- The flash loan exploit caps at about $3.5 million
- The on-chain data reveals how the attacker used a $10 million flash loan in USDC to mint tokens
- DeFi protocols across many networks act as a target for flash loan exploits
Solana’s decentralized finance (DeFi) yield protocol, Nirvana Finance, suffered a flash loan exploit. The flash loan exploit caps at about $3.5 million.
Nirvana’s stablecoin, NIRV and native token, ANA suffered a massive price fall after the flash loan attack.
The native token slipped 89% from $8.97 to $0.93. Meanwhile, the stablecoin lost 90% of its US Dollar value after the attack.
How the Nirvana attack happened
The on-chain data reveals how the attacker used a $10 million flash loan in USDC to mint tokens and managed to mint $10 million worth of ANA tokens.
The only condition set dictates that the loan must be repaid in the same block. Optimally, the flash loan remains secured on the Solend protocol.
The attacker manipulated the protocol’s oracle feed. The attack led to the inflation of the price of ANA coins making their holdings exceed $10 million. Subsequently, the attacker swapped the $10 million worth of ANA tokens for $13.49 million in USDT.
The attack drained $3.49 million from Nirvana’s treasury.
Nirvana’s situation during the attack
The exploited party repaid the initial $10 million loan and bridged the profit. The profit was bridged to an Ethereum wallet address through Wormhole. The profit in the wallet then undertook a series of conversions to the DAI stablecoin.
Nirvana remains quiet on the attack and no official statement seems to surface at the moment. Solend released a statement claiming that the firm continues to work with the Nirvana team to solve the issue.
The firm also added that its protocol remained unaffected despite the attack on Nirvana. The Nirvana team continues to remain silent. This lingers on despite efforts to obtain a statement regarding the attack.
Recent flash loan attacks
DeFi protocols across many networks act as a target for flash loan exploits. Beanstalk lost $182 million in April becoming the largest flash loan exploit in the world.
The Ethereum stablecoin project attack emanated from two sinister governance proposals and a flash loan attack. The BIP-18 and BIP-19 governance proposals gave the exploiter a leeway to donate funds to Ukraine.
However, these protocols contained a malicious rider attached to them. Ultimately, the malicious rider enabled the sinkhole of funds from the protocol.
Another exploit involved the Aave (AAVE) protocol. The exploiter took out $1 billion in flash loans from the Aave protocol. The protocol attack is denominated into DAI, USD coin and Tether (USDT) stablecoins.
The attacker used these funds to accumulate enough assets to take over 67% of the protocol’s governance. The protocol also ensured that the attacker could approve their own proposals.
Trust in such protocols continues to be a concern for the users of crypto and crypto platforms across the world.




