Cream Finance Hack
What happened
Cream's Ethereum v1 AMP market was exploited when AMP's ERC777-style transfer hook re-entered Cream's borrow flow before its accounting was updated. The attacker repeatedly borrowed against the same collateral, then used liquidation to extract ETH and AMP. Cream reported 462,079,976 AMP and 2,804.96 ETH lost; the main attacker later returned 5,152.6 ETH to the protocol multisig.
Case & protocol details
Attack Timeline
Cream transferred AMP during borrowing before updating the borrower's accounting. AMP's ERC777-style post-transfer hook called the attacker contract, which re-entered borrow with the same collateral still available. Repeating this sequence created excess borrowing power and enabled liquidation-based extraction of ETH and AMP.
Flash loans supplied execution capital but the root cause was the unsafe external call before accounting effects. The return of 5,152.6 ETH was a partial recovery, not confirmation that all lost assets were recovered.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Post-mortem medium.com
- report Post-mortem rekt.news
- transaction Transaction etherscan.io
- analysis Halborn: Cream Finance hack, August 2021 halborn.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.