Cream Finance Hack

TOTAL LOST $130M
Critical Flash Loan Attacks

What happened

On October 27, 2021, an attacker used flash liquidity to manipulate the Yearn yUSD vault's pricePerShare, which Cream's PriceOracleProxy used to value collateral. After shrinking the vault and directly adding underlying assets, the attacker doubled the reported share price, inflated crYUSD collateral, and borrowed roughly $130 million from Cream's Ethereum v1 markets.

Case & protocol details

Classification Exchange (DEX),Borrowing and Lending
Protocol Type Exploit/Flash Loan Attack
Affected asset / contract CREAM
Official Website cream.finance/
Protocol Twitter/X @CreamdotFinance

Attack Timeline

Cream relied on the Yearn yUSD vault's instantaneous pricePerShare to value crYUSD collateral. The attacker used flash liquidity to create a large collateral position, redeemed most yUSD shares to shrink the vault, then donated underlying assets to sharply raise the reported share price. The manipulated value doubled the apparent collateral and permitted borrowing across Cream's lending markets.

Flash loans made the sequence atomic, but the core failure was a manipulable spot share-price oracle. Yearn later salvaged $9.42 million that had been donated during the manipulation, which was a partial recovery rather than an attacker refund.

Post-Incident Timeline

  • 2022-09-12

    1000 $ETH was swapped for 80 $BTC and bridged using REN protocol from the attacker's second address

  • 2023-03-23

    The Cream Finance team tweeted about their thoughts and findings about the exploited funds. They firmly believe that TradeOgre DEX is actively complicit in laundering the exploited funds for the exploiter, said in the tweet.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.