Flash Loan Exploit Whips Cream Finance For $130 Million

The Cream team confirms $130 million theft in a tweet, token price plummeted but then recovered during the Asia trading day.

article-image

Blockworks Exclusive Art by Axel Rangel

share

key takeaways

  • Another flash loan exploit hits Cream Finance, this time for $130 million
  • Flash loan exploits involve clever arbitrage plays that drain the protocol’s liquidity pools of their assets, devaluing the token for users

Late Wednesday, Blockchain security provider Peckshield identified that a flash loan attack was underway against DeFi lending platform Cream Finance, with attackers attempting to pilfer Cream liquidity provider tokens. In total, $130 million was stolen, according to on-chain data. This comes after two other successful attacks earlier this year, which saw hackers nab $37.5 million in February and $18.8 million in August.

Loading Tweet..

Cream is affiliated with DeFi stalwart Yearn Finance, as a result of a 2020 ‘merger’, but the much larger Yearn family of products was unaffected, according to the group’s Twitter feed.

Loading Tweet..

What is a flash loan exploit?

Flash loan attacks exploit one of the key pillars of DeFi: the ability to obtain leverage without collateral. Flash loans seek to nullify the defining fear of the credit market — the borrower will run off with the money, leaving the lender empty-handed. Sure, collateral like a house as part of a mortgage would partially eliminate this risk, but needing to post collateral to obtain credit is by its nature exclusionary and, for the world of digital assets, might not work as it would require the participation of lenders that are hostile to crypto.

So, the DeFi and digital assets industry has invented the flash loan. This is a specific type of loan which, via the underlying smart contract, allows the borrower to obtain credit, complete a transaction with said credit (the most common of which is to utilize arbitrage opportunities), and then repay the loan all within the same transaction on the blockchain.

A flash loan attack in progress; Source: Ethexplorer

Should any part of the process fail, the entire transaction will be reverted, thereby undoing the loan — meaning that, in theory, the lender has no risk — provided that the smart contract which controls the whole operation has code strong enough to withstand adversarial scrutiny. 

A flash loan attack occurs when the borrower manipulates the markets as the loan is taking place, driving the value of the borrowed token underwater thanks to excess slippage, and then allowing the attacker to buy back the token at a deflated price. Because the slippage and price deflation is limited to one market, the attacker is free to sell the tokens on other markets for the real price and pocket the profits.

Technically, this particular exploit was quite complex, involving multiple Ethereum wallets and dozens of discrete steps. The attacker is now in the process of laundering the stolen funds.

How many DeFi attacks have occurred in 2020?

According to various leaderboards such as Rekt’s DeFi hack list, there has been over $500 million in theft from different kinds of DeFi hacks like flash loan exploits during 2021 including this most recent one from Cream Finance. In total, there has been approximately $1.2 billion stolen from DeFi protocols since the inception of the industry, according to CryptoSec.info.

SEC Chair Gary Gensler has repeatedly said that regulation of the DeFi sector is coming under the guide of consumer protection, and it’s only a matter of time before regulation is implemented.
Cream Finance’s token recovered during the Asia trading day as the market digested news of the exploit, but remains down 25% over the past 24 hours, according to Coingecko.

Tags

Upcoming Events

Salt Lake City, UT

WED - FRI, OCTOBER 9 - 11, 2024

Pack your bags, anon — we’re heading west! Join us in the beautiful Salt Lake City for the third installment of Permissionless. Come for the alpha, stay for the fresh air. Permissionless III promises unforgettable panels, killer networking opportunities, and mountains […]

recent research

Avail.jpg

Research

Data publishing costs have historically been a bottleneck for rollups, and as more rollups launch, interoperability will continue to be a major challenge. Avail presents a potential solution to rollup fragmentation through its three products: Avail DA, Nexus, and Fusion, which together aim to unify the web3 experience.

article-image

Short-term “sell the news” reactions could follow new BTC price peaks months from now, industry watchers say — but only if history repeats itself

article-image

While crypto fundraising remains well off its bull market highs, Q1 data shows capital is returning to the space

article-image

Billed as a better BRC-20 fungible token standard, Bitcoin Runes launches tomorrow

article-image

Bitcoin miners need to explore unconventional energy avenues or be buried by the financial realities created by this halving

article-image

BlackRock’s iShares Bitcoin Trust continues to see daily positive net flows, though its inflow total for a single day hit a new low Wednesday

article-image

Binance is making moves, from receiving a new license in Dubai to switching its SAFU fund to USDC