What Is a Flash Loan in Crypto?
Borrow millions with zero collateral. Use it. Repay it. All within seconds.
Sounds like a glitch. Actually just math.
Why It's Possible
Blockchain transactions are atomic. Everything executes or nothing does. No in-between.
Flash loan uses this. Borrow from Aave. Do whatever. Repay in the same transaction. If repayment fails for any reason, entire transaction reverts. Borrow never happened. Funds back in the pool. Lender lost nothing.
Aave takes zero risk. Either gets repaid in the same block or the loan never existed. No collateral needed because there's literally no mechanism to keep the money without repaying it first.
Starting capital to execute a flash loan: enough for gas. That's it.
What Actually Gets Done With Them
Arbitrage. ETH at $3,000 on Uniswap, $3,018 on another DEX. Flash loan $5 million. Buy low, sell high, pocket spread, repay loan. Arbitrage that previously required institutional capital now executable by anyone who can write a smart contract. Keeps prices aligned across DeFi constantly. Actually useful.
Collateral swaps. ETH collateral in Aave, want USDC instead. Without flash loans: multiple transactions, multiple points of risk, capital required. With flash loan: one atomic transaction, done. Position restructured cleanly.
Self-liquidation. Position approaching liquidation threshold. Don't want to pay the penalty. Flash loan to repay own debt, withdraw collateral, repay flash loan. Exit without the liquidator taking a cut. Clever use that saves money.
The Exploit Playbook
Flash loans don't break protocols. Broken protocols get broken harder with flash loans.
Classic attack. Protocol reads price directly from AMM spot price. Bad idea but happens constantly. Attacker needs enormous capital to move that spot price meaningfully. Before flash loans: impractical. After: trivial.
Borrow $100 million. Dump into AMM. Price moves to absurd level. Exploit protocol at manipulated price. Repay loan. Keep profit. Transaction reverts if anything fails. Attacker risks gas fees only.
Theoretical attack requiring a hedge fund's capital became executable by anyone with a few hundred dollars in ETH for gas. That's the actual impact of flash loans on DeFi security. Not that they created new vulnerabilities. That they removed the capital barrier to exploiting existing ones.
Times It Went Very Wrong
bZx. February 2020. First one. $350,000. Felt small at the time. Proved the concept. Every protocol started auditing oracle implementations immediately after. Most didn't find their problems until someone else did.
PancakeBunny. May 2021. $45 million in minutes. Attacker flash loaned enormous BNB, inflated BUNNY price through the protocol's own mechanics, minted BUNNY at inflated price, dumped everything. BUNNY collapsed 95% before most users understood what happened.
Cream Finance. October 2021. $130 million. Third time Cream got hit actually. At some point the repeated exploits stop being bad luck.
Euler Finance. March 2023. $197 million. Largest hack of 2023. Attacker returned most funds later in a strange turn of events that still doesn't make complete sense. On-chain negotiations between protocol and anonymous attacker. Genuinely weird situation.
Why Banning Flash Loans Doesn't Work
Protocols can't detect them. Flash loan capital looks identical to whale capital during transaction execution. By the time a protocol's function runs the funds are already there. No way to check the source.
Defense has to be in the logic. Time-weighted average prices instead of spot prices. Circuit breakers on large price movements. Better liquidation mechanics. None of that involves touching flash loans at all.
Protocols that got exploited via flash loans mostly had oracle problems they would have had regardless. Flash loans just made exploiting those problems accessible to everyone instead of just people with nine figure bankrolls.
