BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

Opinion: The essence of the flash loan attack is actually an Oracle attack?

拔丝地瓜
特邀专栏作者
This article is about 1946 words, reading the full article takes about 3 minutes
The novelty of flash loans is that they can temporarily make anyone in the world a very well-funded trader, with the potential to suddenly manipulate the market.
AI Summary
Expand
The novelty of flash loans is that they can temporarily make anyone in the world a very well-funded trader, with the potential to suddenly manipulate the market.

Editor's Note: This article comes fromCrypto Valley Live (ID: cryptovalley)Editor's Note: This article comes from

Crypto Valley Live (ID: cryptovalley)

Crypto Valley Live (ID: cryptovalley)

, Author: Adelyn Zhou, translation: Olivia, reproduced by Odaily with authorization.

Since the start of the year, the decentralized finance (DeFi) ecosystem has grown rapidly to over $12 billion in total value locked. With this exponential growth, the incentive for malicious actors to manipulate and attack vulnerable DeFi protocols increases, often at the expense of ordinary users."One of the tools that has been used in many DeFi attacks recently is the Flash Loan - a new type of financial primitive that allows users to open unsecured loans with the only stipulation that the loan must be repaid in the same block, otherwise will be withdrawn. This is very different from traditional DeFi loans, which often require users to over-collateralize the loan in the early stage."When flash loans are used as part of a malicious scheme to manipulate the protocol and steal funds,

but"Flash loan attack"The term will be the trending crypto term of the week. Media organizations and Twitter’s big V are all concerned about the operation of flash loans, analyzing every step that malicious actors jump from one Token to another Token and from one protocol to another protocol in a transaction."but"Flash loan attack

That word doesn't capture the whole of the problem. Flash loans do not create vulnerabilities within DeFi - they just reveal vulnerabilities that already exist.

Flash loan attack

For bystanders watching the attack take place, there is something fascinating about flash loans. The idea that anyone can suddenly control vast sums of money and configure it in novel and even malicious ways demonstrates how this technology can empower individuals and unlock entirely new financial tools. Instead of analyzing the ultimate function and goals of Flash Loans, we marvel at the ingenuity of its creators and the sophistication of its attacks. As a result, flash loans are increasingly being characterized as a dangerous DeFi innovation.

As Marc Zeller of DeFi protocol Aave puts it, flash loans are just a tool: they allow you to act like a whale during a transaction. Any attack performed via flash loans can also be performed without flash loans by well-funded holders. What a flash loan can do is temporarily make anyone in the world a well-capitalized holder, because there are no permits required to obtain a flash loan, and there are no pre-collateral requirements.

Of course, having such funding publicly available greatly increases the number of people who can carry out such an attack. But even in a world without flash loans, the adoption of more blockchain technology will continue to provide us with faster access and access to more liquidity.

secondary title

Focus on the problem

We need to pay attention to what these malicious actors are doing with their newfound funds. A clear pattern has emerged: malicious parties using flash loans to manipulate DeFi protocols that rely on a single decentralized exchange (DEX) as the protocol’s only price oracle. They used flash loans to manipulate and distort the price of one or more assets on a DEX, resulting in inaccurate price data being provided to DeFi applications using this DEX-based price oracle.

Malicious attackers then take advantage of the opportunity to generate profits at the direct expense of ordinary users. In obsessing over the specific tools used in the exploit, our industry is ignoring the real lesson of these attacks: DeFi protocols that rely on price oracles sourcing data from a single trading venue can be compromised by participants with large sums of money."These are oracle attacks whose attack vectors have not only been predicted but have occurred before. The focus on flash loans has distracted us from the larger problem that DeFi protocols with hundreds of millions and sometimes as much as $1 billion in TVL still rely on price feed oracles from a single exchange. As we have seen, a single exchange can be subject to all kinds of volume changes and whale manipulation. For another protocol that relies on centralized price feeds, the consequences are clear."Today, many of TVL's top DeFi dApps use the decentralized oracle network to asynchronously calculate the transaction volume and liquidity differences of multiple exchanges in multiple different transactions, which makes them insensitive to the manipulation of flash loan funds . As more and more users are attracted by the financial convenience and opportunities of this ecosystem and DeFi protocols absorb more and more value from the global market, it is the responsibility of the maintainers of these protocols to adopt decentralized oracle solutions , to protect users from currently known and preventable attacks.

安全
投资
Welcome to Join Odaily Official Community