What Is a Flash Loan? How Atomic Loans Work on Stellar
What a flash loan is, how atomic loans work, what they are used for, the attacks they enabled, and how Blend and XOXNO implement them on Stellar.
Updated 9 October 2026: Blend and XOXNO flash-loan code and fees re-read from their GitHub repositories, TVL from DefiLlama, Aave's fee from its V3 guide.
A flash loan is a loan with no upfront collateral that is borrowed and settled inside one blockchain transaction. If the borrower does not repay, or on some protocols leave enough collateral behind, the whole transaction is reverted, so the lender never takes credit risk. On Stellar, Blend and XOXNO both offer flash loans, built differently.
A blockchain transaction either succeeds in full or fails in full. A flash loan uses that: the lender sends funds, your contract uses them, and the lender checks it is made whole before the transaction ends. Uses include arbitrage, liquidations, collateral swaps and one-step leverage. Attacks used them to rent huge capital for one transaction. Blend's version records the loan as debt and checks your health factor; XOXNO's requires repayment plus a 0.09% fee.
- Flash loans need no collateral because the transaction is atomic: unpaid means reverted.
- Fees vary: Aave V3 starts at 0.05%, XOXNO's configuration uses 0.09%, Blend charges no separate fee but books ordinary debt.
- Blend's flash loan does not have to be repaid in the same transaction, as long as your position ends healthy.
- Flash loans do not create vulnerabilities; they let anyone exploit an existing one at scale.
Flash loans on Stellar by the numbers (October 2026)
| Measure | Blend V2 | XOXNO Lending |
|---|---|---|
| Stellar TVL (DefiLlama, 9 Oct) | $146.6M | $129K |
| Borrowed | $43.8M | $48K |
| Flash-loan fee | None beyond normal borrow interest | 0.09% (9 bps) |
| Settlement rule | Health factor valid at end of transaction | Principal plus fee pulled back via allowance |
| Flash-loanable assets | Any borrowable reserve in a pool that allows borrowing | XLM, USDC, EURC, PYUSD, USDT0, USST, SolvBTC |
Pool cash limits size: you can only flash-borrow what a pool holds and is willing to lend. Blend's Fixed V2 pool was "on ice" on 8 October, which blocks new borrowing, so flash loans there are unavailable until that changes. Background on that: Blend's 2026 incidents.
How to choose
- You want leverage in one step: use a protocol that turns a flash loan into a debt position (Blend's design, or XOXNO's
flash_position); see leveraged yield farming. - You are building an arbitrage or liquidation bot: a cash flash loan that you repay in full (XOXNO's
flash_loan) is the clean primitive; budget for the fee. - You want to swap collateral or refinance: both designs work; the debt-style loan avoids a fee.
- You are assessing a protocol's safety: ask whether its prices or governance could be moved by someone holding a lot of capital for one transaction.
How a flash loan works, step by step
A flash loan has four steps inside one transaction: the lender sends the tokens to your contract, calls a function on it, lets it run any logic, then checks that it has been made whole. If the check fails, the network discards every change the transaction made, including the loan.
This depends on atomicity. On Stellar, as on Ethereum, a transaction's operations succeed or fail together. Soroban contracts can call other contracts, so a lending pool can hand control to your contract mid-transaction and take it back afterwards. The lender does not care what you did in between, only the state at the end.
Aave's V3 documentation describes the general pattern: borrowers must "return the borrowed amount plus fees" or open a debt position "before the end of the transaction", otherwise "the transaction is reverted". Its default fee is 0.05%, changeable by governance. Variations are about what counts as being made whole.
What flash loans are used for
The main uses are arbitrage (buy low in one market and sell high in another without your own capital), liquidations (repay an unhealthy loan and collect the collateral bonus), collateral swaps and refinancing, and building leveraged positions in one step instead of many loops.
Arbitrage. If an asset is cheaper on one Stellar venue than another, a bot can borrow, buy, sell and repay in one transaction, keeping the spread minus fees. Soroswap's aggregator, for instance, routes across Soroswap, Phoenix and Aquarius, which is where such gaps appear; see Soroswap explained.
Liquidations. A liquidator needs the debt asset to repay an unhealthy loan. A flash loan supplies it, the collateral bonus pays it back. Blend's design discussion lists liquidation auctions among its intended uses.
Leverage. Instead of supply, borrow, swap, supply in repeated loops, a flash loan borrows the full amount upfront, buys more collateral and deposits it in one go. Blend's own design notes say the borrower need not repay in full, only "[have] enough collateral to maintain the loan". This is the engine behind one-click looping.
How flash loans have been abused
Flash loans let anyone command very large capital for one transaction, so any weakness that depends on capital size becomes exploitable by anyone. The common patterns are manipulating prices that a protocol trusts, and buying temporary voting power. The flaw is always in the victim protocol.
Governance. On 18 April 2022 an attacker flash-borrowed about $1B in stablecoins and tokens, including 350M DAI, 500M USDC and 150M USDT from Aave, deposited them to gain Beanstalk voting power, and executed a malicious proposal immediately through an emergency function. rekt.news put the damage at $181M. The missing piece was a delay between a vote and its execution.
Accounting bugs. On 14 March 2023 Euler Finance lost about $197M. Per rekt.news, the attacker used flash-loaned funds and Euler's leverage system to create a large underwater position, exploiting a donation function that "does not contain a check on the health of the user's position".
