Flash Loan Exploit Whips Cream Finance For $130 Million

The Cream team confirms $130 million theft in a tweet, token price plummeted but then recovered during the Asia trading day.

article-image

Blockworks Exclusive Art by Axel Rangel

share

key takeaways

  • Another flash loan exploit hits Cream Finance, this time for $130 million
  • Flash loan exploits involve clever arbitrage plays that drain the protocol’s liquidity pools of their assets, devaluing the token for users

Late Wednesday, Blockchain security provider Peckshield identified that a flash loan attack was underway against DeFi lending platform Cream Finance, with attackers attempting to pilfer Cream liquidity provider tokens. In total, $130 million was stolen, according to on-chain data. This comes after two other successful attacks earlier this year, which saw hackers nab $37.5 million in February and $18.8 million in August.

Loading Tweet..

Cream is affiliated with DeFi stalwart Yearn Finance, as a result of a 2020 ‘merger’, but the much larger Yearn family of products was unaffected, according to the group’s Twitter feed.

Loading Tweet..

What is a flash loan exploit?

Flash loan attacks exploit one of the key pillars of DeFi: the ability to obtain leverage without collateral. Flash loans seek to nullify the defining fear of the credit market — the borrower will run off with the money, leaving the lender empty-handed. Sure, collateral like a house as part of a mortgage would partially eliminate this risk, but needing to post collateral to obtain credit is by its nature exclusionary and, for the world of digital assets, might not work as it would require the participation of lenders that are hostile to crypto.

So, the DeFi and digital assets industry has invented the flash loan. This is a specific type of loan which, via the underlying smart contract, allows the borrower to obtain credit, complete a transaction with said credit (the most common of which is to utilize arbitrage opportunities), and then repay the loan all within the same transaction on the blockchain.

A flash loan attack in progress; Source: Ethexplorer

Should any part of the process fail, the entire transaction will be reverted, thereby undoing the loan — meaning that, in theory, the lender has no risk — provided that the smart contract which controls the whole operation has code strong enough to withstand adversarial scrutiny. 

A flash loan attack occurs when the borrower manipulates the markets as the loan is taking place, driving the value of the borrowed token underwater thanks to excess slippage, and then allowing the attacker to buy back the token at a deflated price. Because the slippage and price deflation is limited to one market, the attacker is free to sell the tokens on other markets for the real price and pocket the profits.

Technically, this particular exploit was quite complex, involving multiple Ethereum wallets and dozens of discrete steps. The attacker is now in the process of laundering the stolen funds.

How many DeFi attacks have occurred in 2020?

According to various leaderboards such as Rekt’s DeFi hack list, there has been over $500 million in theft from different kinds of DeFi hacks like flash loan exploits during 2021 including this most recent one from Cream Finance. In total, there has been approximately $1.2 billion stolen from DeFi protocols since the inception of the industry, according to CryptoSec.info.

SEC Chair Gary Gensler has repeatedly said that regulation of the DeFi sector is coming under the guide of consumer protection, and it’s only a matter of time before regulation is implemented.
Cream Finance’s token recovered during the Asia trading day as the market digested news of the exploit, but remains down 25% over the past 24 hours, according to Coingecko.

Tags

Upcoming Events

Salt Lake City, UT

MON - TUES, OCT. 7 - 8, 2024

Blockworks and Bankless in collaboration with buidlbox are excited to announce the second installment of the Permissionless Hackathon – taking place October 7-8 in Salt Lake City, Utah. We’ve partnered with buidlbox to bring together the brightest minds in crypto for […]

Salt Lake City, UT

WED - FRI, OCTOBER 9 - 11, 2024

Permissionless is a conference for founders, application developers, and users. Come meet the next generation of people building and using crypto.

recent research

Research Report Templates (1).png

Research

Solana Mobile is a highly ambitious foray into the mobile consumer hardware market, seeking to open up a crypto-native distribution channel for mobile-first applications. The market for Solana Mobile devices has demonstrated a phenomenon whereby external market actors (e.g. Solana-native projects) continuously underwrite subsidies to Mobile consumers. The value of these subsidies, coming in the form of airdrops, trial programs, and exclusive NFT mints, have consistently covered the cost of the phone and generated positive returns for consumers. Given this trend in subsidies, the unit economics in the market for Mobile devices, and the initial growth rate and trajectory of sales, it should be expected that Solana mobile can clear 1M to 10M units over the coming years. As more devices circulate amongst users, Solana Mobile presents a promising venue for the emergence of killer-applications uniquely enabled by this mobile-first, crypto-native distribution channel.

article-image

Plus, celebrity memecoins are plummeting from their early price runs

article-image

The FCA claims that CBPL provided e-money services to roughly 13,000 “high-risk” customers

article-image

Plus, breaking down Donald Trump’s shifting crypto stance

article-image

Markets are holding relatively steady despite the supply shock

article-image

Analysts are looking ahead to August, a historically volatile month made more interesting this year by the US presidential election

article-image

Plus, a look into Lighting Labs’ newest feature