Euler Finance Hack

TOTAL LOST $197.0M
Critical Flash Loan Attacks ethereum

What happened

Euler Finance's Ethereum lending protocol was exploited on March 13, 2023 for about $197 million. The attacker used flash liquidity and controlled accounts to create a deliberately unhealthy position, then self-liquidated it under Euler's discounted liquidation terms and withdrew pool assets. Euler later said all recoverable funds were returned; later reporting valued the returned assets at about $240 million after market prices changed.

Technical Root Cause

donateToReserves() could reduce an account's collateral without checking whether the account remained solvent. Combined with self-borrowing and liquidation incentives, that let an attacker manufacture a profitable liquidation of its own position. Lending protocols must test every collateral-reducing state transition for post-condition solvency, including multi-account liquidation paths funded by temporary liquidity.

Case & protocol details

Classification Lending Protocol / Self-Liquidation Logic
Protocol Type Lending
Affected asset / contract EUL
Smart Contract Language Solidity
Official Website app.euler.finance/
Protocol Twitter/X @eulerfinance

Attack Timeline

The attacker borrowed flash liquidity, deposited it into Euler, and used mint() to create a highly leveraged eToken collateral and dToken debt position while intermediate checks passed. donateToReserves() then reduced the attacker's eToken collateral without a corresponding post-operation health check, making the account liquidatable. A second attacker-controlled account liquidated that bad position at Euler's soft-liquidation discount, acquired eTokens worth more than the debt repaid, redeemed them for underlying pool assets, repaid the flash liquidity, and repeated the path against additional pools.

Funds Recovery

89.8%

Recovered

$177.0M

Net Loss

$20,094,000

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.