{"id":51875,"date":"2021-10-27T17:53:36","date_gmt":"2021-10-27T14:53:36","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=51875"},"modified":"2025-09-03T02:03:28","modified_gmt":"2025-09-02T23:03:28","slug":"cream-finance-defi-protocol-hacked-again","status":"publish","type":"post","link":"https:\/\/forklog.com\/en\/cream-finance-defi-protocol-hacked-again\/","title":{"rendered":"Cream Finance DeFi protocol hacked again"},"content":{"rendered":"<p>The decentralized Cream Finance protocol has been hacked once again. This was noted by The Block analyst Igor Igamberdiev.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Looks like <a href=\"https:\/\/twitter.com\/CreamdotFinance?ref_src=twsrc%5Etfw\">@CreamdotFinance<\/a> is dead boys <a href=\"https:\/\/t.co\/3LlWkonoOO\">pic.twitter.com\/3LlWkonoOO<\/a><\/p>\n<p>\u2014 Igor Igamberdiev (@FrankResearcher) <a href=\"https:\/\/twitter.com\/FrankResearcher\/status\/1453367501778264065?ref_src=twsrc%5Etfw\">October 27, 2021<\/a><\/p><\/blockquote>\n<p> <script async=\"\" src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<div class=\"wp-block-text-wrappers-update-2 article_update\"><time class=\"gtb_text-wrappers_update_time\">28 October 2021 | 11:58<\/time><span class=\"gtb_text-wrappers_update_head\">Update: <\/span><\/p>\n<p>The Cream Finance team estimated the damage from the attack at $130 million. Working with developers from yearn.finance, the administration managed to identify and patch the vulnerability. Further details were promised to be disclosed later.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">With the help of friends from <a href=\"https:\/\/twitter.com\/iearnfinance?ref_src=twsrc%5Etfw\">@iearnfinance<\/a> and others in the community, we were able to identify the vulnerabilities and patch them. <\/p>\n<p>In the meantime, we\u2019ve paused our v1 lending markets on Ethereum and we\u2019re in the process of putting together a post-mortem review.<\/p>\n<p>\u2014 Cream Finance \ud83c\udf66 (@CreamdotFinance) <a href=\"https:\/\/twitter.com\/CreamdotFinance\/status\/1453455808239312896?ref_src=twsrc%5Etfw\">October 27, 2021<\/a><\/p><\/blockquote>\n<p> <script async=\"\" src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div>\n<p>According to <a href=\"https:\/\/etherscan.io\/tx\/0x0fe2542079644e107cbf13690eb9c2c65963ccb79089ff96bfaf8dced2331c92\">Etherscan<\/a>, an unknown actor used a flash loan in a complex transaction. The fee exceeded 9 ETH ($36,879 at the time). Most of the stolen assets consisted of Cream Finance liquidity-provider tokens and other ERC-20 coins.<\/p>\n<p>The hacker also left a message: \u201cBaave was lucky, Iron Bank was lucky, Cream isn\u2019t.\u201d Likely referring to the Aave, Iron Bank and Cream Finance projects.<\/p>\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"123\" src=\"https:\/\/forklog.com\/wp-content\/uploads\/Snimok-ekrana-2021-10-27-v-20.07.29-1024x123.png\" alt=\"DeFi-\u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b Cream Finance \u0441\u043d\u043e\u0432\u0430 \u043f\u043e\u0434\u0432\u0435\u0440\u0433\u0441\u044f \u0432\u0437\u043b\u043e\u043c\u0443\" class=\"wp-image-154197\" srcset=\"https:\/\/forklog.com\/wp-content\/uploads\/Snimok-ekrana-2021-10-27-v-20.07.29-1024x123.png 1024w, https:\/\/forklog.com\/wp-content\/uploads\/Snimok-ekrana-2021-10-27-v-20.07.29-300x36.png 300w, https:\/\/forklog.com\/wp-content\/uploads\/Snimok-ekrana-2021-10-27-v-20.07.29-768x92.png 768w, https:\/\/forklog.com\/wp-content\/uploads\/Snimok-ekrana-2021-10-27-v-20.07.29.png 1362w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>Data: <a href=\"https:\/\/etherscan.io\/tx\/0x0fe2542079644e107cbf13690eb9c2c65963ccb79089ff96bfaf8dced2331c92#ContentPlaceHolder1_collapseContent\">Etherscan<\/a>.<\/figcaption><\/figure>\n<p>Representatives of the project said they are studying the exploit and will disclose details as they become available.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">We are investigating an exploit on C.R.E.A.M. v1 on Ethereum and will share updates as soon as they are available.<\/p>\n<p>\u2014 Cream Finance \ud83c\udf66 (@CreamdotFinance) <a href=\"https:\/\/twitter.com\/CreamdotFinance\/status\/1453377073699983366?ref_src=twsrc%5Etfw\">October 27, 2021<\/a><\/p><\/blockquote>\n<p> <script async=\"\" src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p><meta charset=\"utf-8\">According to The Block, the loss amounted to more than $130 million.<\/p>\n<p>As of writing, the project\u2019s token had fallen 28.1% in the last hour, according to CoinGecko.