NewsCryptoFlash Loan Attacks Drained $1.2 Billion From DeFi Between 2020 and 2024, Study Finds

Flash Loan Attacks Drained $1.2 Billion From DeFi Between 2020 and 2024, Study Finds

Author: Decrypt·

Key Takeaways

  • •Flash loan attacks drained $1.211 billion from DeFi platforms in 72 incidents between February 2020 and July 2024, representing 18.44% of the $6.568 billion stolen in all successful DeFi attacks during that period.
  • •Researchers identified 14 distinct flash loan attack types, and logic exploits grew from 28% of losses between February 2020 and January 2022 to 55% between February 2022 and July 2024.
  • •Attacks that stole $10 million or more accounted for over 88% of total losses, with individual incidents ranging from $80,000 to $197 million.
  • •Four attack types—price oracle attacks, donate function logic exploits, reentrancy attacks, and a $181 million governance attack—caused more than 81% of total losses.
  • •The study found flash loan use kept growing throughout the period despite the attacks, which the authors characterized as significant but "not existential" threats to DeFi.
Flash Loan Attacks Drained $1.2 Billion From DeFi Between 2020 and 2024, Study Finds

Flash loan attacks drained $1.211 billion from decentralized finance (DeFi) platforms across 72 incidents between February 2020 and July 2024, according to newly published research in the Journal of Financial Crime.

The losses represented 18.44% of the $6.568 billion stolen in all successful DeFi attacks during the period, and more than 80% of the flash loan losses occurred on Ethereum, the blockchain where most DeFi activity takes place.

The study was conducted by Professor Tim Hall of the University of Winchester and Remo Stieger, a former partner at Swiss risk intelligence firm SyntiFi. It identified 72 flash loan attacks among 254 successful attacks on DeFi over the four-and-a-half-year window.

A new type of cybercrime is seeing mind-boggling sums stolen in the world of digital finance and crypto currencies, according to ground-breaking research involving Prof Tim Hall, an academic @_UoW . Read about flash loan attacks here pic.twitter.com/JkGAqsJJED

— University of Winchester (@_UoW) October 5, 2026

Hall said in a statement that "we now are seeing crimes that we have never seen before," some of them "capable of stealing mind-boggling sums of money, often in the tens of millions of dollars."

Flash loans let users borrow assets from a liquidity pool without posting collateral, provided the loan is repaid within the same blockchain transaction. Because the loan exists only for the life of that single transaction, an attacker can command sums far beyond anything they actually hold, using the mechanism to access the large capital needed to execute an exploit.

Individual attacks ranged in size from $80,000 to $197 million, the study found and attacks that stole $10 million or more accounted for over 88% of total losses.

How the attacks work

The researchers identified 14 distinct types of flash loan attack, falling into two broad groups: those that manipulate price feeds, and those that exploit flaws in a protocol's underlying logic. Price oracles are the external feeds DeFi protocols rely on to value assets, so an attacker who can distort one can trick a protocol into mispricing collateral or payouts. Logic exploits were less frequent but caused higher average losses.

That balance shifted over time. Logic exploits accounted for 28% of flash loan attack losses between February 2020 and January 2022, but rose to 55% from February 2022 to July 2024, as platforms patched exploited weaknesses and attackers moved on to new targets.

Four attack types accounted for more than 81% of losses: price oracle attacks, donate function logic exploits, reentrancy attacks — a flaw that lets a malicious contract repeatedly draw on a protocol before its records update — and a single governance attack, in which borrowed tokens are used to sway a protocol's own voting process, that cost $181 million.

Attack activity moved through phases of growth and consolidation, which the authors write suggests platforms improved their security after attacks while attackers searched for new vulnerabilities.

Inside the aftermath

The study drew on an interview with one platform that suffered a major flash loan attack, granted anonymity at its request. The platform's representative said the exploited bug had passed "ourselves and several of the auditors" and went unnoticed on-chain for more than a year — an account that illustrates why even audited DeFi code can hide flaws until an attacker finds them first.

The attacker then began "taunting" the platform on social media afterward, Hall said, which "led to some victims engaging with the attacker and outlining the devastating impacts that the loss of this money had on them."

The representative divided attackers into "hobbyist individual researchers" and professional state-level or organized crime groups, citing North Korea. From a blockchain security perspective, the professionals' attacks "are not at all advanced," the representative added.

The same representative described the toll on teams that suffer attacks, saying that "most often it ends up fracturing them and destroying them," even when funds recovered.

"Not existential"

Despite the scale of the losses, the paper found that losses exceeded 0.5% of the value borrowed through flash loans in only one six-month period, and flash loan use kept growing throughout the study window — a sign that the lending mechanism itself remains in demand even as it is repeatedly turned into a weapon.

The authors characterize flash loan attacks as significant, increasingly sophisticated and unpredictable threats to DeFi, "but not existential" ones.

The risk has persisted beyond the study period. In October 2025, decentralized exchange Bunni shut down after an $8.4 million exploit that used flash loans, saying it could not afford the cost of a secure relaunch.

"We are keen that this isn't seen just as a piece of academic research," Hall said. "The analysis we did has a host of applications for the cryptocurrency industry, for regulators and for legal and law enforcement agencies."