The post Asymmetric Research discloses Marginfi flash loan bug that risked $160M appeared on BitcoinEthereumNews.com. Marginfi, a Solana-based lending and borrowing protocol, has patched a critical vulnerability in its flash loan mechanism that briefly placed more than $160 million in user deposits at risk. The bug, disclosed by security researcher Felix Wilhelm through Marginfi’s bug bounty program, would have allowed an attacker to borrow funds without repaying them. The issue was resolved before any exploit occurred, and no funds were lost, according to Asymmetric Research’s report. Flash loans, a common DeFi feature, allow users to borrow nearly all available liquidity on the condition that the funds are repaid within the same blockchain transaction. Solana protocols typically enforce this by introspecting instructions in a transaction to ensure a repayment step is included. According to Asymmetric, Marginfi followed this approach but introduced a new instruction, transfer_to_new_account, that unintentionally bypassed repayment checks. This meant liabilities could be shifted to a new account mid-loan, enabling funds to be drained without triggering safeguards. The report indicates that the Marginfi team swiftly deployed a patch to block account transfers during flash loans and prevent disabled accounts from being used for repayment. While Solana’s architecture limits some common Ethereum-style exploits, the vulnerability underscores that logic errors remain a critical threat. The swift resolution demonstrates the role of bug bounty programs in preventing systemic losses. Similar past incidents, including attacks on Mango Markets and other Solana-based protocols, have shown how flash loan vulnerabilities can lead to multimillion-dollar losses. Marginfi representatives did not respond to Blockworks’ request for comment before publication. This is a developing story. This article was generated with the assistance of AI and reviewed by editor Jeffrey Albus before publication. Get the news in your inbox. Explore Blockworks newsletters: Source: https://blockworks.co/news/marginfi-flash-loan-bugThe post Asymmetric Research discloses Marginfi flash loan bug that risked $160M appeared on BitcoinEthereumNews.com. Marginfi, a Solana-based lending and borrowing protocol, has patched a critical vulnerability in its flash loan mechanism that briefly placed more than $160 million in user deposits at risk. The bug, disclosed by security researcher Felix Wilhelm through Marginfi’s bug bounty program, would have allowed an attacker to borrow funds without repaying them. The issue was resolved before any exploit occurred, and no funds were lost, according to Asymmetric Research’s report. Flash loans, a common DeFi feature, allow users to borrow nearly all available liquidity on the condition that the funds are repaid within the same blockchain transaction. Solana protocols typically enforce this by introspecting instructions in a transaction to ensure a repayment step is included. According to Asymmetric, Marginfi followed this approach but introduced a new instruction, transfer_to_new_account, that unintentionally bypassed repayment checks. This meant liabilities could be shifted to a new account mid-loan, enabling funds to be drained without triggering safeguards. The report indicates that the Marginfi team swiftly deployed a patch to block account transfers during flash loans and prevent disabled accounts from being used for repayment. While Solana’s architecture limits some common Ethereum-style exploits, the vulnerability underscores that logic errors remain a critical threat. The swift resolution demonstrates the role of bug bounty programs in preventing systemic losses. Similar past incidents, including attacks on Mango Markets and other Solana-based protocols, have shown how flash loan vulnerabilities can lead to multimillion-dollar losses. Marginfi representatives did not respond to Blockworks’ request for comment before publication. This is a developing story. This article was generated with the assistance of AI and reviewed by editor Jeffrey Albus before publication. Get the news in your inbox. Explore Blockworks newsletters: Source: https://blockworks.co/news/marginfi-flash-loan-bug

Asymmetric Research discloses Marginfi flash loan bug that risked $160M

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Marginfi, a Solana-based lending and borrowing protocol, has patched a critical vulnerability in its flash loan mechanism that briefly placed more than $160 million in user deposits at risk.

The bug, disclosed by security researcher Felix Wilhelm through Marginfi’s bug bounty program, would have allowed an attacker to borrow funds without repaying them. The issue was resolved before any exploit occurred, and no funds were lost, according to Asymmetric Research’s report.

Flash loans, a common DeFi feature, allow users to borrow nearly all available liquidity on the condition that the funds are repaid within the same blockchain transaction. Solana protocols typically enforce this by introspecting instructions in a transaction to ensure a repayment step is included.

