← back to the blog

Bitcoin Explained · May 28, 2026

By Adam Whistler

What Is a Flash Loan? Millions With No Collateral

Fast moving lights representing rapid transactions

Walk into a bank and ask to borrow a million dollars with no collateral, no credit check, and no paperwork, and you'll be shown the door. Ask a DeFi lending protocol for the same thing and it might actually say yes, on one condition: you have to pay every cent back before the transaction finishes, all within a few seconds. That's a flash loan, and it has no real equivalent anywhere in traditional finance, because it depends on a property only a blockchain has.

The property that makes it possible

Every blockchain transaction is atomic, meaning it either completes entirely or it doesn't happen at all, there's no in-between state where part of it succeeded. A flash loan exploits that directly: a lending protocol sends you the requested funds, your own smart contract does whatever you programmed it to do with that money, and then, before the transaction ends, the protocol checks whether its funds plus a small fee actually came back. If they did, the transaction confirms and the loan is recorded as having happened successfully. If they didn't, the entire transaction reverts, as if none of it ever occurred, no money moved, no loan was ever technically issued, and the only thing you actually lose is the gas fee spent attempting it. That single design choice is what makes lending millions to a stranger with zero collateral rational for the lender, there's no real-world scenario where it walks away holding a loss on the principal.

Where it actually came from

The term first showed up in Marble Protocol's 2018 design for what it called a smart contract bank, a proposal for atomic uncollateralized loans on Ethereum that stayed mostly theoretical. Flash loans went mainstream once Aave built them directly into its lending protocol, and they've grown enormously since, Aave alone processed over $7.5 billion in flash loan volume during 2025 and crossed $1 trillion in cumulative all-time flash loan volume by February 2026. Balancer and Uniswap offer versions of the same mechanic through their own liquidity pools. Fees are typically small, Aave charges around 0.05% of the borrowed amount, since the lender's actual risk is close to zero and the fee mostly exists to compensate liquidity providers for the pool being used at all.

What people actually use them for

How the same tool becomes a weapon

Flash loans have also funded some of DeFi's largest exploits, but the mechanism is usually more precise than "flash loans are dangerous." In most real attacks, the loan itself just supplies temporary scale, the actual vulnerability is somewhere else entirely: an oracle that trusts a price it can read directly from a small, easily manipulated liquidity pool rather than a more resistant, aggregated price feed, a flawed accounting function, or a missing check somewhere in a protocol's logic. The March 2023 Euler Finance exploit is a clear example, an attacker used an Aave flash loan to assemble capital quickly, but the real flaw was in a piece of Euler's own code that mishandled debt-collateral accounting under specific conditions the flash loan simply made possible to reach. Security researchers who've studied these cases closely tend to describe the more precise phrase as "flash-loan-enabled oracle manipulation" rather than blaming the loan mechanism on its own, since the same exploit logic, without the flash loan, would just require an attacker to show up with real capital instead of borrowed capital, the vulnerability would still be there either way.

The private key for every Bitcoin wallet on Earth is on this website, even Satoshi's. But even if you try for a million years, you'll never find a funded one.

Try the key collider now

How protocols actually defend against this now

The defense playbook has matured a lot since the earliest incidents. Most established lending protocols now pull prices from oracles built specifically to resist single-block manipulation, Chainlink's aggregated price feeds and time-weighted average prices, TWAPs, being the two most common, both designed so a single flash-loan-sized trade in one block can't meaningfully move the price the protocol actually reads. Circuit breakers that pause a protocol automatically when unusual activity gets detected, along with more rigorous audit cycles before launch, have made top-tier platforms considerably harder to exploit than they were a few years ago. Most successful flash loan attacks in 2025 targeted smaller, newer protocols with weaker security rather than established platforms like Aave or Compound, a sign the defensive tooling that exists actually works when it gets properly implemented, the gap now sits mostly with newer, less battle-tested code rather than the flash loan primitive itself.

A worked example, start to finish

Say a stablecoin trades at $0.97 on a small, thinly traded pool while every other market has it correctly priced near $1.00. An attacker's contract borrows 1,000,000 USDC from Aave in a flash loan, dumps a large chunk of it into the small pool to push the stablecoin's price down even further, then interacts with a separate lending protocol that, mistakenly, reads its collateral value directly from that same distorted pool rather than a more resistant price source. Because the protocol now thinks the stablecoin is worth far less than it actually is, positions that shouldn't be liquidatable suddenly look undercollateralized, and the attacker triggers liquidations at an artificial discount, buying real collateral for a fraction of its actual value. The attacker then reverses the initial trade to restore the price, repays the 1,000,000 USDC flash loan plus its small fee, and keeps whatever profit is left over, all inside a single transaction that started and ended in the same few seconds. Nothing about that sequence required the attacker to personally own any capital at all beyond the gas fee, the flash loan supplied all of it.

The uncomfortable part: it's rarely actually illegal to try

Because flash loans and price arbitrage are legitimate financial activity in their own right, and because DeFi protocols are open, permissionless systems anyone can interact with, there's often a blurry line between an aggressive but legal arbitrage strategy and an exploit that crosses into fraud. Some high-profile cases have ended with attackers returning most of the stolen funds voluntarily, sometimes in exchange for being allowed to keep a "bug bounty" style portion as a reward for exposing the flaw rather than facing prosecution, an outcome that's become common enough in DeFi that it has its own informal name, a "whitehat rescue." Other cases have ended in criminal charges once investigators established clear intent to defraud rather than simply exploit a public, permissionless system exactly as it was coded to work. Where any specific incident lands on that spectrum usually comes down to intent and what happened to the funds afterward, not the mechanics of the flash loan itself.

Is using one actually illegal?

No, not on its own. A flash loan is a neutral financial tool, the same way a kitchen knife is neutral regardless of what someone does with it afterward. Using one for arbitrage, collateral management, or debt refinancing is entirely legitimate and exactly what the feature was built for. Using one specifically to manipulate a protocol's accounting or steal funds is fraud or theft, and several attackers have faced real legal consequences for exploits built this way, the flash loan itself was never the crime, what was done with it was. The tooling to actually build one has gotten dramatically more accessible too, drag and drop platforms now let non-programmers assemble a borrow, swap, and repay sequence visually rather than writing custom Solidity, lowering the barrier to legitimate use considerably while, inevitably, doing the same for the attack side of the equation. For the smart contract layer that makes any of this enforceable and, in the wrong circumstances, exploitable, see what a smart contract actually does, and for the broader DeFi ecosystem flash loans operate inside, see what DeFi actually is.