Alpha Finance Hack
What happened
On February 13, 2021, Alpha Homora V2 was exploited through its protocol-to-protocol credit line with C.R.E.A.M.'s Iron Bank. The attacker turned a debt-share accounting edge case in an unused sUSD market into approximately $38 million of unauthorized borrowing.
Debt-share accounting did not preserve its invariants in an empty market: rounding could leave a residual share, and permissionless reserve resolution increased total debt without a matching increase in total shares. Subsequent borrows could therefore receive zero debt shares.
Case & protocol details
Attack Timeline
The attacker became the first and only sUSD borrower, then used a rounding error to leave one debt share after repaying. Because resolveReserve could add total debt without adding debt shares, the attacker repeatedly expanded the debt while later borrows rounded to zero shares. A custom spell and flash-loan liquidity made it possible to use the resulting position to borrow WETH, DAI, USDC, and USDT from Iron Bank.
Funds Recovery
Recovered
$3.7M
Net Loss
$33,787,500
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report blog.alphaventuredao.io
- report Post-mortem rekt.news
- report Post-mortem medium.com
- transaction Transaction etherscan.io
- analysis Blog reference blog.alphafinance.io
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.