Flash loan attacks stole about $1.211 billion from DeFi protocols between 2020 and 2024, and hackers are increasingly exploiting flaws in protocol logic rather than manipulating price feeds, according to new research from the University of Winchester.
Professor Tim Hall and Remo Stieger analyzed 254 successful attacks across seven blockchains and found logic weaknesses accounted for 55% of flash-loan losses from February 2022 to July 2024.
Flash loan attack losses reach $1.211 billion
Flash loan attack takes advantage of a unique DeFi lending mechanism that allows users to borrow large amounts of cryptocurrency without conventional collateral, provided the funds are returned within the same blockchain transaction.
The mechanism itself is legitimate and can be used for arbitrage, refinancing and other financial strategies. The security problem arises when borrowed capital is combined with weaknesses elsewhere in a protocol.
Hall and Stieger identified 72 flash-loan incidents during their study period, accounting for $1.211 billion of the $6.568 billion lost across all 254 successful DeFi attacks they analyzed.
The scale of individual incidents was also uneven. Attacks involving at least $10 million represented more than 88% of the losses attributed to flash-loan attacks.
The researchers examined more than 20 billion blockchain transactions to identify attack patterns across Ethereum, Base, Optimism, Arbitrum, BNB Chain, Avalanche and Polygon.
The figures highlight why security risk can have a direct impact on the value locked in DeFi protocols. A vulnerability may remain unnoticed while a protocol grows, only becoming financially significant when an attacker discovers a way to combine it with temporary liquidity.
Flash loan attack tactics shift toward protocol flaws
The research found a notable change in the mechanics behind a Flash loan attack. Between February 2020 and January 2022, price-feed manipulation accounted for roughly 72% of flash-loan losses.
The study identified 14 categories of flash-loan attacks, broadly divided between attacks that manipulated price feeds and those exploiting weaknesses in protocol logic.
Price-oracle attacks, donation-related logic exploits, reentrancy vulnerabilities and one major governance attack together accounted for more than 81% of the losses.
Professor Hall said the research points to a broader change in digital financial crime. He also reinstated that they are seeing crimes that have never been seen before and ones that are capable of stealing mind-boggling sums of money, often in the tens of millions of dollars.
The warning is particularly relevant as DeFi applications become more interconnected and increasingly automate financial activity through smart contracts.
Flash loan attack risk remains serious but manageable
Despite the size of the losses, the researchers did not characterize the threat as an existential danger to DeFi. Their analysis found that borrowing through flash loans continued to increase, while losses exceeded 0.5% of the total value borrowed in only one six-month period.
The researchers therefore described the threat as serious and increasingly sophisticated, rather than one capable of bringing the entire DeFi sector down.
Hall also pointed to the changing behavior of attackers and the defensive response from the industry. As known weaknesses are identified and patched, criminals can move toward less obvious vulnerabilities elsewhere in the financial infrastructure.
This creates a continuing cycle for DeFi developers and security teams. A successful Flash loan attack can expose a weakness, prompting a patch or redesign, while attackers subsequently search for another point of failure.
The research also examined how attackers interact with victims after successful exploits. Hall noted that some attackers have publicly taunted platforms, with those interactions sometimes prompting victims to discuss the financial and operational damage caused by the incident.
The message is straightforward: a project’s security profile should extend beyond whether it has undergone an audit or uses established blockchain infrastructure.
What the Flash loan attack trend means for investors
The changing nature of the Flash loan attack threat gives investors another factor to consider when evaluating DeFi protocols. Smart-contract audits remain important, but the study suggests that security must be treated as an ongoing process rather than a one-time certification.
Investors may want to examine whether a protocol has transparent security documentation, an active bug-bounty program, independent audits, emergency controls and clearly defined procedures for responding to vulnerabilities.
The history of exploits affecting a protocol or its major dependencies can also provide useful information about its risk profile.
The researchers analyzed seven major networks, and the majority of losses were concentrated where significant DeFi activity and liquidity were present.
Ultimately, the study suggests that DeFi security is moving into a more complex phase. Attackers are not simply looking for distorted prices; they are increasingly examining the internal rules that govern how decentralized applications operate.
The research does not suggest that flash loans themselves should disappear from DeFi. Instead, it demonstrates that legitimate financial tools can become powerful attack mechanisms when they are combined with weaknesses in decentralized applications.
As DeFi continues to expand, the ability of protocols to identify and eliminate logic vulnerabilities before attackers exploit them could become just as important as liquidity, yields and token performance.