DeFi Protocol Cream Finance Hacked for Second Time This Year

The attacked drained just over $25 million of AMP tokens and ether.

AccessTimeIconAug 30, 2021 at 8:08 a.m. UTC
Updated Aug 30, 2021 at 9:27 p.m. UTC

Eliza Gkritsi is CoinDesk's crypto mining reporter based in Asia.

Cream Finance, a decentralized finance (DeFi) lending protocol, suffered its second flash loan attack this year, with the perpetrators draining more than $25 million.

  • The attack was first reported by PeckShield in a tweet early on Monday. The blockchain security firm pointed to Ethereum records showing at least $6 million were drained at 5:44 UTC.
  • Cream Finance later confirmed the hack in a tweet, adding that 418,311,571 AMP tokens and 1,308.09 ether had been stolen, bringing the total value of the hack to just over $25 million. PeckShield updated its estimate, saying the hacker siphoned off about $18.8 million.
  • The root cause of the incident was lending of AMP tokens, Cream Finance Product Manager Eason Wu said on Discord. Other assets on Cream are secure, he said.
  • AMP token contracts allowed for a reentrancy attack, the same type of exploit used in the infamous DAO hack.
  • Flash loan attacks take advantage of one of DeFi’s most controversial features: loans that do not require collateral.
  • Cream Finance lost $37 million in the attack earlier this year.

UPDATE (AUG. 30, 9:13 UTC): Updates value, adds details from Cream Finance tweet.

UPDATE (AUG. 30, 10:22 UTC) Adds updated estimate from PeckShield.


Read more about

DISCLOSURE

Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

The leader in news and information on cryptocurrency, digital assets and the future of money, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. CoinDesk is an independent operating subsidiary of Digital Currency Group, which invests in cryptocurrencies and blockchain startups. As part of their compensation, certain CoinDesk employees, including editorial employees, may receive exposure to DCG equity in the form of stock appreciation rights, which vest over a multi-year period. CoinDesk journalists are not allowed to purchase stock outright in DCG.

CoinDesk - Unknown

Eliza Gkritsi is CoinDesk's crypto mining reporter based in Asia.

CoinDesk - Unknown

Eliza Gkritsi is CoinDesk's crypto mining reporter based in Asia.

Trending

1
CoinDesk - Unknown
Three Arrows Paper Trail Leads to Trading Desk Obscured Via Offshore Entities

As Three Arrows Capital collapsed under market pressure, its much-lesser known trading desk, TPS Capital, remained active, sources say. But a complex ownership structure might frustrate creditors' efforts to collect.

CoinDesk - Unknown
2
CoinDesk - Unknown
June Was Bitcoin’s Worst Month Ever

Plus, European crypto regulation comes into view.

CoinDesk - Unknown
3
CoinDesk - Unknown
What Traders Are Saying About Bitcoin's Biggest Monthly Loss in 11 Years

Poor macroeconomic sentiment, fears of inflation and systemic risks from the crypto market pushed the cryptocurrency below 2017’s highs.

CoinDesk - Unknown
4
CoinDesk - Unknown
Three Arrows Capital Files for Bankruptcy in New York Tied to British Virgin Islands Proceeding

A British Virgin Islands court ordered Three Arrows' BVI branch into liquidation earlier this week.

CoinDesk - Unknown