A flash loan is a loan that must be borrowed and repaid within the same blockchain transaction. If the repayment doesn't happen, the transaction reverts as if it never occurred. This makes uncollateralized borrowing safe for the lender.
How it works
- Your contract calls Aave: "lend me 10,000 ETH."
- Aave sends 10,000 ETH to your contract.
- Your contract does whatever it wants with the ETH.
- Before the transaction ends, your contract must repay 10,000 ETH + a small fee (0.09% on Aave).
- If not, the whole transaction reverts. Aave never lost anything.
Legitimate uses
- Arbitrage. ETH/USDC price differs on Uniswap vs Sushi. Flash-loan USDC, buy on Uniswap, sell on Sushi, repay, keep the difference.
- Liquidations. Aave position went underwater. Flash-loan the debt token, liquidate, receive collateral at discount, repay loan.
- Collateral swap. Have ETH-backed loan, want to swap collateral to wBTC without repaying full loan. Flash-loan handles the atomic swap.
- Debt refinancing. Move debt from Aave to Compound (or vice versa) if rates diverge, atomically.
Exploit uses
Flash loans have powered many DeFi exploits by amplifying position size. Common pattern: borrow $100M, manipulate an oracle-dependent price, exploit a pool that trusts the manipulated oracle, repay loan. Attacker walks with $10-30M profit.
bZx, Harvest Finance, Yearn, Cream Finance, Beanstalk all suffered flash-loan-amplified exploits.
Where the risk actually lives
Flash loans themselves are safe. The risk is protocols that use manipulable oracles or that assume no attacker has $50M of temporary capital. Every DeFi protocol should stress-test for flash-loan attack scenarios.
Koinlytics