A recent analysis of DeFi incidents between February 2020 and July 2024 identified 72 flash-loan attacks that together erased $1.211 billion from vulnerable platforms. Those incidents represented 18.44% of the $6.568 billion total loss recorded across 254 successful attacks on the sector during the same timeframe.
Predominant target: Ethereum
The research highlighted that over 80% of the monetary damage from flash-loan exploits occurred on Ethereum-based applications. Individual events ranged from modest $80,000 drains to a peak of $197 million, while attacks exceeding $10 million accounted for more than 88% of the overall loss.
Attack classifications and shifting tactics
The investigators catalogued 14 distinct flash-loan attack patterns, which they grouped into two broad categories: price-feed manipulation and exploitation of protocol logic. Although logic-related attacks were less frequent, they produced larger average payouts. Between early 2020 and early 2022, logic exploits comprised 28% of flash-loan losses; that share rose to 55% after February 2022, reflecting a trend toward more complex breach methods.
Four specific vectors dominated the damage landscape, responsible for over 81% of the total: price-oracle manipulation, misuse of donate-function code, reentrancy flaws, and a singular governance exploit that alone cost $181 million.
Evolution of attacker profiles and platform responses
The study distinguished between hobbyist researchers and organized criminal groups, including state-backed actors such as North Korea. Despite the varied motives, the majority of attacks were not technically advanced, according to a platform insider who experienced a major flash-loan breach. The victim platform noted that the exploited bug had passed internal reviews and external audits, remaining hidden on-chain for more than a year before being leveraged.
Following high-profile incidents, many DeFi projects reported periods of heightened security hardening, only to see attackers pivot to newly discovered vulnerabilities. One exchange, Bunni, ultimately ceased operations in October 2025 after an $8.4 million flash-loan exploit rendered a secure relaunch financially untenable.
Implications for regulators and law-enforcement
The authors argue that while flash-loan attacks present a significant and increasingly sophisticated threat, they do not pose an existential risk to the broader DeFi ecosystem. Nonetheless, the magnitude of the losses—exceeding 0.5% of the total value borrowed via flash loans in a single six-month window—underscores the need for clearer regulatory guidance and stronger industry-wide safeguards.
Why it matters
The concentration of flash-loan losses on Ethereum and the growing share of logic-based exploits signal that attackers are adapting to patched vulnerabilities, challenging the resilience of DeFi protocols. As the sector continues to attract capital, understanding these attack vectors is essential for developers, investors, and policymakers seeking to mitigate financial risk while preserving the innovative potential of decentralized finance.