Price manipulation. The most common pattern: borrow, push a thin market's price, let a lending protocol read the distorted price, borrow against inflated collateral. Stellar's largest 2026 loss, the YieldBlox pool, came from a manipulated thin market feeding an oracle, though it did not need a flash loan; see Stellar oracles and DeFi risks.
Flash loans on Blend
Blend V2's pool contract has a flash_loan function that adds the borrowed amount to your debt first, processes any other requests you attach, checks your health factor, then sends the tokens to your receiver contract. There is no separate fee: the loan is ordinary debt accruing the pool's borrow rate.
The code in blend-contracts-v2 shows the order. The pool mints debt tokens for the amount, requires that borrowing is allowed on the pool and the reserve and that utilisation stays below 100%, runs your other requests (for example supplying the collateral your receiver will buy), and always validates health, "since flash_borrow requires it". The whitepaper's summary: users can borrow "undercollateralized ... as long as they have a valid health factor at the end of the transaction".
So a Blend flash loan is less a loan you hand back than debt opened before the collateral that backs it arrives. If you want it closed, attach a repay request. Because the borrow must be allowed, a pool in "on ice" or frozen status cannot issue flash loans. Pool basics: what is Blend.
Flash loans on XOXNO
XOXNO Lending offers two flash primitives on Stellar. flash_loan is a classic cash loan: the pool sends tokens, calls your contract, then pulls back principal plus fee through an allowance. flash_position mints debt onto a Multiply, Long or Short account instead, with no fee, and checks the position afterwards.
In XOXNO's published mainnet configuration, seven assets are flash-loanable at a fee of 9 basis points (0.09%): XLM, USDC, EURC, PYUSD, USDT0, USST and SolvBTC. RWA tokens, LP tokens and AQUA are not. The pool code checks its token balance after paying out, again after your callback (it must be unchanged), and once more after collecting, so a repayment that does not arrive through the allowance fails.
XOXNO's developer guide spells out a Stellar-specific constraint: the Soroban host rejects any call into a contract already on the call stack, so a flash-loan callback cannot call back into the pool or controller. That blocks the classic re-entrancy pattern at the platform level. Its guide also notes that the test receivers in its repository are "not deployable production receivers". More in XOXNO Lending on Stellar and Blend vs XOXNO.
What a safe receiver contract checks
Your receiver contract is public, so anyone can call it. XOXNO's developer guide lists the checks: require authorisation from the configured pool, confirm the caller and initiator are the ones you expect, validate every address and minimum in your instructions, and approve only the exact repayment, with a short-lived allowance.
The guide is concrete about details that cause losses: use the fee the pool passes into the callback rather than recomputing it, never transfer the repayment directly but approve the pool to pull it, and treat a callback that returns normally as unfinished until the whole transaction succeeds. It also warns not to trust addresses or amounts copied into the callback's data field. These are good rules on any chain; they matter most for contracts that hold funds between transactions.
How these fit together
The two Stellar designs map to the two jobs flash loans do. XOXNO's cash loan, repaid with a fee, suits bots that need temporary capital. Blend's debt-style loan, and XOXNO's flash_position, suit users building positions, where the "loan" is meant to stay open. Soroban's ban on re-entering a contract already on the stack removes one historical attack class but not price manipulation or bad accounting, which depend on the protocols being called.
The takeaway
A flash loan is credit secured by atomicity: repay or be reverted. It makes arbitrage, liquidations and one-step leverage cheap, and it makes any capital-sensitive flaw exploitable by anyone. On Stellar, Blend's version opens health-checked debt with no fee, and XOXNO's charges 0.09% for cash or opens debt on a position account. If you are not writing contracts, you will meet flash loans inside leverage and collateral-swap features.
Sources: github.com/blend-capital/blend-contracts-v2 (pool/src/contract.rs, pool/src/pool/submit.rs) and issue #7; Blend whitepaper; github.com/XOXNO/rs-lending-xlm @ 598aa1f (configs/mainnet/markets.json, contracts/pool/src/ops/flash.rs, skills/xoxno-lending-contracts/flash-loans.md); Aave V3 flash-loan guide; rekt.news (Beanstalk, Euler); DefiLlama protocols API, 9 October 2026. WhaleHub is the publisher of this article.
Frequently asked questions
What is a flash loan in simple terms?
A loan that is borrowed and settled inside a single blockchain transaction. Because the transaction either completes in full or is reverted, the lender takes no credit risk: if the money is not returned (or, on some protocols, covered by collateral) by the end, it is as if the loan never happened.
Are flash loans free?
It depends on the protocol. Aave's V3 flash-loan fee starts at 0.05%. On Stellar, XOXNO's published configuration charges 0.09% on its flash-loanable assets, and Blend's contract charges no separate flash-loan fee but records the amount as ordinary debt that accrues the pool's borrow rate.
Are flash loans illegal or a hack?
No. A flash loan is a standard DeFi feature used for arbitrage, liquidations and leverage. It has featured in many exploits because it gives an attacker large capital for one transaction, but the flaw in those cases was in the victim protocol, such as a manipulable price feed or governance without a delay.
Can I use a flash loan without writing code?
Usually only through an app that builds the transaction for you, such as a leverage or collateral-swap feature. A raw flash loan needs a contract that receives the funds and does something with them before the transaction ends.
Yield on Stellar, with the risks written down
WhaleHub stakes AQUA, aggregates ICE voting power and auto-compounds Aquarius rewards, and publishes how each part can fail.
Launch the appThis article is for education only and is not financial advice. Figures are taken from the sources linked in the text as of the date shown and change constantly. Verify them before acting.


