Skip to content

Deep dive · Hacks & Collapses · 9 min

DeFi’s Greatest Exploits: Flash Loans, Oracles & Reentrancy

bZx, Cream, Beanstalk, Euler — a tour of the recurring bug classes that have drained billions from decentralized finance.

On this page
Why this matters

Decentralized finance is the most-hacked category in crypto after bridges. But unlike exchange collapses (Mt. Gox, FTX) or stablecoin failures (Terra), most DeFi exploits are not fraud — they're bugs. And across hundreds of incidents, the same handful of bug classes recur: , , , and math errors. Understanding the bug classes is the only way to read the next exploit headline without re-learning the whole story.

The bug classes, in plain English

Almost every DeFi exploit collapses into one of four recurring problems. Once you know them, you can read most incident reports without new vocabulary.

1. Oracle manipulation

A lending or derivatives protocol needs to know the price of an asset. If it reads that price from a thin on-chain pool, an attacker can borrow money, use it to push the pool's price wildly off, borrow against the now-overvalued collateral at a different protocol that trusts the manipulated price, and walk away with the difference. The first celebrated instance was bZx in February 2020.

The fix is to use a robust or a decentralized like Chainlink that aggregates prices over time and across sources. But every protocol that integrates with another protocol inherits its oracle assumptions, and bugs survive by being re-implemented.

2. Reentrancy

is the oldest bug in DeFi — it's what drained The DAO in 2016 (see the DAO Hack deep dive). The pattern: a vulnerable contract calls out to an external address (often a token or the attacker's own contract) and updates its state only after that call returns. The external contract calls back into the original before the state is updated, “re-entering” the function and withdrawing again.

Despite being famous for a decade, reentrancy still causes major losses — the checks-effects-interactions pattern and reentrancy guards (mutexes) are well known, but composability means a protocol can re-introduce a reentrancy bug through a new token or a callback it didn't realize it had.

3. Flash-loan governance takeovers

A lets a user borrow tens of millions of dollars with no collateral, as long as the loan is repaid in the same transaction. Originally a useful arbitrage tool, flash loans became an attack vector when protocols let governance tokens control critical functions with little timelock.

The canonical example is Beanstalk in April 2022: the attacker flash-borrowed enough tokens to acquire a majority of Beanstalk's governance token, passed a malicious proposal in the same transaction that drained $182M, and repaid the flash loan — all in one block. The fix is governance timelocks: proposals must wait before they can execute, so flash-borrowed votes can't be acted on instantly.

4. Math and rounding errors

Smart contracts do integer math. Overflow/underflow, rounding in the wrong direction, and missing fee-on-transfer deductions have all caused six- and seven-figure losses. Solidity 0.8 added built-in overflow checks (so this class is rarer than it was), but rounding-direction bugs in math and donation-based collateral-value manipulation (as in Euler) still surface.

The timeline

Tap any event to expand its story.

Cross-cutting patterns: why the same bugs recur

Several structural features of DeFi explain why the same four bug classes keep appearing:

  • Composability — protocols call protocols that call protocols. A safe protocol can become unsafe when a new integration is added, because the new integration may have assumptions the original didn't account for.
  • Permissionless deployment — anyone can deploy a contract. Audits are voluntary and uneven; many exploits hit contracts that were never audited or that were re-deployed with changes after an audit.
  • Real value at stake, immediately — a bug in a smart contract is exploitable by anyone, the moment the contract is deployed with funds. There is no “we'll patch it tonight.”
  • Bridges amplify everything — a DeFi bug on a single chain is bounded by that chain's liquidity; a bridge bug can drain assets across chains. See the Bridge Hacks deep dive.
How to read an exploit headline

When the next “$X drained from Protocol Y” post-mortem appears, ask four questions in order: (1) Was the price trusted? If the protocol read a price from a single thin pool, it's oracle manipulation. (2) Was state updated after an external call? Then it's reentrancy. (3) Did the attacker vote? If they flash-borrowed tokens to win a governance vote, it's a flash-loan governance takeover. (4) Otherwise, look at the math. Most remaining exploits are rounding, overflow, or fee-handling errors. These four questions explain the great majority of post-mortems.

The limits of audits

Audits are valuable but not sufficient. A protocol can be audited and still be exploited — because the audit was on a different version, because the bug was in an integration added later, or because the audit was scoped narrowly. The credible defense today is defense in depth: audits from multiple firms, an active bug bounty (sometimes larger than the contract's TVL), real-time monitoring, an emergency pause mechanism, and — increasingly — formal verification of the critical math. Even with all of these, exploits happen. The honest summary is that DeFi remains an experimental financial system, and its security model is still being invented.

For the broader risk framework — how to think about smart-contract risk, protocol risk, and systemic risk in DeFi — see the Risk module and the DeFi module.

Key takeaways

  • Most DeFi exploits are bugs, not fraud. The same handful of bug classes recur: oracle manipulation, reentrancy, flash-loan governance takeovers, and math/rounding errors.
  • Oracle manipulation (bZx 2020, Cream 2021) exploits a protocol that trusts a thin on-chain price; the fix is robust oracles and TWAPs.
  • Reentrancy (the DAO Hack onward) exploits state-updated-after-call; the fix is checks-effects-interactions and reentrancy guards.
  • Flash-loan governance takeovers (Beanstalk 2022) exploit governance with no timelock; the fix is to require a delay before proposals can execute.
  • Composability, permissionless deployment, and immediate value-at-stake explain why these bugs recur. Audits help but are not sufficient — the credible defense is layered: multiple audits, large bug bounties, monitoring, and a pause mechanism. See the Risk module for the full framework.
Educational only, not financial or legal advice.