Alpha Finance hack — February 2021
Incident facts
| Date of incident | |
|---|---|
| Target type | Lending protocol |
| Loss | $38,175,296Published estimates range $37,500,000 to $38,175,296Price at time of incident |
| Method | Contract logic errorDebt-share rounding bug in an unfunded sUSD pool, amplified by Aave flash loans and unrestricted custom spells |
| Chains | Ethereum |
| Outcome | Unresolved |
What happened
On 13 February 2021 at 05:37 UTC an attacker drained Alpha Homora V2, the leveraged yield-farming product built by Alpha Finance Lab. Alpha Homora borrowed from Cream Finance's Iron Bank on an uncollateralised, protocol-to-protocol credit line, so the assets that left were supplied by Iron Bank lenders against Alpha's credit rather than deposited by Alpha Homora users.
The attacker used an sUSD lending pool that Alpha had deployed but never funded. Because he was the only borrower in it, a rounding miscalculation in the borrow function let him repeatedly increase the pool's recorded debt without minting the corresponding debt shares, and a reserve-resolution function that any address could call let him inflate the position further. Alpha Homora V2 also accepted arbitrary user-supplied "spells", so the attacker deployed his own contract to execute the sequence. Flash loans from Aave supplied the working capital, and the borrowed amount was roughly doubled across successive rounds.
Alpha's own post-mortem itemised the proceeds as 13,244.63 WETH plus about $14.3 million in DAI, USDC and USDT, and calculated the total at $38,175,296 using an ETH price of $1,800. Most contemporary reporting used a $37.5 million figure instead. The funds were moved through Tornado Cash and the Curve Aave pool. Cream stated the Iron Bank had incurred no bad debt and that the obligation sat with Alpha; Alpha said it would work with Cream on remedial action. Alpha patched the contracts, restricted borrowing to ETH, DAI, USDC and USDT, whitelisted spells and limited access to externally owned accounts. The stolen funds were not returned and no attacker has been publicly identified.
Sources
- Alpha Finance Lab / Alpha Venture DAOPrimary · retrieved 2026-08-01
- C.R.E.A.M. FinancePrimary · retrieved 2026-08-01
- Crypto BriefingSecondary · retrieved 2026-08-01
Official post-mortem: https://blog.alphaventuredao.io/alpha-homora-v2-post-mortem/
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Alpha Finance hack — February 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/alpha-financehttps://itokenly.com/hacks/alpha-financePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.