Fun

Defi Platform Cream Finance Hacked, $29 Million Lost

News Feed - 2021-08-31 05:08:59

Defi Platform Cream Finance Hacked, $29 Million Lost


Cream finance, a defi borrowing and lending protocol, has been the victim of a hack that erased more than $29 million from its vaults. The attacker took advantage of a loophole in the implementation for adding the amp token to the protocol. This is the second time the platform has been involved in a hack. The first breach happened in February, when Cream lost $37.5 million. Cream Protocol Suffers Hack


Cream protocol, a defi lending-borrowing platform present on four different chains (Ethereum, BSC, Polygon, and Fantom), suffered a hack Monday that resulted in the loss of $29 million in several cryptocurrencies. The attacker took advantage of a bug caused by the introduction of the amp token into the protocol. According to Peckshield, a blockchain security and data analytics company, the hack was perpetrated in just one transaction, taking advantage of a reentrancy bug present in the code of the amp currency.


This allowed the hacker to re-borrow assets during the transfer before updating the first borrow. The exploit was repeated 17 times and allowed the hacker to get ahold of 418,311,571 amp (worth $25.1 million) and 1,308.09 ethereum (worth $4.15 million). The platform had been audited by Trails Of Bits, a cybersecurity research and consulting firm, prior to the inclusion of the amp token.


Cream declared it stopped the exploit by pausing supply and borrow on amp. The protocol also informed users that no other markets were affected, and that it was expecting to offer a post mortem report at a later date. Not the First Time


This is not the first time Cream has suffered a hacking incident. Less than six months ago, the platform was also affected by a hack that allowed the attacker to withdraw $37.5 million. The hack, using an unreleased version of a contract of Alpha Finance, another defi protocol, exploited a rounding miscalculation in the code and a whitelisting function. After taking control of the funds, the attacker took them to Tornado.cash, a protocol that allows private transactions in Ethereum.


Luckily, no user funds were affected during this first hack. However, it shows that the defi environment is very complex and that even a small change in protocol (like adding a currency or whitelisting another platform) can have a big impact on security in the future.


What do you think about defi-related hacks? Tell us in the comments section below. British Auction House Christie"s to Present Full Set of NFT Curio Cards on October 1 NEWS | 2 hours ago Blockchain.com CFO Says Company Could IPO in "18-Months," Firm"s Balance Sheet Holds BTC, ETH NEWS | 10 hours ago Tags in this story bug, cream finance, DeFi, Exploit, Hack, Peckshield, Trails Of Bits


Image Credits: Shutterstock, Pixabay, Wiki Commons Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article. Read disclaimerShow comments

News Feed

BlockShow X BlockDown Asia 2024 and Cointelegraph Accelerator to connect startups and VCs at Startup Connect
Helen Partz13 hours agoBlockShow X BlockDown Asia 2024 and Cointelegraph Accelerator to connect startups and VCs at Startup ConnectBlockShow X BlockDown Asia 2024 and Cointelegraph Accelerator are set to host Startup Con
Cred Now Enables LTC Holders to Earn Up to Ten Percent Interest on Their Digital Assets
Cred Now Enables LTC Holders to Earn Up to Ten Percent Interest on Their Digital Assets Cred, a licensed crypto-backed lending and borrowing platform based in California, now sup
MicroStrategy plans $500M stock sale to buy more Bitcoin
Josh O"Sullivan12 hours agoMicroStrategy plans $500M stock sale to buy more BitcoinMicroStrategy plans a $500 million stock sale to fund additional Bitcoin acquisitions, reinforcing its commitment to BTC as a treasury re
$350K Bitcoin? Crypto Investment Firm CEO Predicts Massive Surge
Este artículo también está disponible en español. The Bitcoin space is buzzing again, but this time with eyebrow-raising predictions that seem almost too good to be true.
El Salvador to Add More Geothermal Energy Sources to Power Bitcoin City
El Salvador to Add More Geothermal Energy Sources to Power Bitcoin City The president of El Salvador, Nayib Bukele, has confirmed that the country is making investments to secure a
Assetera launches secondary tokenized RWA market on Polygon
Derek Andersen11 hours agoAssetera launches secondary tokenized RWA market on PolygonAssetera will provide Europe"s first regulated secondary tokenized real-world asset marketplace.1262 Total views1 Total sharesListen to
Bitcoin Demand Soars As BTC Reclaims $82K — Is $100K Within Reach?
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Dogecoin Indicator Flashes A Buy Signal On The 4-Day Chart – Is DOGE Gearing Up For A Rebound?
Este artículo también está disponible en español. Dogecoin (DOGE) is currently trading below the $0.25 level after experiencing massive volatility and price swings in rec
Lessons from CertiK's dispute with Kraken
Shahar Madar3 hours agoLessons from CertiK"s dispute with KrakenWhite hat hacking is a crucial component of cybersecurity, but it can come with controversy — as CertiK and Kraken recently illustrated.159 Total views9
Bitgo Files Lawsuit Against Novogratz’s Galaxy Digital for $100M Over ‘Intentional Breach’ of a Merger Agreement
Bitgo Files Lawsuit Against Novogratz’s Galaxy Digital for $100M Over "Intentional Breach" of a Merger Agreement According to statements made by the digital asset custody busines
UAE residents can now trade crypto directly with their bank accounts
Ezra Reguerra4 hours agoUAE residents can now trade crypto directly with their bank accountsThe new integration enables the direct conversion of UAE dirhams into Bitcoin and Ether using M2’s spot market.3408 Total view
Former Cohasset High School Employee Accused of Stealing Thousands in Electricity to Mine Bitcoin in School Campus Crawlspace
Former Cohasset High School Employee Accused of Stealing Thousands in Electricity to Mine Bitcoin in School Campus Crawlspace A former school assistant facilities director in Cohas