Free tools Windows power users keep installed
One-click scans. No signup required.
A flash loan is not a vulnerability by itself. It lets a user borrow a large amount without ordinary collateral if the loan and required fee are repaid within the same transaction. Attacks happen when that temporary capital exposes or amplifies a weakness in another protocol—for example, a price source that can be manipulated, governance rules that accept temporary voting power, or accounting logic that mishandles a rapid sequence of actions.
What a flash loan does—and what makes an attack possible
A flash loan makes borrowing conditional on repayment before the transaction ends. In the ERC-3156 pattern, for example, a lender transfers the assets, calls the borrower’s callback, and checks for repayment and the required fee. If the required repayment does not occur, the transaction fails rather than leaving the loan outstanding. The precise interface and conditions depend on the implementation.
This atomic structure has legitimate uses, including arbitrage, collateral swaps, and refinancing. It also lets a user temporarily control substantial funds and combine several protocol interactions before the transaction either completes or reverts. The security question is not simply whether flash loans are available; it is what protocol state that temporary capital can change, and whether another action can consume the changed state before the transaction finishes.
How flash-loan attacks work
A common attack pattern is to borrow, alter a market or protocol state, use the altered state to extract value, and repay before the transaction completes. The borrowed capital is an amplifier. The exploitable weakness is the target protocol’s assumption about prices, voting power, balances, or accounting.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute#1 Best Overall
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Enjoy Bluetooth connectivity, iOS access, and hours of battery use with this mobile-first, secure backup signer. Freedom you can depend on.
- Genuine Check: confirm your signer is authentic during setup with the Ledger Wallet app.
- Protect your signer: keep it in mint condition at all times with a bespoke Pod or Case to avoid scratches and everyday wear and tear.
| Attack path | What the attacker changes | What can go wrong |
|---|---|---|
| Price or oracle manipulation | A large temporary trade moves the price in a shallow or otherwise manipulable market. | A protocol relying on that spot price may overvalue collateral or miscalculate a position, enabling excess borrowing, withdrawal, or another value transfer. |
| Governance voting | Temporary access to tokens changes voting power, if the rules count it at the relevant point. | A proposal may receive influence it would not have had from durable holders. The risk depends on how proposal, voting, delay, and execution stages are separated. |
| Accounting or contract logic | A rapid sequence of deposits, trades, donations, borrowing, or calls changes balances or internal accounting. | Vault shares, lending positions, token valuations, or cross-protocol calculations may rely on assumptions that fail during the sequence. |
Oracle manipulation is a prominent route, but an oracle-only review is incomplete. OWASP’s SC04:2026 Flash Loan–Facilitated Attacks describes the broader attack surface across lending, automated market makers, vaults, token valuation, governance, and inter-contract logic.
Price manipulation in practice
If a protocol treats a pool’s current spot price as the value of collateral, an attacker may use borrowed assets to move that price and then borrow against the artificially inflated collateral value. A shallow market generally takes less capital to move than a deep one. The important question is whether the price observed by the protocol can be pushed far enough, for long enough, to change a consequential action within the same transaction.
Rank #2
- Proven security at scale: Over 9 years and millions of cards issued with no known remote hacks, while military‑grade EAL6+ security keeps your private keys locked inside the chip. Your cryptocurrencies stay strongly protected from online attackers.
- Tap once to manage your entire crypto wallet across 90 blockchains - no USB cables or Bluetooth, no batteries, no setup. Access 14,100+ coins & tokens, DeFi, NFTs, and staking instantly from your phone
- Smart backup: Use your second Tangem Wallet as your Backup keys with end‑to‑end encryption; no more papers, pictures. If one card is lost, the remaining can still restore full access, with an optional seed phrase available for advanced users.
- Engineered to last up to 25 years: Waterproof (IP69K), shockproof and tested for extreme temperatures from −25°C to 50°C. A durable cold wallet with long‑term protection and independently audited security.
- Trusted by 6 million users worldwide - buy, sell, swap, stake, and spend cryptocurrency directly. The secure offline storage wallet designed for how people actually use crypto wallets
Governance and accounting paths
For governance, inspect when voting power is measured and whether a token balance acquired temporarily can count. A proposal process with distinct proposal, voting, timelock, and execution stages can make same-transaction influence harder to turn immediately into an executed change; the exact protection depends on the rules and implementation.
For accounting, trace the full sequence rather than checking each function in isolation. A deposit, donation, share calculation, borrow, and withdrawal may each appear valid alone but interact unsafely. The same principle applies across contract calls: determine whether temporary balances or state changes can affect a later calculation before they normalize.
