Cream Finance DeFi Platform Rooked For $29M (2024)

Cream is latest DeFi platform to get fleeced in rash of attacks.

Cream Finance is the latest decentralized finance (DeFi) platform for cryptocurrency trading to take a major financial hit at the hands of hackers, losing nearly $19 million in an attack this week on its “flash loan” feature.

The attacker was able to steal nearly $29 million before being discovered, 418,311,571 in Amp Coin and 1,308.09 in Ethereum cryptocurrency, Cream Finance confirmed.

“We have stopped the exploit by pausing supply and borrow on AMP,” the company statement said. “No other markets were affected.”

https://twitter.com/CreamdotFinance/status/1432249771750686721

DeFi platforms connect various cryptocurrency blockchains to create a decentralized infrastructure for borrowing, trading and other transactions.

Cream Finance Hit With Reentry Attack

According to researchers at PeckShield, a bug in the feature allowed the threat actors to pull off a “reentry attack,” which allows funds to be borrowed on a loop, repeatedly, while the previous transaction is being processed.

“The hack is made possible due to a reentrancy bug introduced by $AMP, which is an ERC777-like token and exploited to re-borrow assets during its transfer, before updating its first borrow,” PeckShield explained.

2/4 The hack is made possible due to a reentrancy bug introduced by $AMP, which is an ERC777-like token and exploited to re-borrow assets during its transfer before updating the first borrow. pic.twitter.com/oVg0w1FWFt

— PeckShield Inc. (@peckshield) August 30, 2021

The attack on Cream Finance comes just days after Poly Networks suffered a $610 million theft, the largest DeFi breach in history, before the money was returned by the attacker in a weird twist, likely after the criminal figured out that stealing the crypto is easier than making a withdrawal.

Solidity Leaves Plenty of Room for Error

The complexity of implementing Solidity coding language used to create DeFi “smart contracts” on a variety of blockchain platforms leaves plenty of room of coding errors, and opportunity for attackers, Joe Stewart with PhishLabs told Threatpost. An error in smart-contract coding is what enabled the Cream Finance reentry attack, Stewart said.

“The recent security breach of the Cream Finance platform was facilitated by the latest in a long chain of smart contract vulnerabilities introduced by human error (or possibly insider attacks),” Stewart said. “Because Solidity is an evolving language, it is very easy to shoot yourself in the foot by something as simple as failing to include the correct function modifier in your code – exactly what happened to the author of the Cream Finance smart contract.”

The layers of complexity are made even more tricky once those DeFi smart contracts start interacting with others,” Stewart added.

“The increasing complexity of DeFi contracts that interact with one another (possibly even across different blockchains) make it difficult to predict all possible code paths that could lead to privilege escalation and loss of funds locked in the contract,” Stewart added. “This is what happened in the recent PolyNetwork hack resulting in $610M being stolen (although subsequently returned by the hacker).”

Tal Be’ery, co-founder of ZenGo, pointed out via tweet that in both the attacks on both Cream and Poly Networks, the threat actors wouldn’t have been able to test their various exploits in a lab environment, they were likely poking around for some time in the systems looking for a hole.

Attackers Sharpening Tools, Attacks

“The attackers had to develop and test their exploits against a real chain, because it’s too complex to set up in a lab,” Be’ery explained. “A good monitoring (and) alert solution might have given enough time to fix.”

A very important corollary from #polynetworkhack .
The attackers had to develop and test their exploits against the real chain, because it's too complex to set it up in the lab.
A good monitoring + alert solution might have given enough time to fix. https://t.co/IdJsunuVLv

— Tal Be'ery (@TalBeerySec) August 15, 2021

As DeFi platforms figure out how to shore up security, Karl Steinkamp with Coalfire warned that threat actors, motivated by volatile crypto-bubbles, are working overtime to refine attacks.

