Flash Loan Exploit Whips Cream Finance For $130 Million

The Cream team confirms $130 million theft in a tweet, token price plummeted but then recovered during the Asia trading day.


Blockworks Exclusive Art by Axel Rangel


key takeaways

  • Another flash loan exploit hits Cream Finance, this time for $130 million
  • Flash loan exploits involve clever arbitrage plays that drain the protocol’s liquidity pools of their assets, devaluing the token for users

Late Wednesday, Blockchain security provider Peckshield identified that a flash loan attack was underway against DeFi lending platform Cream Finance, with attackers attempting to pilfer Cream liquidity provider tokens. In total, $130 million was stolen, according to on-chain data. This comes after two other successful attacks earlier this year, which saw hackers nab $37.5 million in February and $18.8 million in August.

Loading Tweet..

Cream is affiliated with DeFi stalwart Yearn Finance, as a result of a 2020 ‘merger’, but the much larger Yearn family of products was unaffected, according to the group’s Twitter feed.

Loading Tweet..

What is a flash loan exploit?

Flash loan attacks exploit one of the key pillars of DeFi: the ability to obtain leverage without collateral. Flash loans seek to nullify the defining fear of the credit market — the borrower will run off with the money, leaving the lender empty-handed. Sure, collateral like a house as part of a mortgage would partially eliminate this risk, but needing to post collateral to obtain credit is by its nature exclusionary and, for the world of digital assets, might not work as it would require the participation of lenders that are hostile to crypto.

So, the DeFi and digital assets industry has invented the flash loan. This is a specific type of loan which, via the underlying smart contract, allows the borrower to obtain credit, complete a transaction with said credit (the most common of which is to utilize arbitrage opportunities), and then repay the loan all within the same transaction on the blockchain.

A flash loan attack in progress; Source: Ethexplorer

Should any part of the process fail, the entire transaction will be reverted, thereby undoing the loan — meaning that, in theory, the lender has no risk — provided that the smart contract which controls the whole operation has code strong enough to withstand adversarial scrutiny. 

A flash loan attack occurs when the borrower manipulates the markets as the loan is taking place, driving the value of the borrowed token underwater thanks to excess slippage, and then allowing the attacker to buy back the token at a deflated price. Because the slippage and price deflation is limited to one market, the attacker is free to sell the tokens on other markets for the real price and pocket the profits.

Technically, this particular exploit was quite complex, involving multiple Ethereum wallets and dozens of discrete steps. The attacker is now in the process of laundering the stolen funds.

How many DeFi attacks have occurred in 2020?

According to various leaderboards such as Rekt’s DeFi hack list, there has been over $500 million in theft from different kinds of DeFi hacks like flash loan exploits during 2021 including this most recent one from Cream Finance. In total, there has been approximately $1.2 billion stolen from DeFi protocols since the inception of the industry, according to CryptoSec.info.

SEC Chair Gary Gensler has repeatedly said that regulation of the DeFi sector is coming under the guide of consumer protection, and it’s only a matter of time before regulation is implemented.
Cream Finance’s token recovered during the Asia trading day as the market digested news of the exploit, but remains down 25% over the past 24 hours, according to Coingecko.


Upcoming Events

Hilton Metropole | 225 Edgware Rd, London

MON - WED, MARCH 18 - 20, 2024

Crypto’s premier institutional conference returns to London in March 2024. The DAS: London Experience:  Attend expert-led panel discussions and fireside chats  Hear the latest developments regarding the crypto and digital asset regulatory environment directly from policymakers and experts   Grow your network […]

Salt Lake City, UT

WED - FRI, OCTOBER 9 - 11, 2024

Pack your bags, anon — we’re heading west! Join us in the beautiful Salt Lake City for the third installment of Permissionless. Come for the alpha, stay for the fresh air. Permissionless III promises unforgettable panels, killer networking opportunities, and mountains […]

recent research

Frax report cover.jpg


Frax saw continued development in its frxETH liquid staking derivative and Fraxlend money market throughout 2023. Frax V3 introduces an RWA strategy to drive utility to the protocol's cornerstone product, the FRAX stablecoin.


MicroStrategy discloses the purchase of 16,000 bitcoin throughout November


Digital asset firms face potential new regulatory landscape under Treasury’s proposed authority expansion


Uniswap Labs will be providing trading APIs to Talos investors through Fireblocks


DYDX supply will climb by up to 80% after the Friday unlock, but a couple factors make a massive sell-off appear unlikely


Switzerland-based Pando Asset, which has crypto products trading on the SIX Swiss Exchange, now looks to the US


Binance does not hold the required licenses to advertise and serve customers in the Philippines, the country’s securities regulator said