Article navigation
Purpose

This paper aims to explore attacks on the decentralized finance (DeFi) ecosystem through the case of flash loan attacks (FLAs). FLAs use flash loans, a novel form of lending developed in the DeFi ecosystem, to steal cryptocurrency assets. FLAs have been identified as serious emergent threats to the DeFi ecosystem with the potential to cause significant financial losses.

Design/methodology/approach

The paper used data from a massive on-chain analysis to identify all FLAs on seven major blockchains between February 2020 and July 2024, an analysis of public discussions of FLAs and an interview with a victimized platform.

Findings

The paper identified 254 successful attacks on the DeFi ecosystem resulting in losses of US$ 6.568bn. 72 of these were FLAs, resulting in losses of US$ 1.211bn. It identified 14 different types of FLA that either ‘manipulated price feeds’ (MPF attacks) or ‘exploited (flaws in) the underlying protocol logic’ of platforms in various ways (EUPL attacks). The analysis revealed distinctive temporal patterns of FLA activity.

Originality/value

Crimes targeting the DeFi ecosystem have grown significantly, producing a growing literature primarily from cybersecurity and cognate perspectives. This is true of the limited FLA literature to date. Despite an emergent interest in cryptocurrencies and the advocacy of criminological contributions, very little is known about attacks on the DeFi ecosystem from a criminological perspective. This paper aimed to extend understandings of FLAs specifically, and crimes targeting the DeFi ecosystem more generally, by applying a criminological lens for the first time to FLAs.

Licensed re-use rights only
You do not currently have access to this content.
Don't already have an account? Register

Purchased this content as a guest? Enter your email address to restore access.

Pay-Per-View Access
$41.00
Rental

or Create an Account

Close subscription notice
Close access options