Key facts
- Flash loan attacks caused $1.21 billion in losses across 72 incidents between February 2020 and July 2024.
- These attacks represented 18.44% of the total $6.57 billion lost to all DeFi attacks in the period.
- Over 80% of flash loan losses occurred on Ethereum.
- Logic exploits became more significant over time, accounting for 55% of losses from February 2022 to July 2024.
- The study identified 14 types of flash loan attacks, categorized into price feed manipulation and protocol logic exploits.
- A single governance attack cost $181 million.
Flash loan attacks have resulted in over $1.21 billion in losses across 72 incidents between February 2020 and July 2024, according to research published in the Journal of Financial Crime. These attacks accounted for 18.44% of the total $6.57 billion lost to all decentralized finance (DeFi) exploits during the period.
The study, conducted by Professor Tim Hall of the University of Winchester and Remo Stieger, a former partner at risk intelligence firm SyntiFi, found that more than 80% of flash loan losses occurred on the Ethereum blockchain. Individual attacks ranged from $80,000 to $197 million, with those stealing $10 million or more comprising over 81% of the total losses.
Researchers identified 14 types of flash loan attacks, broadly categorized into price feed manipulation and exploits of a protocol's underlying logic. While logic exploits were less frequent, they led to higher average losses. The significance of logic exploits grew over time, accounting for 55% of flash loan attack losses in the latter part of the study period (February 2022 to July 2024), compared to 28% in the earlier period (February 2020 to January 2022).
Four specific attack types were responsible for over 81% of the losses: price oracle attacks, donate function logic exploits, reentrancy attacks, and a single governance attack that alone cost $181 million.
The study noted that attack activity evolved, suggesting that platforms improved security in response to incidents, while attackers discovered new vulnerabilities. One platform that suffered a major flash loan attack, which requested anonymity, reported that the exploited bug had passed internal and external audits and remained unnoticed on-chain for over a year. The attacker reportedly taunted the platform on social media afterward.
Attackers were described as either "hobbyist individual researchers" or professional state-level or organized crime groups, with North Korea cited as an example. However, the representative from the attacked platform stated that the professionals' attacks were "not at all advanced" from a blockchain security standpoint. The attacks were characterized as significant and unpredictable, but not existential threats to DeFi.