Rank #3
- Secure Element Protection: EAL6+ certified secure element with passphrase protection provides robust physical security for your digital assets
- User-Friendly Interface: Two-button pad device interface designed for straightforward and intuitive operation
- Bright OLED Display: Clear and bright OLED screen enables easy and secure hands-on verification of transactions
- On-Device Security Features: PIN and passphrase protection enabled directly on the device for enhanced security
- Open-Source Transparency: Fully open-source design allows for transparent security verification and community auditing
How to assess a protocol’s flash-loan risk
Assess the entire path from a state change to value extraction. For each item below, inspect the relevant contracts and protocol documentation; do not treat a reassuring feature name or audit badge as proof of safety.
| Area | Questions to answer | Risk signal to investigate |
|---|---|---|
| Price sources and market depth | Which prices drive collateral valuation, borrowing, liquidation, minting, or withdrawal? Are they based on one pool or spot observation? How deep is that market, what observation window is used, and are independent sources combined? | A consequential decision depends on a single, thin, easily moved market or a very recent price. |
| Atomic state changes | Can one transaction move a price, deposit or donate assets, alter share accounting, borrow against the result, and withdraw before conditions normalize? What happens with unusually large temporary balances and inter-contract calls? | Functions are reviewed separately but not tested as a sequence, or a temporary balance is treated as durable value. |
| Governance | How is voting power counted? When can a proposal be made, voted on, delayed, and executed? Can temporarily acquired tokens affect a vote or trigger an immediate action? | Voting power can be borrowed for the relevant snapshot and execution can follow without a meaningful separation. |
| Lending exposure | What are the loan-to-value (LTV) ratios and liquidation thresholds? How are assets onboarded, and how much can be borrowed against volatile or thinly traded collateral? | Large borrowing capacity is available against collateral whose valuation or liquidity may fail under stress. |
| Audit coverage | Which contracts and versions were in scope? What findings were reported, and were they addressed? Does the review cover integrations and relevant attack sequences? | A general audit claim is offered without scope, findings, remediation status, or coverage of the deployed code. |
| Operations | Who can upgrade contracts or intervene? How are keys held and multisigs configured? What monitoring, alerting, and incident-response procedures exist? | Critical permissions or response plans are unclear, concentrated, or untested. |
Aave’s risk documentation identifies LTV and liquidation thresholds as protocol risk parameters; their values and effects should be assessed for the specific assets and deployment rather than treated as universal settings. OpenZeppelin’s Four Layers of DeFi Risk: A Security Framework for Financial Institutions also emphasizes that code audits do not cover every operational risk. Review findings and controls alongside the code, not instead of it.
Rank #4
- UNPARALLELED SECURITY: Protect your assets with Trezor Safe 5's NDA-free EAL 6+ Secure Element, offering robust defense and complete transparency.
- EFFORTLESS NAVIGATION: Experience seamless crypto management with the vibrant color touchscreen, designed for intuitive and user-friendly interactions.
- ENHANCED USER EXPERIENCE: Enjoy tactile confirmation with Trezor Touch Haptic Engine, making each interaction precise and engaging.
- SUPPORTS 1000s OF COINS & TOKENS: Securely handle thousands of assets, including Bitcoin, Ethereum, and more, all in one wallet.
- EASY ASSET MANAGEMENT: Monitor and transact seamlessly with Trezor Suite, our user-friendly desktop and mobile app
Which defenses help, and where they stop
Use price observations that are harder to move briefly
Ethereum.org’s smart-contract security guidance recommends decentralized oracle networks drawing on multiple sources and discusses time-weighted average prices (TWAPs). Its guidance states: “Choosing longer time periods protects your protocol against price manipulation since large orders executed recently cannot impact asset prices.” A longer observation window can reduce the influence of a recent large trade, while multiple sources can reduce dependence on one market. Neither approach guarantees safety: implementation, liquidity, observation windows, and protocol integration all matter.
Limit exposure and separate sensitive actions
LTV limits and liquidation thresholds can constrain how much value is available against risky collateral. Governance procedures that separate voting from execution can constrain the immediate effect of temporary voting power. These measures reduce particular exposures; they do not repair incorrect accounting or make a manipulable price source reliable.
Best Value
- All your digital assets in one place. You can manage thousands of crypto including Bitcoin, Ethereum, Solana, Tether and more.
- Defend your identity against hackers: secure your online accounts with passwordless, hardware backed, 2FA logins for all your favorite apps and websites.
- Connectivity: USB-C cable connection only. No Bluetooth.Compatible with the Ledger Wallet crypto app, both desktop (Windows, macOS, Linux) and mobile (Android only). Not compatible with iOS.
- Protect your digital assets with the industry's best security: keep your private keys offline in your private signer, battle-tested by the Donjon's white hat hackers, CC EAL 6+ certified Secure Element, constantly updated Ledger OS.
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
Pair code review with operational controls
Audits provide evidence about the code and scope that reviewers examined. They are not proof that a protocol is safe, especially if the deployed version, integrations, or operational controls differ from what was reviewed. Monitoring, clear upgrade permissions, secure key custody, and an incident-response plan address risks that a code review alone cannot eliminate.
What published figures do—and do not—show
A 2025 joint report by the European Banking Authority and European Securities and Markets Authority estimates that approximately 20% of value theft from DeFi protocols corresponds to flash-loan attacks. This is the report’s approximate attribution, not a timeless rate or a prediction for an individual protocol.
A 2025 Bank of Canada staff discussion paper reports over US$2 trillion in flash-loan lending activity on EVM-compatible blockchains in 2024. That figure describes lending activity, not attack losses; it also illustrates why flash loans should not be equated with malicious use.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

