You've got money parked in a protocol's liquidity pool. It works, fees trickle in, everything's stable. Then a new protocol shows up — same code, nearly the same interface, different sign on the door — offering double the yield for the same deposit. A week later the original protocol has lost half its liquidity. Two weeks later, a quarter of what's left. Nobody got hacked. The liquidity just stood up and walked, because nothing was chaining it there in the first place.
This is called a vampire attack. The name sounds like marketing, but it describes the mechanic with precision: a new protocol doesn't build demand from scratch — it drains liquidity already pooled at a competitor, by forking its code and paying people to switch.
The mechanic: why this is even possible
DeFi runs on open-source code. Anyone can copy Uniswap's or Compound's smart contracts in a day, deploy the copy, and slap a new name on it. Copying is free. The liquidity itself is not — it belongs to thousands of individual users who put it wherever they saw the best yield at that moment.
Here's the actual attack. The attacker doesn't just fork the code — it builds a migration bridge, a contract that accepts the victim protocol's own LP tokens (the receipts representing your share of a pool) directly. You don't need to withdraw from the old pool, pay gas, swap back, and re-deposit into the new one — you just stake your existing LP tokens into the attacker's contract and immediately start earning its new token as a reward. Friction is almost gone. And the reward is generous, because the new token costs the issuer nothing to hand out — it's minted from nothing.
After a set window — sometimes just a couple of weeks — the migrator executes a single action, at a pre-announced block, that pulls all the liquidity accumulated in those staked LP tokens and physically moves it into the attacker's own pools. The victim protocol doesn't lose liquidity gradually. It loses it in one block.
The case that named the phenomenon: SushiSwap vs. Uniswap
The genre-defining episode happened in August–September 2020. Uniswap was, at the time, the largest decentralized exchange, with no governance token of its own — just an open-source public good. An anonymous figure going by Chef Nomi forked Uniswap's code, added a reward token called SUSHI for staking, and launched SushiSwap.
The mechanism was exactly the one described above: users staked their existing Uniswap LP tokens into SushiSwap's contract and farmed SUSHI, while the underlying liquidity physically remained sitting in Uniswap's own pools. The SUSHI yield was high enough that, over roughly two weeks, estimates put anywhere from $800 million to over a billion dollars in liquidity flowing into the migrator contract — a meaningful chunk of all of Uniswap. Then, on a pre-announced block, the contract executed the migration in one shot, and that liquidity physically relocated into SushiSwap's own pools.
The story had a dramatic sequel. Chef Nomi almost immediately sold off his founder allocation of SUSHI for several million dollars' worth of ETH, the token price crashed, the community panicked, control of the project temporarily passed to Sam Bankman-Fried (then head of FTX), and only after sustained public pressure did Chef Nomi return the withdrawn funds to the project treasury. SushiSwap survived and remains a notable player today — but the story of its birth stayed the textbook example of a vampire attack.
Uniswap, for its part, didn't spend months debating a response — it made its own move. In September 2020 it launched the UNI token and retroactively airdropped it to every past user of the protocol, a step many in the industry directly connect to the pressure created by its fork-turned-competitor. The attack didn't kill the victim, but it forced it to change faster than it had planned to.
Mercenary capital: liquidity has no memory
Our record. In the Maat system, Ren is the name — and to speak someone's true name is to hold power over them. A vampire attack works on exactly that principle: the attacker creates no new value, it simply claims for itself what was already accumulated under someone else's name, by offering a louder name for yield. Liquidity here isn't Ba, isn't a conscious will — it holds no loyalty, no memory of where it earned last month's profit. It flows toward the bigger number and drains away the instant a bigger number appears somewhere else. That's not a personal vice — it's the honest physics of capital with no attachment to meaning.
Which is the lesson worth keeping in mind every time you see a headline advertising "400% APY": behind that number is almost always freshly minted token emission, not real economic revenue. The project prints its own token and hands it out as bait, because printing is cheaper than earning. You're not getting a share of the protocol's profit — you're getting a share of its future inflation, denominated in a token whose price holds up exactly as long as new depositors keep arriving.
What this means for you if you provide liquidity
If you're farming yield in DeFi, three things are worth checking before your liquidity drains out from under you, not after:
- Where the yield actually comes from. Fees from real user trades are one thing; freshly minted token emissions are another. The first is sustainable within reasonable limits; the second almost always dilutes you as the token's supply keeps growing.
- Who holds the keys to the migrator contract. If a new protocol accepts your LP tokens directly, find out who can pull the migration trigger and under what conditions — that's concentrated power dressed up as convenience.
- How young the code is. A fork shipped in a week means a fork with no months of battle-tested audit behind it. A fork's higher yield is often exactly that — a premium for unproven risk, not a free lunch.
A vampire attack, on its own, isn't a crime or a hack. It's competition taken to its logical limit in an environment where copying is free and capital owes no loyalty. It doesn't steal anything from the victim protocol that wasn't already yours to move — it just pulls what was already yours in a decision made in seconds, under the pressure of a bigger number on a screen. The one defense that always works is asking where the yield comes from before you walk in, not after the source has already run dry.