Share this article

DeFi Protocol Cream Finance Hacked for Second Time This Year

The attacked drained just over $25 million of AMP tokens and ether.

Updated May 11, 2023, 4:12 p.m. Published Aug 30, 2021, 8:08 a.m.
Hacker (Azamat E/Unsplash, modified by CoinDesk)

Cream Finance, a decentralized finance (DeFi) lending protocol, suffered its second flash loan attack this year, with the perpetrators draining more than $25 million.

jwp-player-placeholder
STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters
  • The attack was first reported by PeckShield in a tweet early on Monday. The blockchain security firm pointed to Ethereum records showing at least $6 million were drained at 5:44 UTC.
  • Cream Finance later confirmed the hack in a tweet, adding that 418,311,571 AMP tokens and 1,308.09 ether had been stolen, bringing the total value of the hack to just over $25 million. PeckShield updated its estimate, saying the hacker siphoned off about $18.8 million.
  • The root cause of the incident was lending of AMP tokens, Cream Finance Product Manager Eason Wu said on Discord. Other assets on Cream are secure, he said.
  • AMP token contracts allowed for a reentrancy attack, the same type of exploit used in the infamous DAO hack.
  • Flash loan attacks take advantage of one of DeFi’s most controversial features: loans that do not require collateral.
  • Cream Finance lost $37 million in the attack earlier this year.

UPDATE (AUG. 30, 9:13 UTC): Updates value, adds details from Cream Finance tweet.

UPDATE (AUG. 30, 10:22 UTC) Adds updated estimate from PeckShield.

More For You

Pudgy Penguins: A New Blueprint for Tokenized Culture

Pudgy Title Image

Pudgy Penguins is building a multi-vertical consumer IP platform — combining phygital products, games, NFTs and PENGU to monetize culture at scale.

What to know:

Pudgy Penguins is emerging as one of the strongest NFT-native brands of this cycle, shifting from speculative “digital luxury goods” into a multi-vertical consumer IP platform. Its strategy is to acquire users through mainstream channels first; toys, retail partnerships and viral media, then onboard them into Web3 through games, NFTs and the PENGU token.

The ecosystem now spans phygital products (> $13M retail sales and >1M units sold), games and experiences (Pudgy Party surpassed 500k downloads in two weeks), and a widely distributed token (airdropped to 6M+ wallets). While the market is currently pricing Pudgy at a premium relative to traditional IP peers, sustained success depends on execution across retail expansion, gaming adoption and deeper token utility.

More For You

Standard Chartered says U.S. regional banks most at risk in $500 billion stablecoin shift

Stablecoin networks (Unsplash, modified by CoinDesk)

The delay of market structure legislation highlights a growing threat to domestic lenders as digital dollars begin to cannibalize traditional bank deposits.

What to know:

  • Standard Chartered warned that U.S. regional banks are the most exposed to stablecoin disruption due to their heavy reliance on net interest margin (NIM) for revenue.
  • The bank projected that one-third of the growing stablecoin market will be sourced from developed market bank deposits, totaling an estimated $500 billion outflow by 2028.
  • A legislative standoff over whether stablecoin providers can pay interest is stalling market structure legislation, though Standard Chartered still expects a March passage.