Exploit Forces Crema Finance to Temporarily Suspend Services, $8.7 Million Stolen
According to the decentralized finance (defi) protocol Crema Finance, the application was hacked on July 2, 2022. A Twitter account called “Solanafm” says the defi protocol lost around $8.7 million from the attack. Crema...
According to the decentralized finance (defi) protocol Crema Finance, the application was hacked on July 2, 2022. A Twitter account called “Solanafm” says the defi protocol lost around $8.7 million from the attack.
Crema Finance Vulnerability Causes Defi App to Lose Millions — 6 Flashloans Executed
Another defi protocol has lost funds to a hacker as the Solana liquidity application disclosed it was attacked on Saturday, July 2, 2022.
“Attention,” Crema Finance wrote on Saturday. “Our protocol seems to have just experienced a hacking. We temporarily suspended the program and are investigating it. Updates will be shared here ASAP.”
Crema Finance is a concentrated liquidity market maker (CLMM) algorithm built on top of Solana and the Twitter account @solanafm explained the defi app suffered an exploit. “On 2nd July, a vulnerability in the ticks account caused an exploit on Crema Finance for a total amount of $8,782,446,” Solanafm tweeted.
“We worked closely with the Crema team alongside [Ottersec] to break down the movement of the stolen funds following the exploit,” Solanafm added. Ottersec is a blockchain auditing firm that has audited various blockchain smart contracts and infrastructure.
Solanafm says that the hacker siphoned the funds via “6 flash loans on” the Solend Protocol. The attacker also leveraged the Wormhole Exchange to gather the stolen funds.
“Currently, all of the stolen funds are held in the hacker’s ETH wallet and [the] initial SOL wallet,” Solanafm’s Twitter thread concluded.
Ottersec also published a thread on the Crema Finance exploit and the flash loans. “In order to utilize flashloans, the attacker had to deploy their own onchain program,” Ottersec said. “Unfortunately, this program was quickly closed after the exploit.”
“The flashloan calls three key instructions on the Crema contract: ‘DepositFixTokenType,’ ‘Claim,’ and ‘WithdrawAllTokenTypes.’ The attacker is [then] able to deposit and then withdraw the same amount of tokens, while receiving additional tokens from the claim instruction,” Ottersec added.
What do you think about Crema Finance getting hacked for $8.7 million in crypto funds? Let us know what you think about this subject in the comments section below.
Original source
Read on Bitcoin NewsRelated market context
Q2 2026 Sets All-Time High for DeFi Hack Count With ~70 Exploits, $746M Stolen
Q2 2026 has become the most-hacked quarter in DeFi history by incident count, according to DefiLlama, which logged approximately 7...
Blackrock’s IBIT Leads $86 Million Bitcoin ETF Inflow as Ethereum Funds Extend Outflow Streak
Spot bitcoin exchange-traded funds (ETFs) drew $85.85 million in net inflows on Friday, with every one of the 12 tracked funds avo...
Defillama: Q2 2026 Has Been Crypto’s Most-Hacked Quarter on Record With Nearly 70 Exploits
The last three months of 2026 have become the most-hacked quarter in crypto history, with roughly 70 separate exploits draining ab...
Spot bitcoin ETFs snap five-day outflow streak with $85.8 million Friday inflow as ether funds keep sliding
BlackRock's IBIT led Friday's inflows at $57.7 million, with Fidelity's FBTC adding $18.0 million, while no fund reported a net ou...
The future of vaults: neobanks and invisible DeFi
The following is a guest post and opinion from Vincent Maliepaard, VP of Marketing at Sentora. On January 26, 2026, Kraken launche...
Sky Governance Proposal Seeks To Double USDC PSM Buffer To $800 Million
TL;DR BA Labs has proposed doubling key LITE-PSM-USDC-A parameters in the Sky stablecoin system from 400 million to 800 million. T...