“Given the generally appreciating value of crypto-assets, bad actors will likely continue to use them for many more years into the future,” Steinkamp told Threatpost. “While it has been seen currently to a limited extent over the last 10 years, bad cybercriminals will need to get smarter in using blockchains and crypto if they are going to be successful, which will likely include mixing tools and more off-chain and/or hardware addressed wallets.”

And the most recent data shows DeFi platforms were on the receiving end of 76 percent of all major hacks in 2021 and even before the Poly Networks hack, losses for 2021 had already exploded by 180 percent over last year, according to Atlas VPN.

With rising risk of theft, its going to be up to the DeFi platforms themselves and larger cryptocurrency community to offer some reassurance it’s safe.

“The crypto-industry has generated a lot of excitement; however, many newcomers are unaware of the risks,” Atlas VPN’s researchers said. “Lack of regulation in the crypto-industry allows cybercriminals to thrive either by hacking less secured DeFi projects or by carrying out rug pull scams. For DeFi to become more legitimate, it is essential to establish security and business regulations.”

In the meantime, KnowBe4’s James McQuiggan suggested that users concerned about security should keep their cryptocurrency stored offline.

“Whether reverse-engineering the cryptography or attacking the source, cybercriminals continue to find ways to circumvent controls to steal money for their financial gain and ruin the customers’ portfolios,” McQuiggan said. “It demonstrates that users should maintain offline wallets to protect a large portion of their investments versus having them all in one location and risk losing their entire investment through a data breach or attack.”

Check out our freeupcoming live and on-demand webinar events – unique, dynamic discussions with cybersecurity experts and the Threatpost community.

Cream Finance DeFi Platform Rooked For $29M (2024)

FAQs

What is the largest DeFi platform? ›

The Top DeFi Platforms of 2024
PlatformServicesTransaction Volume
AaveBorrowing and Lending218.22M
LidoStaking108.39M
UniswapToken Exchange /Lending167.35M
MakerBorrowing and Lending /Stablecoin75.23M
6 more rows
Nov 8, 2023

How much is cream finance today? ›

The live Cream Finance price today is $41.15 USD with a 24-hour trading volume of $2,471,568 USD. We update our CREAM to USD price in real-time. Cream Finance is down 1.44% in the last 24 hours. The current CoinMarketCap ranking is #479, with a live market cap of $76,362,850 USD.

What is the DeFi platform? ›

Decentralized finance, or DeFi, uses emerging technology to remove third parties and centralized institutions from financial transactions. The components of DeFi are cryptocurrencies, blockchain technology, and software that allow people to transact financially with each other.

What is a DeFi payment? ›

Decentralized finance uses open-source technology to reduce financial institutions' and banks' control over transactions. DeFi payments eliminate costly processing fees by reducing intermediaries. This leaves the power in merchants' and buyers' hands.

What is the best platform for DeFi? ›

Top 15 Best DeFi Staking Platforms in 2024 (Updated)
  1. AQRU.io. AQRU.io is a leading DeFi staking platform that offers users the opportunity to stake a variety of cryptocurrencies and earn rewards. ...
  2. Binance DeFi Staking. ...
  3. Uniswap. ...
  4. Bake.io. ...
  5. Balancer. ...
  6. Curve Finance. ...
  7. Yearn Finance. ...
  8. Aave.
Feb 27, 2024

What is the strongest DeFi? ›

These 5 DeFi platforms are primed to explode in 2024
  • Tether. 83.44 (0.01%) Buy.
  • BNB. 46,348 (-2.53%) Buy.
  • Ethereum. 244,064 (-2.8%) Buy.
  • Solana. 10,396.41 (-3.31%) Buy.
  • Bitcoin. 4,853,618 (-4.92%) Buy.
Mar 5, 2024

Who is the owner of Cream Finance? ›

Jeffrey Huang and Leo Cheng are the founders of C.R.E.A.M. Finance.

What happen to cream Finance? ›

What happened? On October 27, 2021, at around 7am PST, CREAM Finance suffered an attack via a flash loan. The attack was successful due to a series of sophisticated and advanced steps, and it was likely well-planned beforehand.

