A study by Professor Tim Hall of the University of Winchester and Remo Stieger identifies 72 flash loan attacks among 254 successful DeFi breaches during the period. These specific attacks accounted for 18.44% of the total $6.568 billion lost to all DeFi crimes. More than 80% of these losses occurred on Ethereum, with individual incidents ranging from $80,000 to $197 million. The research categorizes exploits into price feed manipulations and protocol logic flaws, noting that logic-based attacks were less frequent but significantly more costly.
The data shows a shift in attack methodology over time. Logic exploits represented 28% of flash loan losses between February 2020 and January 2022, rising to 55% from February 2022 to July 2024. Four specific attack types—price oracle, donate function logic, reentrancy, and governance exploits—caused over 81% of the total losses. A single governance attack alone resulted in $181 million in damages. Despite the severity of these incidents, losses exceeded 0.5% of the value borrowed through flash loans in only one six-month period, suggesting that while threats are significant, they have not yet become existential for the sector.
The rise in protocol logic exploits indicates that as basic security hygiene improves, attackers are targeting deeper architectural vulnerabilities rather than simple configuration errors. This evolution suggests that standard auditing processes may be insufficient against sophisticated adversaries who can identify flaws that pass multiple review layers. The concentration of losses on Ethereum highlights the persistent risk associated with its dominant liquidity pools, where the high volume of collateralized assets provides ample targets for uncollateralized borrowing mechanisms.
Institutional adoption faces a complex risk landscape as the distinction between hobbyist researchers and state-level actors blurs. The study’s finding that professional attacks are often technically straightforward implies that the barrier to entry for high-value theft is lower than commonly assumed, relying more on opportunity than advanced cryptographic capability. Regulators and legal agencies must consider that the financial impact extends beyond direct asset loss to include operational fractures within development teams, which can destabilize projects even when funds are recovered.


