The loan that borrows and repays itself in twelve seconds
Zero collateral. Zero risk to the lender. And somehow, a billion dollars in losses.
$0 collateral. $200 million borrowed. One Ethereum block — roughly 12 seconds. The loan existed and vanished before most people finished reading this sentence. I wanted to understand where that money actually comes from, so I walked through a flash loan line by line, the way you’d take apart a cheap radio to see which wire is hot.
The thing that surprised me is not how clever flash loans are. It’s how boring they are once you see the trick. A flash loan is not magic money, and it’s not a hack. It’s a power tool — and like every power tool, it does exactly what the person holding it points it at.
Borrow $X with no collateral → swap it through some trades → repay $X + fee → keep whatever is left
The one rule that makes it work
A normal loan has three moving parts: the collateral you put up, the interest you pay, and the time the lender is exposed. Take any of those away and a bank will show you the door. A flash loan deletes all three at once by changing one assumption: the loan must be repaid in the same transaction that created it.
Here’s the part that bends your head the first time. On Ethereum, a transaction is atomic — either every step inside it succeeds, or the whole thing unwinds as if it never happened. So the lender can write:
> “Here is $200 million. Do whatever you want. If I don’t get $200 million plus a 0.09% fee back by the end of this transaction, the entire transaction reverts and none of this ever happened.”
The lender cannot lose. If you can’t repay, the network rolls the whole sequence back, and the money was never actually out of the vault. That atomicity is the entire trick. It’s not that the risk disappeared — it’s that the risk got compressed into a single block, so the lender is exposed for about 12 seconds of programmatic time instead of 12 months.

Let me actually run one
I’ll pick the simplest real example: a price gap between two decentralized exchanges. Say ETH trades at $2,000 on Uniswap and $2,020 on SushiSwap. That’s a 1% gap — too small to bother with if you had to put up your own money, but if you can borrow for free, it’s pure spread.
- Borrow 100 ETH from Aave’s flash pool. No collateral.
- Sell all 100 ETH on SushiSwap for ~$202,000.
- Buy back ~101 ETH on Uniswap for ~$202,000.
- Repay the 100 ETH plus the 0.09% fee — 100.09 ETH.
- Keep the ~0.9 ETH difference. About $1,800. Gas aside.
Notice something uncomfortable: the “borrower” is a bot, not a person. The moment that 1% gap opens, dozens of automated accounts race to eat it. Flash loan arbitrage is a game of milliseconds and gas bidding, and the profit goes to whoever gets their transaction in first. This is also why I don’t want you to read this and go try it — the easy money was automated out of existence years ago.
$1B+
estimated total drained across major flash-loan attacks since 2020
The three things people actually use it for
Arbitrage is the one everyone talks about, but it’s the least interesting. The genuinely useful stuff is boring bookkeeping:
- Collateral swaps. You have a loan backed by ETH, you want it backed by USDC. Instead of unwinding and redoing everything (three transactions, three gas bills, exposure in between), a flash loan does the whole swap in one atomic step.
- Self-liquidation. Your position is about to be liquidated, and a third party is about to collect the penalty. You can flash-borrow, repay your own debt, pull your collateral, and repay the flash loan — keeping the liquidation bonus for yourself.
- Debt refinancing. Rates moved and a cheaper protocol is on the other side of town. Flash loan walks your debt across the street in one block.
None of these require trusting anyone, and none of them lose the lender a cent. This is why the primitive stuck around after the 2020 hype died.
Now the part everyone actually remembers
Because here’s the awkward question: if the lender can’t lose, where did the $1 billion go?
- 1
Borrow
Take $200M from Aave with zero collateral. Nothing suspicious yet — it’s a legal primitive.
- 2
Aim
Point the borrowed capital at a target protocol’s weak spot — usually a price feed it trusts blindly.
- 3
Distort
Dump or pump a token to bend that price feed to an extreme value in a single block.
- 4
Exploit
The target now thinks your junk collateral is worth a fortune, and lets you withdraw against it.
- 5
Repay
Return the $200M plus 0.09%. The loan is clean. The books balance.
- 6
Vanish
Walk away with the difference, which came out of the target’s vault, not the lender’s.
Read that sequence again and tell me who the victim is. It’s never the lender. The flash loan is the getaway car, not the robbery. It gives an attacker leverage — a hundred million dollars of temporary muscle to shove a price around — but the actual wound is in the protocol that believed a fake price.

The roster reads like a lowlight reel of the entire DeFi era:
| Attack | Year | Rough loss | The weak point |
|---|---|---|---|
| bZx | 2020 | ~$1M | Oracle manipulated in one block |
| Harvest Finance | 2020 | ~$24M | Curve pool price bent |
| PancakeBunny | 2021 | ~$45M | Single AMM price feed |
| Cream Finance | 2021 | ~$130M | Flash-loan price manipulation |
| Mango Markets | 2022 | ~$116M | Pumped MNGO collateral |
| Beanstalk | 2022 | ~$182M | Bought the governance vote |
| Euler Finance | 2023 | ~$197M | donateToReserves bug, later returned |
Two of those deserve a second look, because they show the tool is neutral. Mango Markets wasn’t a bug — Avraham Eisenberg bought enough of the governance token with a flash loan to vote himself the whole treasury. Beanstalk did the same thing on a bigger scale. In both cases the code worked exactly as written. The vulnerability was the assumption that a voting majority can’t be rented for 12 seconds.
And Euler — the biggest number on the board — wasn’t even a price oracle. It was a plain accounting bug in a donateToReserves function, and the attacker eventually gave almost all of it back. The flash loan just let one person afford to find the bug.
So what’s the honest verdict?
I came in expecting to write “flash loans are dangerous.” I’m leaving with something more precise: a flash loan is a force multiplier, not a cause. It converts a small bug into a nine-figure theft, and it converts a 1% price gap into an instant profit. But in every single case, something was already broken before the loan showed up.
The fix was never to ban flash loans — you can’t, the network doesn’t know the difference between an arbitrage bot and an attacker. The fix was to make protocols stop believing single-block price reads: time-weighted averages, multi-source oracles, governance time-locks, reentrancy guards. The tool stayed; the targets got harder to hit.
There’s an old line that belongs here, and I’ll close with it because it’s the only honest summary: there’s no such thing as a free lunch. The loan was free. The lunch was paid for by whoever left a vault unlocked.
- If you see “flash loan attack,” read it as “flash-loan amplified attack” — the loan named the weapon, not the crime.
- Don’t try to run flash-loan arbitrage yourself. It’s a millisecond arms race against bots you can’t outbid.
- If you build anything in DeFi, assume every price you read can be bent inside one block, and design for that.
(The End)






