Article 78WYQ Flash loan attackers are ditching oracle manipulation for protocol logic exploits

Flash loan attackers are ditching oracle manipulation for protocol logic exploits

by
Krishi Chowdhary
from Techreport on (#78WYQ)
bMNFt_b4bfWMDQJ1OvgdI_UapCklot-1200x800.jpg

Flash loan attacks have shifted from manipulating price feeds to exploiting flaws in DeFi protocol logic, and the newer approach now does most of the damage, a peer-reviewed study published in the Journal of Financial Crime found.

The study, co-authored by Professor Tim Hall of the University of Winchester's Department of Policing, Criminology and Forensics and Remo Stieger, formerly of SyntiFi Risk Intelligence, tallied 72 flash loan attacks that drained $1.211 billion from decentralized finance platforms between February 2020 and July 2024. Within the same window the researchers identified 254 successful DeFi attacks in total, costing $6.568 billion, with flash loans behind 18.44% of the losses. They scanned 20.63 billion transactions across seven blockchains, including Ethereum and BNB Chain.

From price feeds to code flaws

The researchers sorted the attacks into 14 types across two groups: those that manipulate a protocol's price feed, and those that abuse flaws in the protocol's underlying logic. The balance between the two flipped over the study period. Logic exploits accounted for 28% of flash loan losses between February 2020 and January 2022, and 55% from February 2022 to July 2024, the study found. Just four attack types, price oracle attacks, donate function logic exploits, reentrancy attacks and a single governance attack costing $181 million, accounted for more than 81% of all losses.

A flash loan is a legitimate DeFi mechanism: uncollateralized borrowing that is repaid inside the same blockchain transaction, or the whole transaction reverts. Attackers exploit it when a protocol fails to account for manipulated prices or state within that single transaction, borrowing vast sums at no cost to distort a market moment before it is even committed to the chain.

What the shift means for security

The trend matters for how protocols defend themselves. If early losses came from bad price data, a fixable oracle problem, the majority now comes from bugs in code logic, which audits and hardened price feeds alone do not address. Individual attacks ranged from $80,000 to $197 million, and those stealing $10 million or more accounted for over 88% of losses. More than 80% of the damage occurred on Ethereum.

The authors conclude the attacks grew more sophisticated and harder to predict over the four-year window, and call them significant but not existential" threats: losses exceeded 0.5% of the value borrowed through flash loans in only one six-month period, and flash loan use kept growing. The study window closed in July 2024, so the figures do not cover exploits since then, including the October 2025 shutdown of the decentralized exchange Bunni after an $8.4 million flash loan exploit that it said it could not afford to relaunch securely.

Hall, speaking via the University of Winchester, stressed that these incidents are not victimless crimes" and that the analysis we did has a host of applications for the cryptocurrency industry, for regulators and for legal and law enforcement agencies."


>

The post Flash loan attackers are ditching oracle manipulation for protocol logic exploits appeared first on Techreport.

External Content
Source RSS or Atom Feed
Feed Location https://techreport.com/feed/
Feed Title Techreport
Feed Link https://techreport.com/
Reply 0 comments