Cream Finance Hack

TOTAL LOST $36.2M
High Flash Loan Attacks

What happened

Cream's Ethereum v1 AMP market was exploited when AMP's ERC777-style transfer hook re-entered Cream's borrow flow before its accounting was updated. The attacker repeatedly borrowed against the same collateral, then used liquidation to extract ETH and AMP. Cream reported 462,079,976 AMP and 2,804.96 ETH lost; the main attacker later returned 5,152.6 ETH to the protocol multisig.

Case & protocol details

Classification Borrowing and Lending
Protocol Type Exploit/Other
Affected asset / contract CREAM
Official Website cream.finance/
Protocol Twitter/X @CreamdotFinance

Attack Timeline

Cream transferred AMP during borrowing before updating the borrower's accounting. AMP's ERC777-style post-transfer hook called the attacker contract, which re-entered borrow with the same collateral still available. Repeating this sequence created excess borrowing power and enabled liquidation-based extraction of ETH and AMP.

Flash loans supplied execution capital but the root cause was the unsafe external call before accounting effects. The return of 5,152.6 ETH was a partial recovery, not confirmation that all lost assets were recovered.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.