Telegram (AI) YouTube Facebook X
Ру
Hacker drains $37.5 million from Cream Finance DeFi protocol

Hacker drains $37.5 million from Cream Finance DeFi protocol

The attacker exploited a vulnerability in the Iron Bank DeFi protocol (Cream Finance’s second version) and withdrew tokens totaling $37.5 million.

“We are aware of the potential vulnerability and are studying it. Thank you for your support in our investigation,” said representatives of Cream Finance.

The Block analyst Igor Igamberdiev tallied $37.5 million in losses for the project due to the exploit. He also outlined the hacker’s sequence of actions.

“The attacker used Alpha Homora to borrow funds from IronBank. Each time he borrowed twice as much as in the previous case”.

“He did this via two transactions, each time lending the funds back into IronBank and receiving cySUSD.”

After this he deposited the sUSD into IronBank. This allowed the hacker to continue borrowing and supplying funds, ending up with cySUSD.

“Of course, some sUSD were spent on repaying the flash loan,” the researcher noted.

“A $10 million flash loan was taken, which was also used to increase the number of cySUSD. In the end, cySUSD in his possession reached such a level that it allowed borrowing anything from IronBank”.

Then the hacker borrowed:

  • 13,200 WETH;
  • $3.6 million USDC;
  • $5.6 million USDT;
  • $4.2 million DAI.

After this he deposited stablecoins to various services, including Aave (v2) and Alpha Homora (1000 ETH). Almost 11 000 ETH remained at the hacker’s address, 100 ETH donated to Tornado.Cash, and 1000 ETH sent to the IronBank contract address.

“Of course, some sUSD were spent on repaying the flash loan,” the researcher noted.

На фоне произошедшего он депонировал стейблкоины на различные сервисы, включая Aave (v2) и Alpha Homora (1000 ETH). Почти 11 000 ETH остались на адресе злоумышленника, 100 ETH он пожертвовал сервису микширования Tornado.Cash, а 1000 ETH отправил на адрес контракта IronBank.

На фоне произошедшего цена токена CREAM упала с отметок в районе $290 до $220.

Earlier, on February 5, an unknown hacker drained $2.8 million from the yEarn.Finance pool. The DeFi project reimbursed the pool’s losses as a result of the attack.

Subscribe to ForkLog on YouTube!

Подписывайтесь на ForkLog в социальных сетях

Telegram (основной канал) Facebook X
Нашли ошибку в тексте? Выделите ее и нажмите CTRL+ENTER

Рассылки ForkLog: держите руку на пульсе биткоин-индустрии!

We use cookies to improve the quality of our service.

By using this website, you agree to the Privacy policy.

OK