Cream Finance loses $25M in flash loan attack

Cream Finance loses $25M in flash loan attack

DeFi lending protocol Cream Finance has reportedly lost $25 million in a flash loan attack, the second in the past six months.

The decentralized finance (DeFi) lending and borrowing platform reported that its CREAM V1 market had been targeted on Monday.

According to Cream Finance, the attack was executed via reentrancy on the AMP token contract, a Consensys-backed digital collateral token listed within the dApp. The hacker used a flash loan before exploiting the reentrancy bug.

Vulnerabilities that stem from reentrancy are one of the most common types of security bugs in smart contracts. Meanwhile, blockchain security company PeckShield led the initial analysis revealing that the exploit began when the hacker took out a flash loan of 500 ETH and deposited it as collateral to borrow 19 million AMP tokens. He then re-borrowed 355 ETH by leveraging the reentrancy bug before self-liquidating the loan and repeating the process multiple times to extract funds.

41.8 million AMP tokens and 1308.09 ETH, currently worth about $25 million were stolen during the exploit. Following the attack, the supply and borrowing of AMP tokens have been suspended on the platform.

In February, Cream suffered a similar flash loan attack that led to the loss of roughly $37.5 million worth of cryptocurrency.

While the price of AMP appears to have fallen by 15% since the news broke, Ethereum remains relatively unaffected.

The latest flash loan exploit comes amid the increasing spate of exploits on centralized and decentralized cryptocurrency platforms. Poly Network, Bilaxy, and Liquid have all been exploited recently.

Read more

Tronava Crypto Exchange Limited Strengthens Global Brand with Compliance-Centered Strategy and Institutional-Grade Operations

Tronava Crypto Exchange Limited Strengthens Global Brand with Compliance-Centered Strategy and Institutional-Grade Operations

Tronava Crypto Exchange Limited Strengthens Global Brand with Compliance-Centered Strategy and Institutional-Grade Operations Tronava Crypto Exchange Limited has unveiled its latest brand positioning strategy focused on global regulatory compliance and institutional-grade infrastructure. With licenses from FinCEN and the SEC, and pending approval of a high-level license in Poland, Tronava is

By Albert Morgan
Tronava Crypto Exchange Limited Upgrades Trading System and Establishes Infrastructure in the UK, Poland, Hong Kong, and Singapore to Enhance User Speed

Tronava Crypto Exchange Limited Upgrades Trading System and Establishes Infrastructure in the UK, Poland, Hong Kong, and Singapore to Enhance User Speed

Tronava Crypto Exchange Limited today announced a major upgrade to its proprietary trading system, alongside the establishment of data centers in the United Kingdom, Poland, Hong Kong, and Singapore. This global infrastructure expansion is expected to significantly reduce trading latency and improve real-time execution speed for users across major financial

By Albert Morgan