and time-weighted or external reference prices, since a healthy market does not move tens of percent and snap back within one transaction.

Red Flags

  • A large uncollateralized borrow and full repayment occurring within a single transaction
  • An AMM spot price deviating sharply from time-weighted or external reference prices, then reverting
  • A protocol pricing collateral from a single low-liquidity pool that is cheap to move
  • One transaction touching a lending pool, a thin AMM pool, and a victim protocol in rapid sequence

Related Fraud Types