Alpha Finance Hack

TOTAL LOST $37.5M
High Flash Loan Attacks Ethereum

What happened

On February 13, 2021, Alpha Homora V2 was exploited through its protocol-to-protocol credit line with C.R.E.A.M.'s Iron Bank. The attacker turned a debt-share accounting edge case in an unused sUSD market into approximately $38 million of unauthorized borrowing.

Technical Root Cause

Debt-share accounting did not preserve its invariants in an empty market: rounding could leave a residual share, and permissionless reserve resolution increased total debt without a matching increase in total shares. Subsequent borrows could therefore receive zero debt shares.

Case & protocol details

Classification Protocol Logic
Protocol Type Exploit/Flash Loan Attack
Affected asset / contract ALPHA
Smart Contract Language Solidity
Protocol Twitter/X @alphafinancelab

Attack Timeline

The attacker became the first and only sUSD borrower, then used a rounding error to leave one debt share after repaying. Because resolveReserve could add total debt without adding debt shares, the attacker repeatedly expanded the debt while later borrows rounded to zero shares. A custom spell and flash-loan liquidity made it possible to use the resulting position to borrow WETH, DAI, USDC, and USDT from Iron Bank.

Funds Recovery

9.9%

Recovered

$3.7M

Net Loss

$33,787,500

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.