DeFi Platform Cream Finance Hacked, Millions in Crypto Tokens Stolen

Decentralized finance platform Cream Finance became the target of a successful hack. The attack resulted in a total of over $30 million in stolen AMP and ETH tokens.

Cream Finance has already stated that any losses that affected the platform's users will be reimbursed by the platform.

The hack abused the way Cream Finance had implemented AMP in its platform. Cream made it very clear in an official statement that the issue was not caused by a vulnerability or bug with AMP's code but was due to a poor implementation on Cream's part, essentially owning the issue, along with the promise to compensate customers affected by the hack.

A detailed news release and post concerning the incident is available on Cream Finance's website. The post details that the threat actors behind the attack abused a vulnerability in the way the ERC777 token standard was implemented on Cream's platform, along with some functions belonging to it.

This led to a vulnerability allowing the hackers to send multiple borrow() functions before the first one was updated, leading to the theft of the tokens.

Cream Finance is taking a two-way approach towards recovering the stolen funds and tracking down the hacker who was behind the attack. The platform is offering a very tasty 50% of the stolen money to any party who secures information concerning the real identity of the hackers, which leads to legal prosecution.

Additionally, Cream is also offering a 10% cut of the stolen tokens as a sort of a bug-hunter reward to the hackers, if they choose to cooperate and return the other 90% of the stolen crypto.

Cream have put a temporary halt on AMP transactions until the bug used by the hackers is patched out.

A similar but much bigger incident that took place about a month earlier led to the theft of over $500 million worth of crypto tokens from Chinese-based DeFi platform Poly Network. In that attack, a lone hacker abused a vulnerability in the way one of the functions worked.

September 1, 2021
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.