A study in the Journal of Financial Crime counted 72 flash loan attacks among 254 DeFi exploits, with losses of $1.211 billion. Here is what the numbers cover.

Flash loan attacks drained $1.211 billion from DeFi platforms between February 2020 and July 2024, according to research published in the Journal of Financial Crime.
For anyone holding DeFi tokens, the number that matters sits underneath it. Those 72 attacks were 18.44% of the $6.568 billion lost across 254 successful DeFi exploits in the same window, and more than 80% of the flash loan losses happened on Ethereum.
A flash loan is a loan with no collateral, repaid inside the same blockchain transaction. If the repayment fails, the whole transaction unwinds. That makes them useful for arbitrage and liquidations, and it also lets an attacker borrow tens of millions for a few seconds at near-zero cost, which is what the study says happened here.
The paper is by Professor Tim Hall of the University of Winchester and Remo Stieger, a former partner at the Swiss risk intelligence firm SyntiFi. It identified 72 flash loan attacks among 254 successful DeFi attacks between February 2020 and July 2024, causing $6.568 billion in losses, 18.44% of which came from flash loans.
The method was transaction-level rather than press-release-level. The team analysed seven blockchains where flash loans are available, Ethereum, Base, Optimism, Arbitrum, BNB Chain, Avalanche and Polygon, using SyntiFi's ORI engine, which scanned 20.63 billion blockchain transactions. The University of Winchester describes it as the first work to combine criminological analysis with on-chain risk intelligence and to use multiple sources to map attacks on DeFi.
One caveat on the detail below: the paper's full text was behind a paywall, so the methodology and attack-type figures here come from the university's release and the paper's abstract, not from reading the paper end to end.
The researchers sorted the attacks into 14 types, and the 14 fall into two families. Price feed manipulation attacks push an oracle's reported price to a wrong value. The other family exploits flaws in a protocol's own logic. The paper labels them MPF and EUPL.
Four types carried more than 81% of the losses: price oracle attacks, donate function logic exploits, reentrancy attacks, and a single governance attack that cost $181 million. One governance flaw, $181 million.
Hall said the research uncovered crimes that had never been seen before, some "capable of stealing mind-boggling sums of money, often in the tens of millions of dollars."
The mix changed over time. Logic exploits were 28% of flash loan losses between February 2020 and January 2022, then 55% between February 2022 and July 2024. Logic exploits were less frequent but produced higher average losses, which is the pattern you would expect if price feeds got harder to bend and the code around them did not.
Individual attacks ranged from $80,000 to $197 million. Attacks that took $10 million or more accounted for over 88% of all losses.
Set against how much flash loan volume moved, the damage is small. Losses exceeded 0.5% of the value borrowed through flash loans in only one six-month period, and flash loan use kept growing throughout.
The authors read the shape of activity as phases of growth and consolidation. Their conclusion is that platforms improved security after being hit while attackers moved to new vulnerabilities.
The study includes an interview with one platform that suffered a major flash loan attack, granted anonymity at its request. The details there are the most useful part for anyone judging their own risk.
The bug the attacker used had passed the platform's own checks and several auditors, and it went unnoticed on-chain for more than a year. That is the part to sit with: audits found nothing, and the exploit was sitting on a public chain the whole time.
After the attack, the attacker taunted the platform on social media, Hall said, which led some victims to engage with the attacker about what the losses did to them. The representative said attacks usually fracture and destroy the teams behind them, even when funds come back.
The representative split attackers into hobbyist individual researchers and professional state-level or organized crime groups, citing North Korea, and said the professionals' attacks are "not at all advanced" from a blockchain security perspective.
The paper's recommendations on collateral design and oracle design could not be verified from the pages reviewed, so this article makes no claim about them. Nothing in the material names the protocols behind the $80,000 and $197 million extremes, or the protocol that lost $181 million to the governance attack.
The study period also ended before some of the damage it describes as ongoing. Bunni, a decentralized exchange, shut down in October 2025 after an $8.4 million exploit that used flash loans. Its announcement said a secure relaunch would have required six- to seven-figure spending on audits and monitoring it could not fund, and attributed the drain to flash loan manipulation and rounding errors in its Liquidity Distribution Function.
The authors call the attacks significant, increasingly sophisticated and unpredictable, but not existential, threats to DeFi. The university's release is careful to note that flash loans themselves are legal and that the attacks exploit weaknesses in the systems around them.
Hall said the work is meant to be used, not filed away.
"We are keen that this isn't seen just as a piece of academic research," Hall said. "The analysis we did has a host of applications for the cryptocurrency industry, for regulators and for legal and law enforcement agencies."
For a holder, the practical reading is narrow. The $1.211 billion is not spread evenly across DeFi or across chains. It is concentrated on Ethereum, in 72 incidents, and in four attack types, one of which was a single governance attack. The mechanism to watch is the one the paper found growing: logic flaws that internal checks and auditors missed for more than a year.

Visa finds 46% of Asia Pacific consumers may use stablecoins within five years, while CoinShares reports major allocation plans among affluent investors.

Strategy retained billions in stock issuance capacity and flexible cash, but weaker market valuation has raised doubts about funding future Bitcoin buys.

Ether gained 70% in Q3, ahead of bitcoin’s 42%, but its order book depth fell sharply compared with a year earlier.