Newly published research in the Journal of Financial Crime says flash loan attacks drained $1.211 billion from decentralized finance platforms between February 2020 and July 2024. Professor Tim Hall of the University of Winchester and Remo Stieger, a former partner at Swiss risk intelligence firm SyntiFi, identified 72 flash loan attacks among 254 successful attacks on DeFi during that time. Of those 254 attacks, 18.44% of the losses came from flash loan attacks, with the total losses amounting to $6.568 billion.
The Flash Loan Mechanism
Flash loans let users borrow assets from a liquidity pool without collateral, provided the loan is repaid within the same blockchain transaction. Attackers use them to access the large sums needed to execute an exploit. Decrypt’s study found that individual attacks ranged from $80,000 to $197 million, and those that stole $10 million or more accounted for over 88% of losses.
The Scope of the Damage
Ethereum was where more than 80% of losses from flash loan attacks took place. The researchers found several kinds of attack, among them those that tamper with price feeds and others that take advantage of faults in a protocol’s core logic. The logic-based exploits happened less often, but they carried larger average losses.
How the Attacks Were Categorized
Researchers sorted 14 different kinds of flash loan attack into two main groups: one where attackers manipulate price feeds, and another where they take advantage of errors in a protocol’s logic. Between February 2020 and January 2022, logic exploits made up 28% of the losses from flash loan attacks, while they represented 55% of such losses from February 2022 to July 2024, per the paper.
The Biggest Losses
Four attack types accounted for more than 81% of losses: price oracle attacks, donate function logic exploits, reentrancy attacks and a single governance attack, which cost $181 million.
The Platform Interview
One platform, which requested anonymity, was interviewed for the study after suffering a major flash loan attack. Its representative said that the bug had passed “ourselves and several of the auditors,” before it was discovered, remaining unnoticed on-chain for more than a year.
The attacker began “taunting” the platform on social media afterward, Hall said, which “led to some victims engaging with the attacker and outlining the devastating impacts that the loss of this money had on them.”
The representative divided attackers into “hobbyist individual researchers” and professional state-level or organized crime groups, citing North Korea. From a blockchain security perspective, the professionals’ attacks “are not at all advanced,” the representative said.
The representative spoke about the burden on teams that endure attacks, noting that it persists “most often it ends up fracturing them and destroying them,” even when funds are recovered.
The Pattern of Attack Activity
The authors describe attack activity as passing through stages of growth followed by consolidation, a pattern they say points to platforms strengthening their security in response to attacks even as attackers continued to uncover new weaknesses.
In a single six-month span, losses went past 0.5% of what was borrowed via flash loans, while flash loan use kept growing, according to the paper.
DeFi faces serious, increasingly sophisticated and unpredictable “but not existential” attacks, according to the authors’ description.
What Happened After the Study Period
After the study period concluded, Bunni closed its doors in October 2025, citing the expense of a secure restart as the reason behind the shutdown. The exchange was hit by an $8.4 million exploit that relied on flash loans.
“We are keen that this isn’t seen just as a piece of academic research,” Hall said. “The analysis we did has a host of applications for the cryptocurrency industry, for regulators and for legal and law enforcement agencies.”
The Significance of the Research
The study documents 72 flash loan attacks costing $1.211 billion across 254 DeFi attacks, with logic exploits growing from 28% to 55% of losses over the period.
“We now are seeing crimes that we have never seen before,” Hall said, some “capable of stealing mind-boggling sums of money, often in the tens of millions of dollars.”
Human costs are recorded in the study as well. Some victims connected with their attackers online, and platform teams were described as fractured and destroyed even when funds were recovered.
The State of DeFi Security
Beyond academia is where the study’s authors hope their work lands. They believe regulators, legal authorities and law enforcement agencies must grasp how these attacks operate and how they evolve.
This study serves as an alert rather than a final judgment. The assaults described are substantial, growing in skill and hard to forecast — yet they fall short of being a threat that could end everything.
Source material: “Flash Loan Attacks Drained $1.2B From DeFi Between 2020 and 2024: Study,” Decrypt.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

