Share this article

Solana DeFi Protocol Nirvana Drained of Liquidity After Flash Loan Exploit

The price of the protocol’s ANA token fell almost 80% following the attack.

Updated May 11, 2023, 4:43 p.m. Published Jul 28, 2022, 11:41 a.m.
Solana-based yield protocol Nirvana Finance suffered a $3.5 million exploit. (Kevin Ku/Unsplash)
Solana-based yield protocol Nirvana Finance suffered a $3.5 million exploit. (Kevin Ku/Unsplash)

Nirvana Finance, a Solana-based yield protocol, suffered a $3.5 million exploit utilizing flash loans to manipulate and drain its liquidity pools, blockchain data shows.

The price of the protocol’s native ANA token fell over 80% in the past few hours, while its NIRV stablecoin lost its peg to the U.S. dollar and dropped to 8 cents at writing time, CoinGecko data shows.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters

Nirvana allowed users to earn annual yields of over 100% on their locked assets by creating and destroying tokens based on user demand as the ANA tokens were bought from and sold to the protocol. Over $3.5 million worth of ANA was locked on the protocol before the attack on Thursday.

Flash loans are a popular way for attackers to gain the funds to conduct exploits on decentralized finance (DeFi) systems. In April, the Beanstalk stablecoin protocol was drained of $182 million, and last month more than $1.2 million was taken from Inverse Finance.

The loans allow traders to borrow unsecured funds from lenders using smart contracts instead of third parties. They do not require any collateral because the contract considers the transaction complete only when the borrower repays the lender. This means a borrower defaulting on a flash loan would cause the smart contract to cancel the transaction and the money would be returned to the lender.

Data from blockchain explorers shows the attack used over 10 million USDC sourced from lending tool Solend in a flash loan. At that point over $10 million worth of ANA was minted, or created, and the entire amount swapped to receive $3.5 million worth of tether from Nirvana’s treasury wallet.

This was possible because the treasury considered the 10 million USDC infusion to be genuine. However, it wasn't, and the protocol was hence tricked into releasing its treasury's liquidity.

The attacker sourced over 10 million USDC in a flash loan and drained Nirvana's liquidity pool. (Solana FM)
The attacker sourced over 10 million USDC in a flash loan and drained Nirvana's liquidity pool. (Solana FM)

The total value locked (TVL) on Nirvana fell to 7 cents in European morning hours following the attack. Its entire liquidity pool was effectively drained, data from DeFi Llama shows.

Value locked on Nirvana fell to 62 cents following the attack. (DeFi Llama)
Value locked on Nirvana fell to 62 cents following the attack. (DeFi Llama)

The 10 million USDC was returned to Solend after the exploit. The stolen funds were transferred to the Ethereum network using Wormhole, a blockchain tool that connects Solana to other networks, and converted to DAI, an Ethereum-based stablecoin, blockchain data shows.

The attacker address – 0xB9AE2624Ab08661F010185d72Dd506E199E67C09 – currently holds over $3.5 million worth of DAI, blockchain data shows.

Nirvana’s trading functions were suspended by developers following the attack, as per messages by admins on the protocol’s Telegram channel.

Nirvana had not responded to requests for comments by publication time.

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

NFT Project Pudgy Penguins Takes Over Las Vegas Sphere in Holiday Campaign

Pudgy Penguins NFT are on a holiday rally. (Screenshot)

The NFT brand’s animated segments will air on the Sphere across Christmas week, signaling the crypto company's move into real-world consumer markets.

What to know:

  • Pudgy Penguins will run an ad campaign at the Las Vegas Sphere during Christmas week, one of the few crypto brands to secure a spot at the high-profile venue.
  • The NFT project, which launched on Ethereum in 2021, has expanded into physical toys and digital gaming as part of a broader consumer push.
  • Pudgy Penguins briefly overtook Bored Apes in floor price earlier this year and recently launched its PENGU token on Solana, now trading on major exchanges.