Urgent.News

What's breaking now, across thousands of outlets.

Tech

Flash Loan Attack Vector Analysis: MEXC

Flash Loan Attack Vector Analysis: MEXC Target Protocol : MEXC (TVL: $5240.9M) MEXC – Flash‑Loan Attack Vector Analysis Protocol: MEXC (Decentralised Finance suite on Ethereum & L2s) TVL (Ethereum/L2): $5.24 B Date of Assessment: 30 August 2026 Prepared by: Senior DeFi Security Researcher – Audits & Threat‑Intelligence 1. Executive Summary MEXC has rapidly expanded its DeFi offering…

MEXC, a decentralized finance protocol operating on Ethereum and Layer 2 solutions, has a total value locked of $5.24 billion. This substantial TVL makes it a prime target for flash loan attacks, which are executed within a single transaction using uncollateralized capital borrowed from on-chain liquidity sources. The analysis focuses on five key attack vectors:

1. Oracle manipulation via price-feed lag on L2 AMM pools: This high-risk attack could potentially drain $200 million from leveraged positions. Attackers could manipulate price feeds on L2 AMM pools, such as Uniswap V3 on Arbitrum, to trigger liquidations or margin calls before the price feed can revert.

2. Re‑entrancy / callback abuse in the Liquidity‑Mining Reward contract: This critical but low-moderate risk attack could lead to losses of up to $50 million in the reward pool. By exploiting the claimRewards() function's design, which transfers rewards before updating a user's accrued balance, attackers can repeatedly claim the same reward multiple times within a single transaction.

3. Cross‑chain bridge “instant‑withdraw” race condition: This high-risk attack could result in the loss of up to $300 million in bridge‑locked assets. Attackers can exploit the bridge's withdrawInstant() function by calling it twice within a single transaction before the balance is updated, allowing them to withdraw assets twice.

4. Governance token price‑oracle flash‑loan manipulation for “vote‑buy‑back” attacks: This medium-risk attack could lead to governance capture and changes to protocol-wide parameters. Attackers could manipulate the TWAP oracle used for the governance token price by using flash loans, triggering a buy‑back and burn function that purchases the token at a depressed price and burns them.

5. Collateral‑ratio bypass in the lending module via flash‑loan “price‑sandwich” attacks: This medium-high risk attack could result in losses of $50–$100 million due to under‑collateralized liquidations. Attackers can manipulate the price on L2 AMM pools and exploit the lending module's collateral‑ratio calculation to generate forced liquidations.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at dev.to →

More in Tech

More from Sunday 30 August →