Flash loan attacks drained $1.211 billion from DeFi, University of Winchester study finds

Flash loan attacks drained $1.211 billion from DeFi, University of Winchester study finds

Researchers scanned 20.63 billion transactions and found that flash loan exploits grew more sophisticated and harder to predict over four years

Decentralized finance has a security problem, and a new academic study has put a price tag on one corner of it.

Researchers from the University of Winchester and a blockchain risk analyst found that flash loan attacks cost DeFi users $1.211 billion between February 2020 and July 2024. Worse, the attacks became more sophisticated and less predictable as time went on.

What the researchers found

The study was co-authored by Professor Tim Hall of the University of Winchester’s Department of Policing, Criminology and Forensics. His partner on the project was Remo Stieger, formerly of SyntiFi Risk Intelligence.

Together they combed through 20.63 billion transactions across seven blockchains, including Ethereum and BNB Chain.

Across the full study window, the pair identified 254 successful DeFi attacks. Combined losses reached $6.568 billion.

Advertisement

Flash loan attacks made up 72 of those incidents. They accounted for $1.211 billion of the total damage.

The findings were published in the Journal of Financial Crime. The researchers describe their work as the first to combine traditional criminology with on-chain intelligence analysis.

Flash loans, explained without the headache

A user borrows funds without putting anything up, provided the loan is repaid within the same transaction. If repayment fails, the whole thing unwinds as if it never happened.

Flash loans are a legitimate DeFi tool. According to the study, attackers have been exploiting vulnerabilities in decentralized protocols using exactly this mechanism. A flash loan does not create the flaw. It hands an attacker enough temporary firepower to exploit one, often in a single move. The loan gets repaid, and the protocol is left holding the bill.

Professor Hall stressed that these incidents are not victimless crimes. He framed the research as useful for industry participants, regulators and law enforcement alike.

Why sophistication is the real headline

The researchers concluded that flash loan attacks grew more sophisticated and harder to predict over the study period.

What this means for DeFi users and protocols

For anyone depositing funds into DeFi, the study is a reminder that smart contract risk is not theoretical. Across 254 successful attacks and $6.568 billion in losses, the cost of protocol vulnerabilities has been very real.

There is also a regulatory dimension. Peer-reviewed research in a financial crime journal carries weight with policymakers in a way that a forum post or a post-mortem thread does not.

The research also points toward a more collaborative model of defense. By pairing a criminologist with an on-chain risk specialist, the study suggests that stopping these attacks may require more than better code.

For law enforcement, a dataset spanning 20.63 billion transactions across seven chains offers something investigators have often lacked: a systematic view of how DeFi crime has actually unfolded, rather than a collection of isolated incidents.

Disclosure: This article was edited by John Chen. For more information on how we create and review content, see our Editorial Policy.
Flash loan attacks drained $1.211 billion from DeFi, University of Winchester study finds
Flash loan attacks drained $1.211 billion from DeFi, University of Winchester study finds

Researchers scanned 20.63 billion transactions and found that flash loan exploits grew more sophisticated and harder to predict over four years

Share

Add us on Google

Decentralized finance has a security problem, and a new academic study has put a price tag on one corner of it.

Researchers from the University of Winchester and a blockchain risk analyst found that flash loan attacks cost DeFi users $1.211 billion between February 2020 and July 2024. Worse, the attacks became more sophisticated and less predictable as time went on.

What the researchers found

The study was co-authored by Professor Tim Hall of the University of Winchester’s Department of Policing, Criminology and Forensics. His partner on the project was Remo Stieger, formerly of SyntiFi Risk Intelligence.

Together they combed through 20.63 billion transactions across seven blockchains, including Ethereum and BNB Chain.

Across the full study window, the pair identified 254 successful DeFi attacks. Combined losses reached $6.568 billion.

Advertisement

Flash loan attacks made up 72 of those incidents. They accounted for $1.211 billion of the total damage.

The findings were published in the Journal of Financial Crime. The researchers describe their work as the first to combine traditional criminology with on-chain intelligence analysis.

Flash loans, explained without the headache

A user borrows funds without putting anything up, provided the loan is repaid within the same transaction. If repayment fails, the whole thing unwinds as if it never happened.

Flash loans are a legitimate DeFi tool. According to the study, attackers have been exploiting vulnerabilities in decentralized protocols using exactly this mechanism. A flash loan does not create the flaw. It hands an attacker enough temporary firepower to exploit one, often in a single move. The loan gets repaid, and the protocol is left holding the bill.

Professor Hall stressed that these incidents are not victimless crimes. He framed the research as useful for industry participants, regulators and law enforcement alike.

Why sophistication is the real headline

The researchers concluded that flash loan attacks grew more sophisticated and harder to predict over the study period.

What this means for DeFi users and protocols

For anyone depositing funds into DeFi, the study is a reminder that smart contract risk is not theoretical. Across 254 successful attacks and $6.568 billion in losses, the cost of protocol vulnerabilities has been very real.

There is also a regulatory dimension. Peer-reviewed research in a financial crime journal carries weight with policymakers in a way that a forum post or a post-mortem thread does not.

The research also points toward a more collaborative model of defense. By pairing a criminologist with an on-chain risk specialist, the study suggests that stopping these attacks may require more than better code.

For law enforcement, a dataset spanning 20.63 billion transactions across seven chains offers something investigators have often lacked: a systematic view of how DeFi crime has actually unfolded, rather than a collection of isolated incidents.

Disclosure: This article was edited by John Chen. For more information on how we create and review content, see our Editorial Policy.