Flash Loans Drained $1.2 Billion in Four Years. The Mechanism Is Legal, Documented, and Working as Designed

CryptoShakti
By -
0

Key takeaways

  • A study reported this week puts losses from flash loan attacks at approximately $1.2 billion between 2020 and 2024.
  • A flash loan is not an exploit. It is a documented feature that lets anyone borrow a very large sum with no collateral, provided it is repaid within the same transaction.
  • The attacks do not break the loan - they use the borrowed capital to distort a price the target protocol relies on, then trade against that distortion.
  • Which makes this a price-source problem rather than a lending problem, and it is the same oracle question we have covered repeatedly.
  • Separately, the trust bank charter story has moved: reporting indicates Agora has received OCC approval and Rain is seeking a charter, while the banking industry's lawsuit over those charters continues.

A study reported this week puts losses from flash loan attacks at roughly $1.2 billion between 2020 and 2024.

That figure is worth sitting with, because the mechanism involved is not a vulnerability in the usual sense. Flash loans are a documented, intended feature. They work exactly as specified, and the attacks work because of that rather than in spite of it.

What a flash loan actually is

You can borrow an enormous sum - millions of dollars - with no collateral whatsoever, on one condition: you repay it before the same transaction finishes.

That sounds impossible until you remember how a blockchain transaction works. Everything inside a single transaction either all succeeds or all reverts. There is no partial state. So a lender can hand over any amount safely, because if the repayment is not there by the end, the entire transaction - including the loan itself - is erased as though it never happened.

The lender genuinely takes no credit risk. It is a clever piece of design, and it has legitimate uses: arbitrage between venues, refinancing a position, swapping collateral without unwinding first.

It also means that for the duration of one transaction, anybody at all can command the capital of a whale. That is the part that matters.

How the attacks work, and what they actually target

The attacks almost never target the lending protocol. They target something else entirely: the price a different protocol is using.

The pattern runs roughly like this. Borrow a very large sum. Use it to buy or sell aggressively in a market whose price some other protocol reads as truth. That heavy trading moves the price. The target protocol, reading the distorted price, now believes something is worth far more or far less than it is. Transact against that mistaken belief - borrow against inflated collateral, or liquidate a position that is not actually underwater. Repay the loan. Keep the difference.

All inside one transaction, with no capital at risk beyond fees.

Notice that nothing was hacked in the conventional sense. No key was stolen, no bug in the lender was triggered. Every step used the systems as documented. The failure was that a protocol trusted a price that could be moved cheaply.

So this is an oracle problem

We have raised this question repeatedly: what mechanism asserts an external fact to a contract, and how hard is it to make that mechanism lie?

Flash loan attacks are that question with a dollar figure attached. If a protocol derives a price from a single on-chain pool, that price is only as reliable as the cost of moving that pool. Flash loans reduce that cost to approximately nothing, because the attacker does not need to own the capital - only to borrow it for a few seconds.

The defences follow directly from understanding this, and they are well known. Use a time-weighted average price rather than a spot reading, so a single transaction cannot move it. Draw from several independent sources. Use an oracle with its own economic security rather than reading one pool. None of this is novel - which is why the $1.2 billion figure is a story about what got deployed rather than about what was knowable.

Why this matters more than the number

The reason to understand this one properly is that it is the clearest example of a pattern we keep returning to.

Composability - the ability of any protocol to call any other - is genuinely the most powerful property of this ecosystem. It is also the attack surface. A protocol can be impeccably written and still be broken by the behaviour of something it depends on, because it chose to trust a number that somebody else could move.

Which means reading an audit of one contract tells you less than you would hope. The question is not only whether this code is sound, but what it reads from, and what it would take to make that source wrong.

Elsewhere: the charter fight has moved

Following the lawsuit we covered, reporting indicates Agora has received OCC approval setting up a move to a US trust bank, and Rain is seeking a trust bank charter for stablecoin issuance.

So approvals are proceeding while the banking industry's challenge to the rule behind them is live. Both things are happening at once, which is normal and worth holding in mind: a granted charter is not a settled question while the authority to grant it is being litigated.

Reporting also indicates the US Treasury has dropped certain crypto surveillance proposals, and the UK has named six banks to lead a first digital gilt pilot. The direction in both cases is conventional institutions moving onto this infrastructure rather than away from it.

The market

Bitcoin is around $85,800, up roughly 0.6% over 24 hours and about 2.5% over the week. Ether is near $2,700. Total market capitalisation is approximately $2.93 trillion. The Fear and Greed Index reads 73, in its greed range. Current conditions only, with no claim about direction.

The point

$1.2 billion was taken using a feature that worked correctly every single time.

The lesson is not that flash loans are dangerous. It is that a protocol is only as sound as the least reliable number it trusts - and that is a question you can ask about anything you use, before anybody attacks it.

Frequently asked questions

What is a flash loan in plain terms?

Borrowing a large sum with no collateral, on condition that you repay it before the same blockchain transaction finishes. It works because a transaction either fully succeeds or fully reverts - if the repayment is not there at the end, the entire thing including the loan is erased. The lender genuinely takes no credit risk.

If flash loans enable $1.2 billion in attacks, why do they exist?

Because they are useful and the lending itself is not what fails. They allow arbitrage between venues, refinancing, and swapping collateral without unwinding a position first. The attacks do not break the loan - they use the borrowed capital to distort a price that some other protocol trusts.

So what is actually being exploited?

The price source. If a protocol reads a value from a single on-chain pool, that value is only as trustworthy as the cost of moving that pool. A flash loan makes moving it almost free, because the attacker borrows the capital for a few seconds rather than owning it. The target then transacts on a price that is briefly wrong.

How do protocols defend against this?

Use a time-weighted average price so no single transaction can shift it, draw from several independent sources, and use an oracle with its own economic security rather than reading one pool directly. These defences are well established, which is why the losses say more about what got deployed than about what was knowable.

Does an audit protect me from this?

Only partly. An audit assesses the contract's own code. A flash loan attack can break a correctly written contract by corrupting something it depends on. So the useful question extends beyond whether the code is sound to what it reads from, and how hard that source is to manipulate.

What is happening with the trust bank charters?

Reporting indicates Agora has received OCC approval and Rain is seeking a charter, while the banking industry's lawsuit challenging the rule behind those charters continues. Approvals and litigation are proceeding simultaneously - a granted charter is not a settled matter while the authority to grant it is being contested.


Not financial advice. Crypto assets are volatile and unregulated in many jurisdictions. In India, gains are taxed at 30% with 1% TDS on transfers. Do your own research and never invest money you cannot afford to lose.

Editorial note: Crypto Shakti uses an AI-assisted research and drafting workflow. Every article is grounded in the linked primary sources and live market data captured at publication time.

Post a Comment

0 Comments

Post a Comment (0)

#buttons=(Ok, Go it!) #days=(20)

Our website uses cookies to enhance your experience. Check Out
Ok, Go it!