Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Flash Loan Attacks

ASecurity

Detect vulnerability to flash-loan-funded attacks — governance manipulation, price manipulation, collateral inflation, vault donation attacks. Activate when reviewing AMMs, lending protocols, governors, ERC-4626 vaults, staking with voting power, or any system whose state depends on its own balance.

36 stars
0 votes
0 copies
0 views
Added 10/4/2026
blockchainrustgo

Security Analysis

A100/100

Scanned 10/4/2026

$npx -y skills add iktok90-design/ai-smart-contract-auditor --skill flash-loan-attacks --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Flash Loan Attacks?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Flash Loan Attacks
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/iktok90-design-flash-loan-attacks/badge)](https://www.skillsdirectory.com/skills/iktok90-design-flash-loan-attacks)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: flash-loan-attacks
description: Detect vulnerability to flash-loan-funded attacks — governance manipulation, price manipulation, collateral inflation, vault donation attacks. Activate when reviewing AMMs, lending protocols, governors, ERC-4626 vaults, staking with voting power, or any system whose state depends on its own balance.
---

# Flash-loan attack detection

## When this applies

- AMMs, lending markets, ERC-4626 vaults, staking with voting power
- Governance using `getVotes` or `balanceOf` at the moment of vote-casting
- Liquidations / collateral health checks that use spot price
- Reward distributions proportional to balance held at a snapshot
- Any protocol whose state depends on its own `address(this).balance` or token balance

## Detection patterns

### Governance flash-loan voting (CRITICAL)
```solidity
function castVote(uint256 propId) external {
    uint256 power = token.balanceOf(msg.sender);   // ← spot balance
    proposals[propId].votes += power;
}
```
Fix: snapshot at `proposalCreated` via `ERC20Votes` checkpoints + sufficient voting delay.

### Vault donation / inflation attack (CRITICAL on ERC-4626)
First depositor mints 1 share, attacker sends huge `transfer` directly to vault → share price inflates → subsequent depositor's small deposit rounds to 0 shares.
```solidity
// vulnerable mint math
shares = assets * totalSupply / totalAssets;   // ← totalAssets manipulable by direct transfer
```
Fix: virtual shares + virtual assets (OpenZeppelin v4.9+ ERC4626), or dead-shares pattern, or minimum first deposit.

### Spot-price collateral check (CRITICAL)
```solidity
function isHealthy(address user) public view returns (bool) {
    uint256 collateralValue = oracle.spotPrice() * collat[user];   // ← spot
    return collateralValue >= debt[user] * MIN_RATIO;
}
```
Flash-loan moves spot → temporarily unhealthy → liquidator (attacker) takes collateral at discount. See [[oracle-manipulation]].

### Staking rewards via instantaneous balance (HIGH)
Snapshot-less reward math that integrates `balanceOf` at unpredictable moments.

### Lending utilization-rate manipulation (HIGH)
Borrow rate as a function of `utilization = borrowed / supplied`. Flash-deposit → instantaneous low utilization → favorable borrow → flash-repay.

### Single-block circular flash-loan abuse
Take flash loan from A, deposit into B, manipulate B's price/rate, borrow from C, repay A — all in one block. Detect via: "this contract takes external balance into account in a single function."

### Bribe / token-distribution gaming
Flash-loan governance token to claim bribes that are paid pro-rata to current holders.

## Severity rubric

| Pattern | Severity |
|---|---|
| Governance vote weight from spot balance | **Critical** |
| ERC-4626 vault with no inflation protection | **Critical** |
| Liquidation health check using spot price | **Critical** |
| Bonding-curve / mint price tied to spot | **Critical** |
| Reward distribution proportional to spot balance, claim is permissionless | **High** |
| Utilization-rate function exploitable in single block | **High** |
| Bribe market with spot-balance pro-rata distribution | **High** |
| Display-only metric tied to spot balance | **Info** |

## Remediation patterns

- **Snapshot vote weight** at proposal creation. Enforce `votingDelay > 0` (typically 1 day).
- **ERC-4626 inflation guards**: OZ virtual shares/assets, or "dead-shares" (mint 1000 shares to address(0) on first deposit), or require minimum first-deposit amount.
- **TWAP + multi-oracle** pricing on health checks and liquidations (≥30 min window).
- **Per-block accounting limits** — no state should depend on within-block deltas that can be flash-loan-funded.
- **Lockup periods** — claim rewards only N blocks after deposit.
- **Cooldown on key actions** — e.g. governance can't vote in the block balance was acquired.

## False-positive notes

- Internal-only functions or functions guarded by trusted roles aren't flash-loan exploitable unless the trusted role is compromised — note but down-severity.
- Protocols using `ERC20Votes` with proper checkpoints + `votingDelay` are typically safe — verify the delay value.

## Related

- [[oracle-manipulation]] — flash loans almost always pair with oracle manipulation
- [[governance-specialist]] — protocol-specific governance review
- [[yield-aggregator-specialist]] — ERC-4626 deep-dive

Attribution

iktok90-designiktok90-design
View sourceSee grades on GitHubMore from iktok90-design →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Nft Standards

Implement NFT standards (ERC-721, ERC-1155) with proper metadata handling, minting strategies, and marketplace integration. Use when creating NFT contracts, building NFT marketplaces, or implementing digital asset systems.

458250 votes

Nft Standards

Implement NFT standards (ERC-721, ERC-1155) with proper metadata handling, minting strategies, and marketplace integration. Use when creating NFT contracts, building NFT marketplaces, or implementing digital asset systems.

401990 votes

vyper-compiler

Vyper smart contract compiler internals. Use when working on the Vyper compiler codebase — compilation pipeline, Venom IR, semantic analysis, code generation, testing, or contributing. Triggers on vyper compiler development, Venom passes, AST/semantics changes, codegen work, or test writing.

51840 votes

Flash Loan Simulator

Simulate flash loan arbitrage strategies and profitability across DeFi protocols. Use when performing crypto analysis. Trigger with phrases like "analyze crypto", "check blockchain", or "monitor market".

27190 votes

On Chain Analytics

Perform on-chain analysis including whale tracking, token flows, and network activity. Use when performing crypto analysis. Trigger with phrases like "analyze crypto", "check blockchain", or "monitor market".

27190 votes
View all in blockchain →