{"id":8877,"date":"2021-08-30T10:59:21","date_gmt":"2021-08-30T09:59:21","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=8877"},"modified":"2021-08-30T10:59:30","modified_gmt":"2021-08-30T09:59:30","slug":"cream-finances-defi-platform-suffers-a-19-million-loss-as-a-result-of-a-flash-loan-hack","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/cream-finances-defi-platform-suffers-a-19-million-loss-as-a-result-of-a-flash-loan-hack\/","title":{"rendered":"Cream Finance&#8217;s DeFi platform suffers a $19 million loss as a result of a flash loan hack"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\">Using a reentrancy issue in the AMP token, the Cream <a href=\"https:\/\/coinscreed.com\/staging\/japanese-crypto-exchange-liquid-loses-almost-100m-to-hackers.html\" data-type=\"post\" data-id=\"8367\">Finance hacker<\/a> was able to profit by $18.8 million over the course of 17 transactions. <\/h5>\n\n\n\n<figure class=\"wp-block-image size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"774\" height=\"505\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/08\/image-301.png\" alt=\"Cream Finance's DeFi platform suffers a $19 million loss as a result of a flash loan hack\" class=\"wp-image-8884\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/08\/image-301.png 774w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/08\/image-301-300x196.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/08\/image-301-768x501.png 768w\" sizes=\"(max-width: 774px) 100vw, 774px\" \/><\/figure>\n\n\n\n<p>In a huge exploit, <a href=\"https:\/\/www.google.com\/search?q=Cream+Finance%27s+DeFi+platform+suffers+a+%2419+million+loss+as+a+result+of+a+flash+loan+hack&oq=Cream+Finance%27s+DeFi+platform+suffers+a+%2419+million+loss+as+a+result+of+a+flash+loan+hack&aqs=chrome..69i57.1166j0j7&sourceid=chrome&ie=UTF-8\" data-type=\"URL\" data-id=\"https:\/\/www.google.com\/search?q=Cream+Finance%27s+DeFi+platform+suffers+a+%2419+million+loss+as+a+result+of+a+flash+loan+hack&oq=Cream+Finance%27s+DeFi+platform+suffers+a+%2419+million+loss+as+a+result+of+a+flash+loan+hack&aqs=chrome..69i57.1166j0j7&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noopener\">Cream Finance<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>, a major decentralized finance (DeFi) protocol focusing on lending, was targeted by a hacker who stole approximately $19 million from the platform's cryptocurrency.<\/p>\n\n\n\n<p>According to a study by blockchain security firm Peckshield, an anonymous <a href=\"https:\/\/coinscreed.com\/staging\/japanese-crypto-exchange-liquid-loses-almost-100m-to-hackers.html\" data-type=\"post\" data-id=\"8367\">hacker <\/a>was able to obtain access to $18.8 million in the latest flash loan exploit of the Cream Finance protocol by exploiting a reentrancy issue introduced by the Amp (AMP) token.<\/p>\n\n\n\n<p>Cream Finance, which made the announcement on Monday, stated that the protocol has prevented the exploit by suspending supply and borrow contracts on the <a href=\"https:\/\/coinscreed.com\/staging\/nomura-offers-clients-luxury-italian-restaurant-services-for-token-exchange.html\" data-type=\"post\" data-id=\"8748\">AMP token<\/a>. Cream Finance reported that no other markets were affected.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>C.R.E.A.M. v1 market on Ethereum has suffered an exploit, resulting in a loss of 418,311,571 in AMP and 1,308.09 in ETH, by way of reentrancy on the AMP token contract. <\/p><p>We have stopped the exploit by pausing supply and borrow on AMP. No other markets were affected. <\/p><cite>\u2014 Cream Finance (@CreamdotFinance) August 30, 2021<\/cite><\/blockquote>\n\n\n\n<p>AMP tokens were exploited by the hacker, according to Peckshield, by re-borrowing assets during its transfer and then updating the first to borrow in a total of 17 transactions. According to the security firm, an example transaction might be as follows: &#8220;A hacker takes out a flash loan of 500 ETH and deposits the funds as collateral.&#8221; <\/p>\n\n\n\n<p>The hacker then borrows 19M $AMP and exploits the reentrancy problem to re-borrow 355 ETH during the $AMP token transfer, a total of 355 ETH. The hacker then self-liquidates the borrowed funds.\u201d<\/p>\n\n\n\n<p>\u201cThe funds are still sitting in the address 0xCE1F\u2026.6EDE. After disclosing the hacker's location, Peckshield stated, &#8220;We are actively monitoring this address for any movement.&#8221;<\/p>\n\n\n\n<p>It is an <a href=\"https:\/\/coinscreed.com\/staging\/fenerbahce-a-major-turkish-sports-club-launches-an-ethereum-based-fan-token.html\" data-type=\"post\" data-id=\"7584\">Ethereum-based currency<\/a> that is intended to serve as collateral for payments made through the digital payments network Flexa, according to its creators. The AMP token contract implements the ERC1820 registry smart contract, which is based on the ERC77 standard. <\/p>\n\n\n\n<p>The ERC1820 standard, which was introduced in 2019, defines a smart contract that acts as a universal registry, allowing any address to \u201cregister which interface it supports and which smart contract is responsible for its implementation.\u201d <\/p>\n\n\n\n<p>Any address can register which interface it supports and which smart contract is responsible for its implementation.<\/p>\n\n\n\n<p>AMP token and Cream Finance's native token CREAM both experienced significant price drops as a result of the attack, with AMP falling by over 13 percent in the last 24 hours alone. <\/p>\n\n\n\n<p>According to CoinGecko data, at the time of writing, the AMP token is trading at $0.051908, while the CREAM <a href=\"https:\/\/coinscreed.com\/staging\/defi-project-xtoken-suffers-a-major-second-exploit-since-may.html\" data-type=\"post\" data-id=\"8860\">token <\/a>is selling at $167, down almost 5 percent over the previous 24 hours.<\/p>\n\n\n\n<p>Cream's Iron Bank protocol-to-protocol lending platform was used to commit a $37 million hack against <a href=\"https:\/\/coinscreed.com\/staging\/defi-project-xtoken-suffers-a-major-second-exploit-since-may.html\" data-type=\"post\" data-id=\"8860\">DeFi <\/a>product Alpha Homora in February, according to a previous article by Cointelegraph.<\/p>\n\n\n\n<p>The latest flash loan vulnerability comes amid an increase in the number of hacks and exploits across cryptocurrency systems, both centralized and decentralized, in recent months. <\/p>\n\n\n\n<p>On August 28, the Bilaxy <a href=\"https:\/\/coinscreed.com\/staging\/paws-chicago-now-accepts-cryptocurrency.html\" data-type=\"post\" data-id=\"8547\">cryptocurrency <\/a>exchange was the victim of a large hot wallet breach, which resulted in the compromise of 295 ERC-20 tokens. A cyberattack that occurred on August 19 resulted in the loss of approximately $100 million for Liquid.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Using a reentrancy issue in the AMP token, the Cream Finance hacker was able to profit by $18.8 million over the course of 17 transactions. In a huge exploit, Cream Finance , a major decentralized finance (DeFi) protocol focusing on lending, was targeted by a hacker who stole approximately $19 million from the platform&#8217;s cryptocurrency. [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":8884,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[4132,197,128],"class_list":["post-8877","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-cream-token","tag-defi","tag-ethereum"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/08\/image-301.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/8877","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=8877"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/8877\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/8884"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=8877"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=8877"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=8877"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}