Solana-Based Liquidity Protocol CremaFinance Hacked for $8.7M

CremaFinance said Sunday it was “temporarily” suspending its service while it investigates a debilitating flash loan exploit

article-image

Blockworks exclusive art by axel Rangel

share

key takeaways

  • Hackers raided CremaFinance liquidity pools over the weekend, forcing the protocol to pull the plug
  • The incident is the latest in a string of exploits that have plagued the beleagured decentralized finance sector this year

Solana-based liquidity protocol CremaFinance has become the latest DeFi (decentralized finance) platform to fall victim to hackers.

First brought to attention to users on Saturday, CremaFinance said it was temporarily suspending service and investigating the exploit, believed to have totaled more than $6.4 million in digital assets at the time.

That figure was later revised to stand at over $8.7 million, Solana blockchain explorer SolanaFM said in a tweet. The hacker exploited a vulnerability in the protocol’s tick account, CremaFinance said.

A tick is a dedicated account that stores price “tick data” from a centralized liquidity market maker (CLMM). In DeFi, CLMMs typically calculate transaction fees based on data in the tick account.

In CremaFinance’s case, the authentic transaction fee data was replaced by the hacker’s faked data. This allowed the attacker to claim a “huge fee amount” out of CremaFinance’s liquidity pool, resulting in epic losses.

The hacker deployed a malicious contract and used it to activate six flash loans from Solana lending platform Solend in order to add liquidity on Crema and open their positions, CremaFinance said.

Millions of dollars in various cryptocurrencies, including tether and lido staked solana, were taken. Stolen funds are being held in the hacker’s Ethereum and Solana wallets, which have since been flagged by SolanaFM. CremaFinance is yet to confirm exactly how much crypto was left in its pools.

The firm announced it had raised $5.4 million in a private fundraising round just two weeks ago. CremaFinance is not to be confused with DeFi’s Cream Finance, which has suffered multiple “flash loan exploits” in the last year, including a $130 million hack in October.

But the incident is the latest in a string of DeFi exploits that have plagued the sector this year. Last month, a hacker stole 20 million governance tokens from Ethereum scaling solution Optimism, worth around $30 million at the time, that were intended for a loan deployed by major market maker Wintermute.

In the same month, smart contracts platform Elrond Network witnessed around $4 million siphoned off its decentralized exchange.

Still, those pale in comparison to digital asset bridge Wormhole’s $320-million hack in February and April’s $625-million attack on Axie Infinite’s Ronin bridge — the two largest DeFi thefts to date.


Start your day with top crypto insights from David Canellis and Katherine Ross. Subscribe to the Empire newsletter.

Explore the growing intersection between crypto, macroeconomics, policy and finance with Ben Strack, Casey Wagner and Felix Jauvin. Subscribe to the Forward Guidance newsletter.

Get alpha directly in your inbox with the 0xResearch newsletter — market highlights, charts, degen trade ideas, governance updates, and more.

The Lightspeed newsletter is all things Solana, in your inbox, every day. Subscribe to daily Solana news from Jack Kubinec and Jeff Albus.

Tags

Upcoming Events

Javits Center North | 445 11th Ave

Tues - Thurs, March 18 - 20, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

kamino cover.jpg

Research

Kamino has solidified its position as the leading money market on Solana and is emerging as a DeFi bluechip. Although DeFi competition is fierce, Kamino has kept iterating on its product to provide the best-in-class UX, paired with a robust risk management framework and battle-tested infrastructure. Given the rollout of Kamino Lend V2, the protocol may scale aggressively over the coming months, penetrating previously untapped markets in Solana DeFi.

article-image

Crypto stances vary among candidates vying for Senate seats in Utah, Michigan and Arizona

article-image

Blue Sheets Simple-Earn offers a new route to fixed-rate lending on EVM chains

article-image

True sovereignty isn’t just about financial freedom

article-image

OpenSea co-founder Devin Finzer claims the new OpenSea is being rebuilt “from the ground up”

article-image

A pilot project from Swift, UBS and Chainlink demonstrates how tokenized funds can bridge traditional and crypto rails

article-image

Predictions that the US election will fuel bitcoin’s price are set to be tested