C.R.E.A.M. Finance hack — October 2021
Incident facts
| Date of incident | |
|---|---|
| Target type | Lending protocol |
| Loss | $130,000,000Published estimates range $130,000,000 to $136,000,000Price at time of incident |
| Method | Oracle or price manipulationFlash-loaned capital used to inflate yUSD price-per-share in Cream's hybrid oracle |
| Chains | Ethereum |
| Outcome | Unresolved |
What happened
C.R.E.A.M. Finance's Ethereum v1 lending markets were drained on 27 October 2021. Cream's own post-mortem said the attacker removed about $130 million of tokens, and that only the Ethereum v1 markets were affected; other v1 deployments and the Iron Bank were untouched.
The attack turned on how Cream priced yUSD, a Yearn vault token, using a hybrid oracle that read the vault's price-per-share. Working from flash-borrowed capital — Cream's account cites roughly $500 million of DAI flash-minted from MakerDAO and about $2 billion of ETH, which Immunefi identifies as borrowed from Aave v2 — the attacker deposited into Curve's yPool and the Yearn vault to obtain yUSD, supplied it as collateral, then transferred Yearn LP tokens directly into the vault. Cream put that donation at about $8 million of yCrv, Immunefi at about $10 million; either way it roughly doubled the reported price-per-share, so the same collateral was valued at about twice its worth and could be recycled across two attacker-deployed contracts to borrow far more than it backed. The whole sequence ran inside a single transaction touching dozens of assets.
Published figures differ, and partly on valuation basis rather than on measurement. Cream itself said about $130 million. CoinDesk reported the same figure — roughly $130 million netted by the attacker out of more than $260 million moved in total — under a headline of 'over $100 million'. Crypto Briefing, citing Zerion, reported $136 million at peak prices, a mark on the attacker's holdings rather than a value at the time of the theft. Cream paused the affected markets and offered a 10% bounty for the return of the funds; it said it was working to repay lost funds starting with a partial payment. The attacker was never identified and the funds were not returned.
On-chain references
Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.
Transactions
- 0x0fe2542079644e107cbf13690eb9c2c65963ccb79089ff96bfaf8dced2331c92
Sources
- C.R.E.A.M. FinancePrimary · retrieved 2026-08-01
- ImmunefiSecondary · retrieved 2026-08-01
- Crypto BriefingSecondary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
Official post-mortem: https://medium.com/cream-finance/post-mortem-exploit-oct-27-507b12bb6f8e
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "C.R.E.A.M. Finance hack — October 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/cream-financehttps://itokenly.com/hacks/cream-financePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.