According to Asymmetric, Marginfi followed this approach but introduced a new instruction, transfer_to_new_account, that unintentionally bypassed repayment checks. This meant liabilities could be shifted to a new account mid-loan, enabling funds to be drained without triggering safeguards.

The report indicates that the Marginfi team swiftly deployed a patch to block account transfers during flash loans and prevent disabled accounts from being used for repayment. While Solana’s architecture limits some common Ethereum-style exploits, the vulnerability underscores that logic errors remain a critical threat.

The swift resolution demonstrates the role of bug bounty programs in preventing systemic losses. Similar past incidents, including attacks on Mango Markets and other Solana-based protocols, have shown how flash loan vulnerabilities can lead to multimillion-dollar losses.

Marginfi representatives did not respond to Blockworks’ request for comment before publication.

This is a developing story.


This article was generated with the assistance of AI and reviewed by editor Jeffrey Albus before publication.


Get the news in your inbox. Explore Blockworks newsletters:

Source: https://blockworks.co/news/marginfi-flash-loan-bug

Market Opportunity
Moonveil Logo
Moonveil Price(MORE)
$0,0001411
$0,0001411$0,0001411
-%6,55
USD
Moonveil (MORE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

James Gunn’s ‘Superman’ Coming To HBO Max This Week

James Gunn’s ‘Superman’ Coming To HBO Max This Week

The post James Gunn’s ‘Superman’ Coming To HBO Max This Week appeared on BitcoinEthereumNews.com. David Corenswet in “Superman.” Warner Bros. Pictures Superman, director James Gunn’s Man of Steel tale starring David Corenswet, Rachel Brosnahan and Nicholas Hoult, is coming to HBO Max this week. Rated PG-13, Superman opened in theaters on July 11 before arriving on digital streaming via premium video on demand on Aug. 15. The official summary for the movie reads, “When Superman (Corenswet) is drawn into conflicts both abroad and at home, his actions to protect humankind are questioned, and his vulnerability allows tech billionaire and master deceiver Lex Luthor (Hoult) to leverage the opportunity to get Superman out of the way for good. Forbes‘The Fantastic Four: First Steps’ Gets Streaming DateBy Tim Lammers “Will the Daily Planet’s intrepid reporter Lois Lane (Brosnahan), together with the aid of Metropolis’s other metahumans and Superman’s own four-legged companion, Krypto, be able to help Superman before Luthor can completely destroy him?” Warner Bros. Discovery announced earlier this week that Superman will begin streaming on HBO Max on Friday, Sept. 19, and debut on cable on HBO linear on Saturday, Sept. 20, at 8 p.m. ET. HBO Max will also stream a version of Superman using American Sign Language, which will be interpreted by deaf ASL interpreter Giovanni Maucere and directed by Leila Hanaumi (Barbie with ASL, The Last of Us with ASL), the streaming platform noted. Forbes‘South Park’ Season 27 Updated Release Schedule: When Do New Episodes Come Out?By Tim Lammers HBO Max offers an ad-based tier that costs $9.99 per month and an ad-free tier that $16.99 per month. Additionally, an ad-free tier with 4K Ultra HD programming costs $20.99 per month. How Did ‘Superman’ Perform In Theaters? Superman has earned $353.9 million domestically and $261.2 internationally for a worldwide box office tally of $615.1 million to date. The film had a production…
Share
BitcoinEthereumNews2025/09/18 20:38
XRP Moves Above $1.40 as Traders Watch Bullish Signals

XRP Moves Above $1.40 as Traders Watch Bullish Signals

The post XRP Moves Above $1.40 as Traders Watch Bullish Signals appeared on BitcoinEthereumNews.com. XRP climbed above $1.40 with $3.5B volume as traders highlight
Share
BitcoinEthereumNews2026/03/14 18:54
Paramount-WBD 2027 movie slate could dominate. Can it sustain?

Paramount-WBD 2027 movie slate could dominate. Can it sustain?

The post Paramount-WBD 2027 movie slate could dominate. Can it sustain? appeared on BitcoinEthereumNews.com. Paramount Skydance CEO David Ellison speaks during
Share
BitcoinEthereumNews2026/03/14 19:06