Overview
- The peer-reviewed paper, published Oct. 6, 2026, examined 20.63 billion on-chain transactions across seven blockchains and identified 72 flash-loan incidents that caused $1.211 billion in losses between February 2020 and July 2024.
- A flash loan lets a user borrow large sums without collateral inside a single blockchain transaction and repay them in the same transaction, which attackers use to amplify a protocol bug into a large theft.
- The study found attacks became more sophisticated and less predictable over time, with logic-based exploits rising from 28% of flash-loan losses early on to 55% after February 2022.
- More than 80% of flash-loan losses happened on Ethereum, and four attack types — price oracle manipulation, donate-function logic exploits, reentrancy bugs, and one $181 million governance exploit — accounted for over 81% of the total.
- The findings highlight persistent audit and monitoring gaps that can leave bugs on-chain for years, have forced teams and platforms to shut down after thefts, and give firms and regulators a clear dataset to shape defenses and investigations.