/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Hackers steal an estimated $130M from DeFi platform Cream Finance in a flash loan attack; the company lost $37M in Feb. and $29M in Aug. in similar attacks

Hackers have stolen an estimated $130 million worth of cryptocurrency assets from Cream Finance, a decentralized finance (DeFi) …

The Record Catalin Cimpanu

Context & Ripple Effects

Cream Finance's latest loss follows two similar attacks on the same platform earlier in 2021, making it a recurrence rather than an isolated smart-contract failure. It also fits a broader DeFi security pattern that included the Lendf.Me lending-platform theft and a CipherTrace tally showing DeFi represented a large share of crypto thefts in 2020.

The significance is the scale and repetition: a lending protocol built around on-chain transactions has again been exploited through flash-loan mechanics, reinforcing that rapid capital movement can turn a vulnerability into an immediate loss event.

First-order effects

  • Cream Finance has lost an estimated $130 million in cryptocurrency assets and must address a third similar attack within the year.
  • Cream Finance users and counterparties face a protocol whose prior attack history has now expanded from two smaller incidents to a much larger loss.

Second-order effects

  • Other DeFi lending services face sharper pressure to review exposure to the exploit paths that have repeatedly affected lending platforms, from Lendf.Me's token-related exploit to Cream Finance's flash-loan attack.
  • The repeated losses make security controls a more consequential point of competition for DeFi protocols seeking users and liquidity.

Third-order effects

  • If repeated flash-loan losses persist, DeFi lending's growth will be increasingly constrained by whether protocols can demonstrate that composable, instant liquidity does not amplify smart-contract failures.
  • The pattern points toward a DeFi market in which security architecture and exploit resilience become as important to platform credibility as lending and borrowing features.

The trend: DeFi lending is exposing a structural trade-off in composable finance: the same rapid, permissionless liquidity that enables new services can magnify vulnerabilities into large losses.

Discussion

  • @creamdotfinance @creamdotfinance on x
    Our Ethereum C.R.E.A.M. v1 lending markets were exploited and liquidity was removed on October 27, 1354 UTC. The attacker removed a total of ~$130m USD worth of tokens from these markets, using this address: https://etherscan.io/... No other markets were impacted.
  • @frankresearcher Igor Igamberdiev on x
    Looks like @CreamdotFinance is dead boys https://twitter.com/...
  • @creamdotfinance @creamdotfinance on x
    With the help of friends from @iearnfinance and others in the community, we were able to identify the vulnerabilities and patch them. In the meantime, we've paused our v1 lending markets on Ethereum and we're in the process of putting together a post-mortem review.
  • @thijsniks Thijs Niks on x
    Gotta love that crypto comes with a built-in bug bounty system https://www.bloomberg.com/...
  • @azflin @azflin on x
    Cream finance hacker was a true programmer. He even appropriately named his contract. https://twitter.com/...
  • @carnage4life Dare Obasanjo on x
    Another day, another ethereum based DeFi platform tricked into giving $130M to hackers. Once I realized smart contracts are just code similar to stored procedures running on the blockchain, it became obvious that these sorts of attacks will be commonplace. https://www.bloomberg.c…