Skip to content

Invest2 publishers2 min readPublished

Logic flaws overtook price-feed manipulation as the costlier kind of DeFi flash loan attack

Researchers Tim Hall and Remo Stieger found protocol logic exploits caused 55% of DeFi flash loan losses from 2022 to mid-2024, up from 28% before. For an investor, diligence on a DeFi position moves from price feeds to the design of the contracts themselves.

The Investor · Invest desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Logic flaws overtook price-feed manipulation as the costlier kind of DeFi flash loan attack
Generated illustration

What happened

  • Flash loan attacks were 72 of the 254 successful DeFi attacks from February 2020 to July 2024, accounting for 18.44% of the $6.568 billion lost.
  • The researchers sorted 14 attack types into two groups, price-feed manipulation and flaws in protocol logic, and found logic exploits rarer but costlier on average.
  • Price oracle attacks, donate-function logic exploits, reentrancy attacks and a single $181 million governance attack made up more than 81% of flash loan losses.
  • More than 80% of the flash loan losses occurred on Ethereum, the study found.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • constraint The logic-versus-oracle split covers only the flash loan slice. The other $5.357 billion of DeFi exploit losses, about 82% of the total, needs its own breakdown before it can direct a diligence budget.
  • cost Bunni closed in October 2025 after an $8.4 million flash loan exploit. It could not afford a secure relaunch. An investor has to price a protocol's ability to pay for recovery alongside the bug.
  • precedent Hall said the analysis has "a host of applications for the cryptocurrency industry, for regulators and for legal and law enforcement agencies." This peer-reviewed tally is likely to be cited when DeFi losses come up in enforcement and rule-making.

Divided out, the flash loan attack was the smaller kind of DeFi exploit. The 72 incidents averaged about $16.8 million each [19], against roughly $29.4 million for each of the other 182 successful attacks [20]. The researchers drew the sample from 20.63 billion transactions on seven blockchains [16].

Within the category, the mix turned over. The two groups cover all 14 attack types the researchers identified [7]. Take logic out, and price-feed manipulation fell from about 72% of flash loan losses in the period to January 2022 to about 45% in the period to July 2024 [21]. The authors say the cycles of growth and consolidation suggest platforms fixed what had been hit while attackers went looking for new flaws [11].

One reading of those numbers is that oracle defences matured and the money now sits in contract logic, where it will stay. The second is concentration. Attacks of $10 million or more made up over 88% of losses, with individual hits running from $80,000 to $197 million [10]. The one governance attack was about 15% of the four-year flash loan total by itself [22]. A period share built on a few large incidents can swing back with the next big oracle exploit. The third is scale. Losses topped 0.5% of the value borrowed through flash loans in only one six-month period, while use kept growing [14]. The authors call the attacks significant but "not existential" threats [4].

I think the first reading is mostly right, or rather right about where the losses went and weaker on what a review can do about them. The authors describe the attacks as increasingly sophisticated [4], and Hall said in a statement that "we now are seeing crimes that we have never seen before" [5]. The victim platform the researchers interviewed put it differently. From a blockchain security perspective, the attacks by professional state-level and organized crime groups "are not at all advanced," its representative said [13]. That platform's own bug had passed "ourselves and several of the auditors," the representative said, and went unnoticed on-chain for more than a year [12].

A fund that moves its review hours to protocol design is aiming them at the group of attacks that now costs the most [21]. It also has to stop treating an audit report as clearance. The one victim the paper interviewed had passed several audits before it was hit [12].

What to watch

  • Post-July 2024 incident data collected the same way, to test whether logic exploits stayed above half of flash loan losses.
  • Incident counts behind each period's loss share, showing whether two or three attacks of $10 million or more drive the move from 28% to 55%.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories