Skip to content
DeFi & Web3Beginner

Flash loan attacks: what they are and how they work

A flash loan attack uses an instant, uncollateralized loan to exploit a DeFi protocol, often by manipulating a price oracle inside one transaction.

Vahe HakobyanVahe HakobyanEditor-in-chief Updated Oct 6, 20263 min readFact-checked
A glowing emerald chain of light links stacked glass blocks on a dark navy background.
Illustration: World-Crypt
On this page
Key takeaways
  • A flash loan is uncollateralized and must be repaid in the same transaction.
  • Attackers often manipulate a price oracle to drain a protocol.
  • Protocols use time-weighted oracles, audits and pause controls as defenses.
  • A flash loan is a tool; an attack is the exploit.

Short answer

A flash loan attack is an exploit that uses an instant, uncollateralized loan to manipulate a DeFi protocol and drain funds. The loan is a legitimate tool. The attack is the abuse of that tool.

A blockchain can run many actions as one transaction. If any step fails, the whole transaction reverses. That lets a lender hand over funds without collateral, and attackers use the same feature to fund an exploit.

What is a flash loan attack?

A flash loan attack is a DeFi exploit that uses an instant, uncollateralized loan as fuel. The attacker borrows crypto, uses it to push a protocol into a bad state, and repays the loan before the transaction ends. Flash loans are a normal DeFi tool. An attack is what happens when someone uses that tool to break a protocol.

How does the attack work?

The attacker writes a smart contract that borrows from a flash loan provider. In the same transaction, the contract trades to move a price on a decentralized exchange. That move can make the protocol value its assets incorrectly. The contract then drains funds and repays the loan. If repayment fails, the transaction reverses.

Many attacks target a price oracle or exchange rate. A large trade can distort a spot price for a moment, and the attacker uses that false price to borrow too much or withdraw more than allowed.

How do protocols defend?

Protocols cannot easily stop a transaction while it runs, so most defenses work before an attack happens. Teams use time-weighted average prices so a short price spike does not count. They also get audits and bug bounties. Emergency pause controls can stop a protocol if an exploit is spotted.

Defense checks

  • Use time-weighted oracles instead of one spot price.
  • Get independent audits and run bug bounties.
  • Add emergency pause controls and monitoring.

How is it different from a flash loan?

A flash loan is just capital that must be borrowed and repaid in one transaction. It is not an attack by itself. People use flash loans for legitimate DeFi actions. A flash loan attack is the exploit that uses that capital to harm a protocol.

Flash loan vs flash loan attack
Criterion Flash loan Flash loan attack
Nature A DeFi borrowing tool An exploit that uses that tool
Collateral None, repayment is enforced by the transaction None, the attack uses borrowed funds
Goal Complete a DeFi action Drain or manipulate a protocol

Frequently asked questions

No. The loan and repayment happen in the same transaction, so the lender does not need collateral.

Sometimes. Pause controls and monitoring can halt a protocol, but an attack often runs inside one transaction and finishes in seconds.

The loan is not illegal, but using one to steal funds or manipulate a market can break fraud or market manipulation laws.

Recovery is not guaranteed. Some protocols have negotiated returns or traced funds, but attackers often move assets quickly.

Was this guide helpful?
Written byVahe HakobyanVahe Hakobyan is the editor-in-chief of World-Crypt. He covers bitcoin, markets and regulation, and leads the newsroom that fact-checks every story before it goes live.