Euler Finance Loses $197M to a Flash-Loan Attack on Its Donation Mechanism
Euler Finance, one of DeFi's more established lending platforms, suffered a roughly $200 million exploit on Tuesday, March 14, 2023 — arriving just as the market was recovering from a banking crisis and stablecoin de-peg scare and USDC was climbing back toward its dollar peg.
Peckshield was first to flag unusual activity on the protocol. Euler Labs confirmed the incident shortly after, stating it was working with security professionals and law enforcement to respond.

As details emerged, the scale of the loss became clear: attackers made off with $197 million across ETH, WBTC, USDC, and DAI, enough to place Euler sixth on rekt.news's leaderboard of largest exploits. The protocol's total value locked collapsed from $264 million to roughly $10 million, according to DeFiLlama.
Speculation that this might be a whitehat rescue rather than a theft was quickly dismissed: on-chain investigators noted that the same attacker-linked address had previously drained the BSC-based EPMAX project before routing those proceeds through Tornado Cash — establishing a pattern inconsistent with a good-faith recovery.
Mechanics of the exploit
Euler's lending system is built around two token types: eTokens representing collateral and dTokens representing debt. Liquidation is triggered whenever a user's dToken balance exceeds their eToken balance.
The vulnerability lived in a rarely-used function called donateToReserves, added to the protocol via EIP-14 the previous year. This function lets users donate eTokens directly to Euler's reserves — but critically, it performed no check on whether the donor's position remained healthy afterward.
The attacker exploited this gap using a pair of contracts working in tandem: one would deliberately donate eTokens to push itself into bad debt via donateToReserves, while the second acted as liquidator. By first taking out a large leveraged position with flash-loaned capital and then triggering the donation, the attacker created conditions where the liquidator contract could scoop up artificially inflated eToken collateral at a steep discount and convert it to underlying assets.
Omniscia, one of six firms that had audited Euler, published a post-mortem describing the root cause: the donation mechanism failed to account for the donor's own debt health, allowing the creation of unbacked dToken debt that could never actually be liquidated.
Tracing the funds
The attacker's wallet, where the bulk of funds still sits, is 0xb66cd966670d962c227b3eaba30a872dbfb995db. An example transaction moving DAI can be found at 0xc310a0affe2169d1f6feec1c63dbc7f7c62a887fa48795d327d4d2da2d6b111d.
SlowMist published a breakdown of the total haul: approximately 86,000 ETH-denominated derivatives worth $134.6 million, 849 WBTC worth $18.6 million, 34 million USDC, and 8.9 million DAI.
Sherlock, the smart-contract insurance provider whose auditors had reviewed EIP-14 without catching the flaw, publicly accepted responsibility for the oversight and committed to paying Euler a $4.5 million claim.
Euler's team attempted direct contact with the attacker by embedding a message in transaction input data, asking whether the attacker would be willing to discuss next steps regarding the morning's events. However, since a portion of the stolen funds had already moved to Tornado Cash through an intermediary address — seemingly as a test transfer — expectations for a voluntary return of funds remained low.

Contagion across DeFi
Because Euler had built a reputation as a stable, well-regarded protocol, numerous other projects had integrated with it or held funds there, and the exploit's fallout rippled outward. The scale of that integration itself underscored how significant the breach was for the wider ecosystem, and many teams publicly expressed solidarity with Euler.
Euler's own token, EUL, dropped more than 50% in the aftermath. Other affected projects included:
- Angle Protocol — over $17 million in agEUR collateral exposed; its ANGLE token also fell more than 50%
- Balancer — $11.9 million in bbeUSD
- Temple DAO — $5 million exposed; TEMPLE token down 30%
- Idle DAO — approximately $5 million
- Swissborg — $2.6 million in ETH and $1.7 million in USDT
- Yield Protocol — $1.5 million
- Yearn — $1.38 million in indirect exposure, with losses to be absorbed by its Treasury
- Inverse Finance — $800,000
- Several other smaller protocols also reported exposure
The interconnected nature of DeFi lets projects build sophisticated, composable systems that traditional finance structures can't easily replicate — but that same interconnection means a single failure can cascade quickly across the ecosystem. Incidents like this reinforce the case for continued investment in more resilient protocol design, even as they raise uncomfortable questions about how secure any of these systems truly are.
Get new scam files the moment we publish them — usually 2–3 emails a week.