Alpha Finance Hack
Incident Overview
An attacker exploited a bug in Cream's Iron Bank, resulting in a loss of 13,244.63 WETH, 3.6M USDC, 5.6M USDT, and 4.26M DAI.
The attacker manipulated the system by swapping ETH for UNI, supplying ETH + UNI to the Uniswap pool, and swapping ETH for sUSD on Uniswap. They then deposited sUSD to Cream’s Iron Bank, borrowed 1000e18 sUSD, deposited UNI-WETH LP to WERC20, and used it as collateral. The attacker then repaid the sUSD, leaving a repay share of 1 less than the total share.
This resulted in the attacker's EOA having 1 minisUSD debt and 1 debt share. They then borrowed 19709787742196 minisUSD and transferred it to their EOA, repeating this process 16 times, each time doubling the borrowed amount. The attacker then flash loaned from Aave, swapped USDC for sUSD, and deposited it to Cream to have enough liquidity to borrow using the custom spell.
They continued doubling the sUSD borrow and swapped sUSD for USDC on Curve. They then borrowed 13,244.63 WETH + 3.6M USDC + 5.6M USDT + 4.26M DAI, supplied the stablecoins to Aave, and supplied aDAI, aUSDT, aUSDC to Curve a3Crv pool.
The attacker's address:
https://etherscan.io/address/0x2b528a28…bea6ae#tokentxns
The transactions behind the attack:
https://etherscan.io/tx/0x4441eefe…4dd3ad
https://etherscan.io/tx/0xcc57ac77…e7e571
https://etherscan.io/tx/0xf31ee9d9…20dd41
https://etherscan.io/tx/0x98f623af…c67c0e
https://etherscan.io/tx/0x2e387620…5409e3
https://etherscan.io/tx/0x64de824a…3532a4
https://etherscan.io/tx/0x7eb2436e…3912f9
https://etherscan.io/tx/0xd7a91172…f0e26e
https://etherscan.io/tx/0xacec6ddb…24ba57
https://etherscan.io/tx/0x745ddedf…43eb1b
https://etherscan.io/tx/0xc60bc6ab…2fe896
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Alpha Finance, these are the critical security checks that could have prevented this incident (February 2021).
- Verify all logic paths related to Flashloan Pool Shares Exploit / Flash Loan Attack are guarded by proper access controls and input validation - see the Flash Loans Attacks attack class for patterns
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialFunds Recovery
Recovered
$3.7M
Net Loss
33787500
Related Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Sources & References
- 01
-
02
Reference https://rekt.news/alpha-finance-rekt/
- 03
Learn to Prevent the Next Alpha Finance
The Alpha Finance hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.