Cream Finance Suffers $130 Million Hack
Ethereum defi protocol Cream Finance suffered an exploit yesterday that allowed attackers to steal $130 million from its holdings. The news was first revealed by Peckshield, a blockchain analytics company that discovered...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Ethereum defi protocol Cream Finance suffered an exploit yesterday that allowed attackers to steal $130 million from its holdings. The news was first revealed by Peckshield, a blockchain analytics company that discovered a flash loan had exploited the platform. This is the third hack the protocol has suffered in its history, being exploited for $36 and $29 million before, respectively.
Cream Finance Hacked Yet AgainCream Finance, an Ethereum-based lending and borrowing protocol, suffered an exploit that allowed the hackers to steal $130 million worth of ether and ERC-20 tokens. According to Slowmist, a blockchain security organization, the attack netted 2,760.22 ether and 60 tokens including HBTC, USDT, BUSD, and others. The attack was perpetrated in the form of a series of flash loans in a very unorthodox way, which has led some to think the hacker was an experienced defi developer.
Another blockchain security firm, Peckshield, broke the news, linking to the flash loan that caused the hack via Twitter. The firm supposed the attack was possible due to a bug in a price oracle. The Cream team quickly acknowledged the situation, informing users about the hack. They also stated:
With the help of friends from Yearn Finance and others in the community, we were able to identify the vulnerabilities and patch them. In the meantime, we’ve paused our v1 lending markets on Ethereum and we’re in the process of putting together a post-mortem review.
Suspicious CircumstancesThe Cream Finance team has since been trying to communicate with the hackers, offering to give them 10% of all the tokens that were lost. This is a known strategy that has paid off for some protocols that have been exploited in the past. Still, no response has been received.
The exploit transaction carries an enigmatic message that seems to point in the direction of this being a directed action against the protocol. The message, that also mentioned other protocols, stated:
gÃTµ Baave lucky, iron bank lucky, cream not. ydev : incest bad, dont do.
This is not the first time that Cream has been exploited. The protocol has a rather bad record, having been exploited three times during this year. The first time, in February, the protocol’s Iron Bank lost $36 million in another flash loan attack. After that event, Cream Finance was hacked again in August, when an exploit caused losses of $29 million.
What do you think about Cream Finance’s last exploit and the strange circumstances that surround it? Tell us in the comments section below.
Why this matters
This security story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on Bitcoin NewsRelated market context
A $650 million wave of bridge hacks just triggered a $7 billion mass migration to Chainlink
Chainlink drew more than $7 billion of token value onto its cross-chain infrastructure in the second quarter as institutional adop...
Goldman Sachs backs CLARITY Act, BitMEX shuts down, and bridge hacks steal $31.6 million in a pivotal day for crypto
Goldman Sachs CEO David Solomon backs the CLARITY Act, BitMEX shuts down after 11 years, and two bridge exploits steal over $31.6...
BitMEX to Shut Down After 11 Years as E*TRADE Enters Spot Crypto and Bridge Exploits Hit $31.6 Million
BitMEX closes after 11 years, E*TRADE launches spot crypto trading, bridge exploits steal $31.6 million, and the Senate opposes cl...
Two Ethereum bridges lose $31.7M within hours as third protocol halts staking
AFX and the Verus-Ethereum bridge suffered about $31.69 million in combined losses within hours of each other, while B² Network se...
$BNKR Tumbles After Bankr X Hack Sparks Fake Airdrop Scam Despite Passkey Security
Key Takeaways: The Bankr X account was spoofed to promote fraudulent airdrop links to users. Security fears are emerging due to th...
Robinhood CEO X Hack Shows Why Crypto Scams Still Target Trusted Names
Robinhood CEO Vlad Tenev’s X account was compromised to promote a fake memecoin, giving crypto another reminder that social engine...