Is cream a good investment? ›

Moving Average. On the four-hour time frame, Cream Finance is currently trending bearish with the 50 day moving average currently sloping down. Cream Finance's 200 day moving average is sloping up and has been doing so since 4/26/2024 which means the trend is strong.

What is the most popular DeFi platform? ›

Top 10 Leading DeFi Platforms of 2024
  1. Uniswap. Uniswap stands as a trailblazer in decentralized exchanges, offering an effortless trading experience through automated liquidity pools. ...
  2. Compound Finance. ...
  3. Aave. ...
  4. MakerDAO. ...
  5. SushiSwap. ...
  6. PancakeSwap. ...
  7. Yearn Finance. ...
  8. Curve Finance.
Mar 6, 2024

Who owns DeFi? ›

The ownership structure of DeFi Technologies (TSE:DEFI) stock is a mix of institutional, retail and individual investors. Approximately 0.07% of the company's stock is owned by Institutional Investors, 49.42% is owned by Insiders and 50.51% is owned by Public Companies and Individual Investors.

How do DeFi platforms make money? ›

Decentralised Exchanges

To achieve this, most DEXs use automated market makers (AMMs) whereby liquidity providers send their tokens into a liquidity pool. Akin to traditional lenders and banks, providers offer their liquidity in exchange for interest. DEXs generate DeFi revenue by taking fees for every transaction.

Is DeFi good or bad? ›

Faulty smart contracts are among the most common risks of DeFi. Malicious actors eager to steal users' funds can exploit smart contracts that have weak coding.

What currency does DeFi use? ›

DeFi is making its way into a wide variety of simple and complex financial transactions. It's powered by decentralised applications (dApps), also known as protocols Dapps and protocols handle transactions in the two main cryptocurrencies, Bitcoin (BTC) and Ethereum (ETH).

How do banks use DeFi? ›

With DeFi, lending, trading, and transferring money happen automatically when the conditions of the smart contract are met, as opposed to traditional finance where many people and systems can be involved in processing, verification, and logging of transactions.

What is the largest DeFi? ›

  • UNI. Uniswap. $7.02. -0.69% $182.52M. $4.20B.
  • MKR. Maker. $2,697.00. +1.05% $74.12M. $2.49B.
  • INJ. Injective. $23.72. -1.62% $132.92M. $2.21B.
  • LDO. Lido DAO. $1.92. +0.58% $104.25M. $1.71B.
  • RUNE. THORChain. $4.84. +0.27% $403.29M. $1.62B.
  • JUP. Jupiter. $0.9561. +2.91% $189.67M. ...
  • AAVE. Aave. $83.42. -0.36% $90.20M. ...
  • ENA. Ethena. $0.802. -3.26% $446.84M.

What is the highest volume of DeFi? ›

We track 766 decentralized crypto exchanges with a total 24h trading volume of $4.02 Billion, a -26.18% change in the last 24 hours. Currently, the DeFi volume dominance is at 6.0%, and the 3 largest decentralized exchanges by volume are Uniswap V3 (Ethereum), Jupiter, and Raydium.

Which coin is the king of DeFi? ›

KING OF DEFI Price (KODX)

KODX is a decentralize finance aggregation protocol that delivers a diverse range of staking and lending products all at once. KODX would be put up as collateral to borrow stable coin Such as TRC20-USDT, USDJ.

Top Articles
Latest Posts
Article information

Author: Msgr. Benton Quitzon

Last Updated:

Views: 6276

Rating: 4.2 / 5 (63 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Msgr. Benton Quitzon

Birthday: 2001-08-13

Address: 96487 Kris Cliff, Teresiafurt, WI 95201

Phone: +9418513585781

Job: Senior Designer

Hobby: Calligraphy, Rowing, Vacation, Geocaching, Web surfing, Electronics, Electronics

Introduction: My name is Msgr. Benton Quitzon, I am a comfortable, charming, thankful, happy, adventurous, handsome, precious person who loves writing and wants to share my knowledge and understanding with you.