Vampire Attacks Drain Crypto Liquidity with High-Yield Token Rewards
A 'vampire attack' in crypto is a competitive strategy where a new DeFi protocol offers higher token rewards to drain liquidity from an established rival platform. This tactic exploits the structural feature of open-source DeFi, where protocols publish their code under permissive licenses, allowing competitors to fork the entire codebase within hours.
The only moat an established protocol holds is its accumulated liquidity and brand recognition. A well-funded attacker can erode both simultaneously by offering outsized rewards during an initial migration period. The attacking protocol typically announces a migration deadline, after which users who stake their LP tokens receive the highest reward allocation.
One notable example of a vampire attack occurred in 2020 when SushiSwap drained roughly $830 million from Uniswap in under two weeks. SushiSwap launched as a direct fork of Uniswap V2 and offered 1,000 SUSHI tokens per Ethereum block to anyone who staked Uniswap LP tokens in its MasterChef contract.
Protocols defend against vampire attacks by launching their own governance tokens, introducing liquidity lock periods, and building ecosystem integrations that raise user switching costs significantly. The 2026 DeFi landscape has seen institutional capital become the fastest-growing source of DeFi deposits, accounting for roughly a third of new deposits in early 2026.