Flash Loan Attack
An attacker borrows a massive, entirely uncollateralized sum within a single transaction, uses that temporary capital to push a protocol's price, accounting, or governance logic into an abnormal state and profit from it, then repays the loan in full before that same transaction ends. The <a href="https://crypto-bible.com/en/glossary/defi-basics/flash-loan/" target="_blank" rel="noopener">Flash Loan</a> itself is a legitimate financial primitive — the real vulnerability is always the underlying weakness it amplifies, never the act of borrowing itself.
advanced
Oracle Manipulation
An attack where the attacker artificially distorts the price data a <a href="https://crypto-bible.com/en/glossary/blockchain-fundamentals/smart-contract/" target="_blank" rel="noopener">Smart Contract</a>'s <a href="https://crypto-bible.com/en/glossary/defi-basics/oracle/" target="_blank" rel="noopener">Oracle</a> feeds it, causing the contract to execute lending, <a href="https://crypto-bible.com/en/glossary/derivatives-and-leverage/liquidation/" target="_blank" rel="noopener">Liquidation</a>, or trades based on false pricing to extract illicit profit.
advanced
Reentrancy Attack
An exploit of the gap created when a contract sends assets out before it updates its own internal ledger — before the contract has a chance to record "this has already been withdrawn," the attacker repeatedly calls the same withdrawal function, tricking the contract into believing each call is a brand-new request, and drains the assets within a single transaction.
advanced