<\/p>\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"581\" src=\"https:\/\/forklog.com\/wp-content\/uploads\/CREAMUSDT_2021-10-27_18-06-48-1024x581.png\" alt=\"DeFi-\u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b Cream Finance \u0441\u043d\u043e\u0432\u0430 \u043f\u043e\u0434\u0432\u0435\u0440\u0433\u0441\u044f \u0432\u0437\u043b\u043e\u043c\u0443\" class=\"wp-image-154167\" srcset=\"https:\/\/forklog.com\/wp-content\/uploads\/CREAMUSDT_2021-10-27_18-06-48-1024w.png 1024w, https:\/\/forklog.com\/wp-content\/uploads\/CREAMUSDT_2021-10-27_18-06-48-300x170.png 300w, https:\/\/forklog.com\/wp-content\/uploads\/CREAMUSDT_2021-10-27_18-06-48-768x436.png 768w, https:\/\/forklog.com\/wp-content\/uploads\/CREAMUSDT_2021-10-27_18-06-48.png 1084w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>Chart: Cream\/USDT on FTX. Data: <a href=\"https:\/\/ru.tradingview.com\/symbols\/CREAMUSDT\/\">TradingView<\/a>.<\/figcaption><\/figure>\n<div class=\"wp-block-text-wrappers-update-2 article_update\"><time class=\"gtb_text-wrappers_update_time\">27 October 2021 | 20:09<\/time><span class=\"gtb_text-wrappers_update_head\">Update: <\/span><\/p>\n<p>PeckShield, the analytical firm, said that the attack was made possible by an error that \u201callows borrowing all funds in the current lending pools.\u201d<\/p>\n<blockquote class=\"twitter-tweet\" data-conversation=\"none\">\n<p lang=\"en\" dir=\"ltr\">2\/4 The hack is made possible due to a price manipulation bug in CREAM price oracle. And this bug allows a directly transferred yDAI+yUSDC+yUSDT+yTUSD tokens to significantly increase yUSD pricePerShare, which allows for basically borrowing all funds in current lending pools. <a href=\\\"https:\/\/t.co\/oETHCPiuWi\\\">pic.twitter.com\/oETHCPiuWi<\/a><\/p>\n<p>\u2014 PeckShield Inc. (@peckshield) <a href=\"https:\/\/twitter.com\/peckshield\/status\/1453399225216102400?ref_src=twsrc%5Etfw\">October 27, 2021<\/a><\/p><\/blockquote>\n<p> <script async=\"\" src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div>\n<p>As a reminder, in February an unknown attacker exploited a vulnerability in the Iron Bank protocol (Cream Finance\u2019s second version) and <a href=\"https:\/\/forklog.com\/en\/news\/hacker-drains-37-5-million-from-cream-finance-defi-protocol\">withdrawn tokens worth $37.5 million<\/a>.<\/p>\n<p>On August 30, the Cream Finance DeFi protocol <a href=\"https:\/\/forklog.com\/en\/news\/hackers-drain-more-than-18m-from-cream-finance-defi-protocol\">came under attack<\/a> with the use of <a href=\"https:\/\/forklog.com\/en\/news\/what-are-flash-loans\">a flash loan<\/a>. The damage amounted to 462 079 976 AMP and 2 804 ETH (more than $18 million).<\/p>\n<p>On September 8, the hacker transferred to the project\u2019s multisig wallet <a href=\"https:\/\/forklog.com\/en\/news\/cream-finance-defi-protocol-hacker-returns-17-6-million\">the majority of the stolen sum<\/a> amounting to 5 152.6 ETH.<\/p>\n<p>In early October, developers confirmed that <a href=\"https:\/\/forklog.com\/en\/news\/cream-finance-reports-recovery-of-5152-6-eth-after-hack-hacker-received-10-of-the-stolen-funds\">the project had recovered 5 152.6 ETH<\/a>. The hacker was allowed to keep 10% of the stolen funds \u2013 about 515 ETH \u2013 as a reward for the bug.<\/p>\n<p>Follow ForkLog news on VK!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The decentralized Cream Finance protocol has been hacked once again. This was noted by The Block analyst Igor Igamberdiev.<\/p>\n","protected":false},"author":1,"featured_media":51876,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[2101,1154,1093],"class_list":["post-51875","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-cream-finance","tag-crimes","tag-defi"],"aioseo_notices":[],"amp_enabled":true,"views":"35","promo_type":"1","layout_type":"1","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/51875","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/comments?post=51875"}],"version-history":[{"count":1,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/51875\/revisions"}],"predecessor-version":[{"id":51877,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/51875\/revisions\/51877"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media\/51876"}],"wp:attachment":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media?parent=51875"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/categories?post=51875"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/tags?post=51875"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}