Flash loan attacks: what they are and how they work
A flash loan attack uses an instant, uncollateralized loan to exploit a DeFi protocol, often by manipulating a price oracle inside one transaction.

On this page
- A flash loan is uncollateralized and must be repaid in the same transaction.
- Attackers often manipulate a price oracle to drain a protocol.
- Protocols use time-weighted oracles, audits and pause controls as defenses.
- A flash loan is a tool; an attack is the exploit.
A blockchain can run many actions as one transaction. If any step fails, the whole transaction reverses. That lets a lender hand over funds without collateral, and attackers use the same feature to fund an exploit.
What is a flash loan attack?
A flash loan attack is a DeFi exploit that uses an instant, uncollateralized loan as fuel. The attacker borrows crypto, uses it to push a protocol into a bad state, and repays the loan before the transaction ends. Flash loans are a normal DeFi tool. An attack is what happens when someone uses that tool to break a protocol.
How does the attack work?
The attacker writes a smart contract that borrows from a flash loan provider. In the same transaction, the contract trades to move a price on a decentralized exchange. That move can make the protocol value its assets incorrectly. The contract then drains funds and repays the loan. If repayment fails, the transaction reverses.
Many attacks target a price oracle or exchange rate. A large trade can distort a spot price for a moment, and the attacker uses that false price to borrow too much or withdraw more than allowed.
How do protocols defend?
Protocols cannot easily stop a transaction while it runs, so most defenses work before an attack happens. Teams use time-weighted average prices so a short price spike does not count. They also get audits and bug bounties. Emergency pause controls can stop a protocol if an exploit is spotted.
How is it different from a flash loan?
A flash loan is just capital that must be borrowed and repaid in one transaction. It is not an attack by itself. People use flash loans for legitimate DeFi actions. A flash loan attack is the exploit that uses that capital to harm a protocol.
Frequently asked questions
No. The loan and repayment happen in the same transaction, so the lender does not need collateral.
Sometimes. Pause controls and monitoring can halt a protocol, but an attack often runs inside one transaction and finishes in seconds.
The loan is not illegal, but using one to steal funds or manipulate a market can break fraud or market manipulation laws.
Recovery is not guaranteed. Some protocols have negotiated returns or traced funds, but attackers often move assets quickly.





