Flash loan attacks led to $1.211 billion in losses across 72 cases in decentralized finance (DeFi) between February 2020 and July 2024, according to new research published in the Journal of Financial Crime.
Research highlights scale and impact of flash loan exploits
The study, authored by Professor Tim Hall from the University of Winchester and Remo Stieger, a former partner at Swiss risk intelligence company SyntiFi, reviewed 254 successful attacks that together resulted in $6.568 billion in DeFi losses. Flash loan-related incidents made up 18.44% of this overall damage.
Professor Hall stated that the study found crimes of a new nature in the space, with some incidents involving sums “often in the tens of millions of dollars,” highlighting the rapid evolution of digital financial threats.
Professor Hall described the emergence of crimes previously unseen in finance, some capable of removing tens of millions of dollars in a single exploit.
Flash loans are a DeFi tool allowing users to borrow assets from liquidity pools without collateral, provided the loan is repaid within the same blockchain transaction. Attackers can leverage flash loans to access significant capital and execute complex exploits.
Mini dictionary: Flash loan, a type of uncollateralized loan in DeFi that must be borrowed and repaid within a single blockchain transaction. This feature enables quick and complex operations, including arbitrage or, in some cases, attacks.
More than 80% of flash loan attack losses occurred on the Ethereum network during the study period. The report documented individual incidents ranging from $80,000 up to $197 million, with attacks exceeding $10 million making up over 88% of all flash loan-related losses.
| Category | Number of Attacks | Total Losses | % of DeFi Losses |
|---|---|---|---|
| All DeFi Attacks | 254 | $6.568 billion | 100% |
| Flash Loan Attacks | 72 | $1.211 billion | 18.44% |
Shifting tactics and major vulnerabilities
Researchers identified 14 distinct types of flash loan attacks, broadly categorized into price feed manipulations and exploits targeting flaws in protocol logic. While logic exploits were less frequent, they led to higher average losses. The share of losses attributed to logic exploits rose from 28% between February 2020 and January 2022, to 55% between February 2022 and July 2024.
Four attack methods accounted for more than 81% of total losses: price oracle attacks, donate function logic exploits, reentrancy attacks, and a single governance exploit which alone cost $181 million.
Researchers observed that as platforms strengthened security, attackers sought new types of vulnerabilities. The report highlighted phases of growing and consolidating attack patterns, reflecting this cat-and-mouse dynamic in DeFi security.
The paper noted that platforms improved security after significant losses, but attackers continually discovered fresh vulnerabilities, driving waves of new incidents.
The human and technical toll of major attacks
An anonymized platform that experienced a major flash loan attack told the researchers the exploited bug had previously passed internal and external audits and lingered on-chain for over a year before being discovered.
According to the platform representative, attackers included both “hobbyist individual researchers” and coordinated groups, sometimes with state backing. They stated that, from a blockchain security standpoint, even professional attacks were “not at all advanced.”
The study also described how many teams suffered significant internal damage from such incidents, with the representative reporting that project teams are often fractured or destroyed even if some funds are later recovered.
Trends, responses, and ongoing risks
Flash loan losses surpassed 0.5% of all borrowed value in only one six-month interval, with usage of flash loans continuing to increase over the years covered. The authors characterized flash loan attacks as severe and ever more sophisticated but did not see them as threats to the overall existence of the DeFi sector.
After the period studied, decentralized exchange Bunni shut down in October 2025 after losing $8.4 million in a flash loan-based attack, citing the unaffordable cost of a secure relaunch.
Professor Hall emphasized the real-world impact of these findings, stating that their research has multiple applications across the cryptocurrency sector, regulatory bodies, and law enforcement agencies.




