Exploit_type: Flash Loan + Logic Flaw in donateToReserves()
Loss: ~$197 million (DAI, wBTC, stETH, USDC, etc.)
Entry_point: EToken::donateToReserves in the EToken collateral contracts
Exploit_vector: Attacker used flash-loaned funds to self-over-leverage, manipulate health score, donate collateral, and then liquidate themselves under favorable terms
Severity: Critical
Attack_steps:
Acquired a ~$30 million DAI flash loan from Aave.
Deposited ~20M DAI into Euler to mint eDAI.
Borrowed against collateral, minting large amounts of eDAI and dDAI multiple times.
Donated eDAI to reserves via donateToReserves(), reducing collateral without adjusting debt.