Cream Finance: A Review of Flash Loan Attacks and Responses in 2021

Cream Finance, a decentralized lending protocol based on Ethereum, was one of the most prominent projects in the DeFi space in 2021. However, the protocol suffered multiple major security attacks that year, leveraging the flash loan mechanism, which significantly impacted its users and the entire DeFi ecosystem.

Cream Finance:2021年闪电贷攻击后曾向攻击者提供漏洞赏金

Details of Multiple Flash Loan Attacks in 2021

Cream Finance experienced three major flash loan attacks in 2021:

  • February 2021: The first attack occurred in February, exploiting Cream Finance's Iron Bank service through the Alpha Homora protocol, resulting in the theft of approximately $37.5 million in assets.
  • August 30, 2021: The second attack stemmed from a reentrancy vulnerability in the AMP token contract. This attack caused losses of approximately $18.8 million (estimated losses were reported to be between $25 million and $35 million at different times), primarily involving AMP tokens and Ethereum (ETH).
  • October 27, 2021: This was the largest attack in Cream Finance's history, with losses amounting to approximately $130 million. The attacker exploited a price oracle vulnerability in yUSDVault, stealing Cream LP tokens and various other ERC-20 tokens through multiple complex on-chain operations.

Cream Finance:2021年闪电贷攻击后曾向攻击者提供漏洞赏金

Cream Finance's Bug Bounty and Fund Recovery Strategy

In response to these attacks, the Cream Finance team took proactive measures, with a core strategy being to offer bug bounties to attackers in an attempt to recover stolen funds:

Cream Finance:2021年闪电贷攻击后曾向攻击者提供漏洞赏金

  • Bounty for Attackers: After the attacks in August and October 2021, Cream Finance publicly appealed to the attackers, promising a 10% bug bounty as a reward if they returned most of the stolen funds. For the August attack, an additional 10% bonus was even offered.
  • Rewards for Assistants: For the August 2021 attack, Cream Finance also pledged to share 50% of the recovered funds with third parties who could assist in identifying and prosecuting the attackers.
  • Fund Recovery Progress: After the October 2021 attack, the Yearn Finance team, associated with Cream Finance, successfully salvaged $9.42 million that the attacker had "donated" to the yUSD vault, demonstrating the role of community collaboration in crisis management.

Post-Incident Security Measures and Industry Reflection

To address the attacks and enhance security, Cream Finance implemented a series of measures, including pausing its v1 Ethereum lending market and collaborating with Yearn Finance, as well as blockchain security companies like PeckShield and SlowMist, to fix vulnerabilities. Additionally, Cream Finance partnered with the Immunefi platform to establish an ongoing bug bounty program, encouraging global security researchers to report potential vulnerabilities.

Cream Finance:2021年闪电贷攻击后曾向攻击者提供漏洞赏金

These attack incidents also prompted the entire DeFi industry to reflect more deeply on smart contract audits, price oracle design, and flash loan risk management. The industry generally believes that flash loans themselves are an innovative financial tool, but their exploitation often exposes deep-seated vulnerabilities in the design or implementation of DeFi protocols, rather than flash loans themselves being the problem.