📈 Get daily crypto insights that make you smarter about your money

UniLend Finance Suffers $200K Flash Loan Exploit Through Flawed Health Factor Check

The decentralized lending protocol UniLend Finance fell victim to a sophisticated flash loan exploit on January 12, 2025, losing approximately $200,000 in stETH. The attack exposed a critical vulnerability in the protocol’s redeemUnderlying function, specifically in how it validated health factor calculations during collateral redemption.

The Exploit Mechanics

The attacker initiated the operation by taking a flash loan of 60 million USDC and 5 wstETH from Morpho Blue, a leading lending protocol. The borrowed wstETH was immediately converted to 6 stETH through a token exchange. With these flash loan funds in hand, the attacker called the lend() function twice on UniLend V2’s core contract, depositing the 60 million USDC and 6 stETH as collateral.

This is where the critical flaw came into play. The attacker then called borrow() with the recipient set to their own contract address, borrowing 60.67 stETH. The vulnerability was in how the checkHealthFactorLtv0 and checkHealthFactorLtv1 functions assessed collateral adequacy. These functions relied on userBalanceOftoken0 and userBalanceOftoken1 to verify the health factor, but the _lendBalance0 value was inflated due to an incorrect calculation that failed to account for actual token transfers.

The inflated share calculations made the system believe the attacker had significantly more collateral than they actually deposited. By exploiting this discrepancy, the attacker passed all health checks, withdrew the borrowed 60.67 stETH worth approximately $200,000, repaid the flash loan, and pocketed the difference.

Affected Systems

The exploit targeted UniLend V2’s core lending and borrowing smart contracts deployed on the Ethereum mainnet. The vulnerable contract at address 0x7f2E contained the flawed redeemUnderlying function. The attacker deployed a custom contract at 0x3F81 to orchestrate the multi-step exploit, using an externally owned account at 0x55F5 to fund and initiate the attack.

At the time of the exploit, Ethereum was trading at approximately $3,266 and Bitcoin hovered around $94,488. The broader crypto market had been experiencing a correction, with most major tokens down between 3% and 12% over the previous week. This market environment may have contributed to lower monitoring activity on mid-tier DeFi protocols.

The Mitigation Strategy

Flash loan exploits remain one of the most common attack vectors in decentralized finance, and this incident follows a familiar pattern. The core issue was that UniLend’s health factor validation relied on stale or inflated balance calculations rather than real-time token transfers. Effective mitigation requires implementing checks that account for actual token movements during the same transaction, not just cached balance states.

Protocols can defend against such attacks by incorporating reentrancy guards, using up-to-date oracle prices for collateral valuation, and implementing flash loan-resistant design patterns that verify collateral adequacy after all internal operations complete. Regular security audits by multiple independent firms remain essential, particularly for protocols handling significant value.

Lessons Learned

The UniLend exploit underscores several critical lessons for the DeFi ecosystem. First, the complexity of lending protocol logic creates numerous attack surfaces that even experienced development teams can overlook. The redeemUnderlying function appeared to work correctly under normal conditions, but the health factor validation failed when subjected to adversarial inputs designed to exploit balance calculation discrepancies.

Second, flash loans continue to democratize exploitation by allowing attackers to execute sophisticated multi-step attacks without requiring significant upfront capital. The attacker needed only gas fees to attempt this exploit, as the 60 million USDC flash loan was borrowed and repaid within a single transaction.

Third, the incident highlights the importance of real-time monitoring systems that can detect unusual transaction patterns, such as massive flash loan borrows followed by rapid collateral manipulation, before the full exploit completes.

User Action Required

Users who had funds deposited in UniLend V2 lending pools should immediately check their positions and assess whether any of their collateral was affected by the exploit. If the protocol has not yet published a post-mortem, users should monitor UniLend’s official communication channels for updates on remediation efforts and potential reimbursement plans. As a general practice, DeFi users should diversify their holdings across multiple protocols and avoid concentrating large positions in any single lending platform, regardless of its track record.

