Crema Finance Hack

Reported loss $8.8M
Solana Ethereum
Forged tick-account data plus Solend flash-loan liquidity to inflate fee claims

What happened

On July 2, 2022, Crema Finance, a Solana concentrated-liquidity protocol, was drained through a series of flash-loan-assisted transactions after an attacker used fabricated tick-account fee data to claim fees they had not earned. The protocol halted operations and later confirmed that it had recovered the vast majority of the stolen assets.

Technical root cause

The fee-claim flow trusted a caller-supplied tick account without sufficiently binding it to the legitimate pool and tick state. Since fee calculation relied on data in that account, a fabricated account passed the available validation and produced inflated fee entitlement. The precise code-level predicate is not publicly verifiable because the affected code was closed source.

How it happened

The attacker created a fake tick account, then used Solend flash loans to provide temporary liquidity to Crema pools. The attacker deposited the borrowed assets, invoked the fee-claim path using fabricated tick data, withdrew the liquidity, and repeated the process across pools. CertiK identifies DepositFixTokenType(), Claim(), and WithdrawAllTokenTypes() as the cycle. The proceeds were consolidated into SOL and USDC, bridged through Wormhole to Ethereum, and swapped into ETH.

The attack used several Solana transactions rather than one canonical exploit transaction. Crema later reported recovery of the vast majority of stolen funds. Public reports differ on the recovered dollar value because the returned assets and the incident-time valuations differ, so no single recovery amount is given here.

Protocol details

Classification Protocol Logic / DEX / Improper Account Validation
Protocol Type DEX
Implementation language Rust
Protocol links Website @Crema_Finance

Security review history

  • Bramah Systems 2022-02-03 No public report

Funds Recovery

83.6%

Recovered

$7.4M

Net Loss

$1,439,920

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.