Key Points
- A study in the “Journal of Financial Crimes” indicates that between February 2020 and July 2024, flash loan attacks resulted in losses of $1.211 billion across 72 incidents.
- This is equivalent to 18.44% of the total losses of $6.568 billion from various attacks during the same period for DeFi, with over 80% of the losses from flash loans occurring on Ethereum.
- Although attacks that exploit logical flaws in protocols are less common, they come at a higher cost; as platforms patch the vulnerabilities that have been exploited, attackers have turned to new flaws, and the significance of such attacks has increased.
According to a study recently published in the Journal of Financial Crimes, between February 2020 and July 2024, flash loan attacks withdrew $1.211 billion from decentralized financial platforms.
This research was conducted jointly by Professor Tim Hall from the University of Winchester and Remo Stieger, a former partner of Swiss risk intelligence company SyntiFi. The study identified that among 254 successful attacks in the DeFi domain during this period, 72 were lightning loan attacks. These 254 attacks resulted in a total loss of 6.568 billion US dollars, of which 18.44% came from lightning loan attacks.
Hall stated in a declaration: "What we are witnessing now is a form of crime that has never been seen before," some of which "are capable of stealing astonishing amounts of funds, often reaching tens of millions of dollars."
Flash loans allow users to borrow assets from a liquidity pool without the need for collateral, provided that the loan must be repaid within the same blockchain transaction. Attackers exploit this mechanism to obtain the large amounts of funds required to carry out vulnerability exploits.
Research has found that over 80% of losses from flash loan attacks occur on Ethereum. The losses caused by a single attack range from $80,000 to $197 million, and attacks that steal $10 million or more account for more than 88% of the total losses.
Researchers have identified 14 types of flash loan attacks, which can be categorized into two main categories: one involves manipulating price predictors, and the other exploits flaws in the underlying logic of the protocols. According to the paper, attacks that exploit logical vulnerabilities occur less frequently, but on average, they cause greater losses.
According to the paper, between February 2020 and January 2022, logical vulnerabilities accounted for 28% of losses from flash loan attacks; whereas between February 2022 and July 2024, this proportion rose to 55%.
Four types of attacks account for more than 81% of the losses: price predictor attacks, exploitation of donate function logic vulnerabilities, re-entry attacks, and a separate governance attack, which caused a loss of $181 million.
Lightning Loan Attackers
The author writes that the attack activities went through different stages of growth and consolidation, indicating that the platform improved its security after being attacked, while the attackers continued to look for new vulnerabilities.
This study also cited interviews with a platform that had previously suffered a major loan fraud attack. At the request of the affected party, the study did not disclose the identity of that platform. A representative of the platform stated that the exploited vulnerability had "escaped our own and several auditing institutions' inspections" and had existed on the blockchain for over a year without being discovered.
This representative categorized attackers into "individual researchers out of interest" and professional national-level or organized criminal groups, specifically mentioning North Korea. The representative stated that from the perspective of blockchain security, the attacks by the latter group "are not considered advanced at all."
This representative also talked about the impact of the attack on the team, stating that "in most cases, this will ultimately lead to the team's division and destruction," even if the funds are later recovered.

The paper found that there was only one six-month period during which the loss exceeded 0.5% of the value borrowed through flash loans, yet the usage of flash loans continued to grow.
The author describes such attacks as posing a “significant, increasingly complex, and difficult to predict” risk to DeFi, but “not a threat to survival.”
After the end of the statistical period for this study, the decentralized exchange Bunni was shut down in October 2025 following an attack that exploited a $8.4 million vulnerability involving lightning loans, and the exchange stated that it could not afford the costs of a secure restart.
Hall indicates: "We very much hope that this will not be seen merely as an academic study. The analysis we have conducted holds great value for the cryptocurrency industry, regulatory authorities, as well as legal and law enforcement departments."












