Flash Loan Exploit Whips Cream Finance For $130 Million

The Cream team confirms $130 million theft in a tweet, token price plummeted but then recovered during the Asia trading day.

article-image

Blockworks Exclusive Art by Axel Rangel

share

key takeaways

  • Another flash loan exploit hits Cream Finance, this time for $130 million
  • Flash loan exploits involve clever arbitrage plays that drain the protocol’s liquidity pools of their assets, devaluing the token for users

Late Wednesday, Blockchain security provider Peckshield identified that a flash loan attack was underway against DeFi lending platform Cream Finance, with attackers attempting to pilfer Cream liquidity provider tokens. In total, $130 million was stolen, according to on-chain data. This comes after two other successful attacks earlier this year, which saw hackers nab $37.5 million in February and $18.8 million in August.

Loading Tweet..

Cream is affiliated with DeFi stalwart Yearn Finance, as a result of a 2020 ‘merger’, but the much larger Yearn family of products was unaffected, according to the group’s Twitter feed.

Loading Tweet..

What is a flash loan exploit?

Flash loan attacks exploit one of the key pillars of DeFi: the ability to obtain leverage without collateral. Flash loans seek to nullify the defining fear of the credit market — the borrower will run off with the money, leaving the lender empty-handed. Sure, collateral like a house as part of a mortgage would partially eliminate this risk, but needing to post collateral to obtain credit is by its nature exclusionary and, for the world of digital assets, might not work as it would require the participation of lenders that are hostile to crypto.

So, the DeFi and digital assets industry has invented the flash loan. This is a specific type of loan which, via the underlying smart contract, allows the borrower to obtain credit, complete a transaction with said credit (the most common of which is to utilize arbitrage opportunities), and then repay the loan all within the same transaction on the blockchain.

A flash loan attack in progress; Source: Ethexplorer

Should any part of the process fail, the entire transaction will be reverted, thereby undoing the loan — meaning that, in theory, the lender has no risk — provided that the smart contract which controls the whole operation has code strong enough to withstand adversarial scrutiny. 

A flash loan attack occurs when the borrower manipulates the markets as the loan is taking place, driving the value of the borrowed token underwater thanks to excess slippage, and then allowing the attacker to buy back the token at a deflated price. Because the slippage and price deflation is limited to one market, the attacker is free to sell the tokens on other markets for the real price and pocket the profits.

Technically, this particular exploit was quite complex, involving multiple Ethereum wallets and dozens of discrete steps. The attacker is now in the process of laundering the stolen funds.

How many DeFi attacks have occurred in 2020?

According to various leaderboards such as Rekt’s DeFi hack list, there has been over $500 million in theft from different kinds of DeFi hacks like flash loan exploits during 2021 including this most recent one from Cream Finance. In total, there has been approximately $1.2 billion stolen from DeFi protocols since the inception of the industry, according to CryptoSec.info.

SEC Chair Gary Gensler has repeatedly said that regulation of the DeFi sector is coming under the guide of consumer protection, and it’s only a matter of time before regulation is implemented.
Cream Finance’s token recovered during the Asia trading day as the market digested news of the exploit, but remains down 25% over the past 24 hours, according to Coingecko.

Tags

Upcoming Events

Salt Lake City, UT

WED - FRI, OCTOBER 9 - 11, 2024

Pack your bags, anon — we’re heading west! Join us in the beautiful Salt Lake City for the third installment of Permissionless. Come for the alpha, stay for the fresh air. Permissionless III promises unforgettable panels, killer networking opportunities, and mountains […]

recent research

ao cover.jpg

Research

Arweave recently launched the testnet for AO computer, a new messaging protocol that will sit atop a PoS network and aims to become a scalable global compute platform through parallel processing and modularity.

article-image

The US spot bitcoin fund category has notched negative net flows over the course of a week just three times since coming to market in January

article-image

Elsewhere, rank-and-file employees move around and Binance’s head of legal in Europe departs

article-image

Plus, a Dragonfly partner shares his view on the crypto VC market, and a mining hardware firm raises $80 million

article-image

Plus, a Bored Ape burger restaurant closes, and Crypto: The Game presses on

article-image

Bitcoin scarcity is a meme, with or without the halvings

article-image

The current state of blockchain interoperability poses an existential threat to the mainstream adoption of blockchain technology as a whole