Quantstamp unveils tool to detect DeFi flash loan vulnerabilities

Quick Take

  • Quantstamp has introduced an “Economic Exploit Analysis” tool to detect flash loan vulnerabilities in DeFi protocols.
  • Flash loan attacks account for an increasing proportion of stolen funds in decentralized finance. 

Blockchain security and auditing firm Quantstamp has rolled out what it calls the Economic Exploit Analysis tool, aiming to help identify potential flash loan attack vectors in smart contracts before any hacks occur.

The tool automatically scans for vulnerabilities in the software code of a protocol that could be exploited through flash loan attacks, according to a statement. Quantstamp said it collaborated with the University of Toronto in developing the service, converting its initial academic research into a production-level tool.

The tool is not limited to analyzing only one specific contract or those belonging to a single client. Auditors (those checking the code for security flaws) can use this tool to analyze across various contracts from integrated DeFi protocols, Quantstamp added. However, while the tool’s search process is automated, it does require some manual intervention for protocol-specific adaptations, and it doesn’t guarantee the detection of all vulnerabilities.

Flash loan-based attacks are a significant concern in the DeFi space, siphoning off around $200 million alone from the Euler Finance exploit in March.

Flash loans attract attackers aiming to exploit DeFi protocol vulnerabilities as they grant borrowers access to uncollateralized funds that can be leveraged to manipulate the protocols. However, they also carry substantial risk due to the borrower’s obligation to repay within the same transaction. The complexity of these attacks often allows them to bypass standard code audits, potentially allowing hackers to carry out exploits.

THE SCOOP

Keep up with the latest news, trends, charts and views on crypto and DeFi with a new biweekly newsletter from The Block's Frank Chaparro

By signing-up you agree to our Terms of Service and Privacy Policy
By signing-up you agree to our Terms of Service and Privacy Policy

“DeFi has the potential to change the global financial infrastructure for the better, but its success requires preempting threats like flash loan attacks. We developed this tool to provide DeFi protocols an extra layer of security on top of audits,” Quantstamp Head of New Initiatives Martin Derka said. “As DeFi evolves, security measures need to evolve with it. Services like Economic Exploit Analysis give us an edge against hackers.”

Quantstamp’s Economic Exploit Analysis service is currently available across all Ethereum-compatible chains, with the potential to be adapted for other blockchains in the future, the team said.

Increasing proportion of DeFi funds stolen using flash loans

Flash loan attacks are responsible for an increasing proportion of stolen funds from DeFi projects, according to The Block’s dashboard. In July, 90% of the funds stolen were through flash loan-based attacks.

Last month, the Securities and Exchange Commission (SEC) charged Quantstamp over its $28 million initial coin offering (ICO) in 2019. Quantstamp paid $3.4 million to settle the charges without admitting or denying them. The SEC has established a "fair fund" to return the money paid by Quantstamp to the investors.


© 2023 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

About Author

James Hunt is a reporter at The Block, based in the UK. As the writer behind The Daily newsletter, James also keeps you up to speed on the latest crypto news every weekday. Prior to joining The Block in 2022, James spent four years as a freelance writer in the industry, contributing to both publications and crypto project content. James’ coverage spans everything from Bitcoin and Ethereum to Layer 2 scaling solutions, avant-garde DeFi protocols, evolving DAO governance structures, trending NFTs and memecoins, regulatory landscapes, crypto company deals and the latest market updates. You can get in touch with James on Telegram or X via @humanjets or email him at [email protected].

Editor

To contact the editor of this story:
Vishal Chawla at
[email protected]