Disclaimer: This article is for informational purposes only and does not constitute financial advice. Always conduct your own research before engaging with any DeFi protocol.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

26 thoughts on “UniLend Finance Suffers $200K Flash Loan Exploit Through Flawed Health Factor Check”

  1. another health factor miscalculation. when will lending protocols stop rolling their own liquidation logic and use audited libraries

    1. audit_max the real issue is that lending protocols keep deploying custom health factor math instead of using battle tested implementations. every new codebase is a new attack surface

    2. audit_max the real issue is that lending protocols keep deploying custom health factor math instead of using battle tested implementations. every new codebase is a new attack surface

      1. 0xquasar battle tested implementations exist but every new protocol wants their own spin on health factors. NIH syndrome in DeFi is expensive

    1. flash loan attacks have basically become a bug bounty program where the payout is guaranteed and the auditor is the attacker

  2. borrowing 60M USDC AND 5 wstETH from morpho blue for a 200K exploit. the attacker did all that work for less than what a decent dev makes in a year salary

    1. healthfactor_lol

      morpho_rat_ the ROI wasnt the point. they proved the checkHealthFactorLtv0 function was broken and could be abused on any unilend v2 fork. the real damage was showing the pattern

      1. healthfactor_lol the ROI was never the point. they proved the checkHealthFactorLtv0 function was broken and cashed out. academic flex with a payday

    1. health_factor_zero

      Tomasz V. bzx oracle manipulation vs UniLend logic bug is a different attack class but same outcome. lending protocols keep reinventing the same wheel

    2. same class as bzx but the redeemUnderlying path is new. each time a different function gets hit and auditors play whack a mole

    1. Dara K. Morpho Blue being the flash loan venue for 3 separate exploits this quarter is not a Morpho problem, its a protocol security problem. but the PR is brutal

    2. Dara K. Morpho Blue being the flash loan venue for 3 separate exploits this quarter is not a Morpho problem, its a protocol security problem. but the PR is brutal

    1. audit_max the answer is never. lending protocols will keep rolling custom health factor math because each one thinks their implementation is special. NIH syndrome costs more than audits

    1. ethan_chen 60M flash loan for 200K payout is a 0.33% return on borrowed capital. these attackers are running tighter margins than tradfi HFTs

  3. morpho_skeptic

    Morpho Blue being flash loan venue for 3 exploits this quarter. Not a Morpho problem, but PR is brutal

    1. morpho_defender_

      morpho_skeptic Morpho Blue being the flash loan source is like blaming the bank for a robbery. the protocol that gets borrowed from is never the problem, the protocol that gets exploited is

  4. custom_math_skep_

    60M USDC flash loan to extract 200K. the attacker ran more complex logistics than most legitimate DeFi strategies for a 0.33% return on borrowed capital

  5. health_factor_zero

    the checkHealthFactorLtv functions relying on userBalanceOftoken instead of current market value is such a basic design flaw. how does that pass any review

  6. 60M USDC flash loan from Morpho Blue to extract 200K from UniLend. the attacker used more brainpower than most legit dev teams

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$63,973.00-1.6%ETH$1,874.26-2.2%SOL$75.82-1.1%BNB$599.59-0.8%XRP$1.01-1.9%ADA$0.1904-2.9%DOGE$0.0699+0.2%DOT$0.8067+0.8%AVAX$6.51+0.5%LINK$8.35+1.9%UNI$3.95-2.3%ATOM$1.40+1.9%LTC$45.16-0.9%ARB$0.0810+3.8%NEAR$1.60-0.7%FIL$0.7014-0.3%SUI$0.6865-0.5%BTC$63,973.00-1.6%ETH$1,874.26-2.2%SOL$75.82-1.1%BNB$599.59-0.8%XRP$1.01-1.9%ADA$0.1904-2.9%DOGE$0.0699+0.2%DOT$0.8067+0.8%AVAX$6.51+0.5%LINK$8.35+1.9%UNI$3.95-2.3%ATOM$1.40+1.9%LTC$45.16-0.9%ARB$0.0810+3.8%NEAR$1.60-0.7%FIL$0.7014-0.3%SUI$0.6865-0.5%
Scroll to Top