defi

Vampire Attack

A vampire attack is a DeFi competitive strategy where a new protocol drains liquidity from an established rival by copying its codebase and layering on aggressive token incentives. Liquidity providers migrate capital to chase higher yields, causing the incumbent's total value locked to collapse as users swap their deposited LP tokens for the attacker's reward-bearing equivalents.

What Is a Vampire Attack in DeFi?

If you're asking what is a vampire attack defi protocols wage against each other, picture a restaurant opening across the street from a popular diner, serving the exact same menu but giving away free meals for a month. Customers flood in. The original diner empties out. That's the social layer. In DeFi, the mechanics are bloodless but brutal: a competitor forks an incumbent's smart contracts, adds a native governance token with inflated yields, and pays users to migrate their liquidity provider positions over. It's legal. It's transparent. And it can drain hundreds of millions in total value locked within days.

This isn't an exploit. No code is hacked. The attacker simply outbids the incumbent on liquidity mining rewards until yield-hungry farmers capitulate. I've watched this play out since 2020, and the script rarely changes. The attacker launches, emissions explode, TVL rockets, and the target protocol is forced into a binary choice: print tokens to compete and dilute existing holders, or bleed liquidity and lose network effects.

How a Vampire Attack Works (Step by Step)

Most tutorials get this wrong by treating vampire attacks as simple clones. They're not. The economic engineering matters more than the copied code.

  1. Fork the incumbent's codebase. The attacker replicates the target's AMM, lending engine, or NFT marketplace with minor tweaks.
  2. Launch a native reward token. Unlike the target, the attacker introduces a new governance token distributed exclusively to LPs.
  3. Incentivize migration. Users stake their original LP tokens on the attacker's contract. The attacker automatically withdraws the underlying assets from the old protocol and redeposits them into its own pools.
  4. Dump or govern. Early farmers either sell the reward token for instant yield, or hold it to influence protocol direction. Either way, the incumbent's liquidity pool depth evaporates.

Anatomy of a Famous Vampire Attack: SushiSwap vs Uniswap

The SushiSwap incident remains the textbook answer to what is a vampire attack defi developers still study. In September 2020, SushiSwap copied Uniswap V2's AMM contracts verbatim but added SUSHI token rewards that Uniswap didn't offer at the time. Within two weeks, SushiSwap attracted over $1 billion in TVL, much of it siphoned directly from Uniswap's ETH-DAI, ETH-USDC, and ETH-USDT pools. Uniswap's liquidity cratered by approximately 70% before it responded with its own UNI token airdrop and incentive program.

It wasn't subtle. It was economic warfare dressed in yield farming clothing.

FeatureNormal Protocol ForkVampire Attack
Liquidity sourceOrganic or bootstrappedSiphoned from incumbent
Token incentivesModest or noneAggressive, front-loaded
User migrationManual, optionalAutomated via LP token staking
GoalCoexist or niche downDominate or force incumbent response

Why Most Vampire Attacks Collapse

This playbook is wildly overrated. For every SushiSwap that survives long-term, there are twenty protocols that merely rented liquidity, burned through their token treasury, and died.

LooksRare tried the same trick against OpenSea in January 2022, rewarding traders with LOOKS tokens and capturing billions in weekly volume during its first thirty days. Volume eventually collapsed as token emissions tapered and farmers moved to the next shiny incentive. Why? Because vampire attacks optimize for short-term metrics, not product moats. The moment rewards drop, capital flees like water finding a lower elevation.

Warning for LPs: If you're earning 400% APY in a new vampire fork, ask yourself who's subsidizing that yield. Usually, it's token inflation that dilutes your claim, or a founder allocation waiting to dump on retail. Chasing these yields is like taking a construction job that pays double because the contractor stole the crew from the site next door—impressive payroll, shaky foundation.

Vampire Attacks vs Curve Wars

Not all liquidity battles are vampire attacks. The Curve Wars and Liquidity Incentive Battles Between DeFi Protocols represent a different species of competition where protocols bribe voters to direct CRV emissions toward specific pools. That's governance arbitrage. A vampire attack skips the diplomacy entirely and tries to drain the pool outright. One is a lobbying campaign; the other is a heist without a mask.

Similarly, understanding whether incentives are sustainable matters. Our analysis of Liquidity Mining Returns Analysis: Sustainable vs Unsustainable Yields shows that vampire forks almost always fall into the latter category.

Can Protocols Defend Themselves?

Yes, but defense is expensive. Incumbents typically respond by launching their own governance token, retroactively airdropping it to past users, or implementing protocol-owned liquidity to reduce dependence on mercenary capital. The problem? Each defense dilutes existing stakeholders or diverts treasury funds that could have funded actual development.

Understanding what is a vampire attack defi founders fear most starts with recognizing that mercenary capital has no loyalty. In my experience, the best defense isn't a token printer. It's sticky product features—concentrated liquidity ranges, proprietary order flow, or integrations that make migration costly. Code is open source. Liquidity is mercenary. Only user lock-in survives an attack.

External Resources