CryptoReal
CASE FILE — Oct 28, 2021

Cream's Second Nine-Figure Bleed Exposes Yearn's Cracks

On Thursday, October 28, 2021, Cream Finance was exploited for a second time, this time for approximately $130 million. The incident put Cream in third place on the overall loss leaderboard, marked the protocol's second appearance on that list, and became the tenth loss recorded across projects connected to the wider Yearn Finance ecosystem — a tally visible in the price impact tracked on CoinGecko's Yearn ecosystem page.

The repeat loss renewed scrutiny of Yearn's aggressive 2020-era acquisition spree, which many had expected would bring tighter security across the platforms it absorbed. Critics pointed out that Yearn's developers kept shipping rapid forks of rival products and steering users toward chains favorable to the ecosystem, while allegedly sidelining the original developers behind code that other users' funds now depended on. That is not to suggest deliberate deception of end users — DeFi participants broadly understand the risks — but the pattern of losses across so many linked protocols raised uncomfortable questions about who benefited when Yearn's competitors stumbled.

Mechanism of the exploit

Two attacker-controlled addresses were used in tandem to manipulate a price oracle: Address A and Address B. The attacker repeatedly lent and borrowed flash-loaned capital across the pair, then used inflated yUSDVault-backed collateral to drain Cream's lending vaults.

The sequence played out as follows. Using Address A, the attacker flash-borrowed 500 million DAI from MakerDAO and deposited it into Curve's yPool for yDAI, minting yUSD that was then placed into Yearn's yUSD strategy. The resulting yUSDVault tokens were posted as collateral on Cream, letting the attacker mint roughly $500 million worth of crYUSD.

Address B then took out a $2 billion ETH flash loan from Aave and posted it as Cream collateral, borrowing an additional ~$500 million in yUSD, which was likewise deposited to mint more crYUSD. The two addresses cycled this deposit-and-borrow pattern repeatedly, with B shuttling roughly $500 million in yUSDVault tokens to A each round, until Address A held about $1.5 billion in crYUSD and roughly $500 million in yUSDVault tokens.

With that position built, the attacker turned to Cream's internal PriceOracleProxy, which values yUSDVault based on its pricePerShare — calculated as the vault's yUSD balance divided by yUSDVault's total supply. By redeeming roughly $500 million in yUSDVault for the underlying yUSD, the attacker shrank the vault's total supply to just $8 million; combined with an $8 million yUSD deposit back into the vault, this pushed the value of each yUSDVault share up by roughly a factor of two.

Sums referenced in this case file

That manipulation left Cream's contracts believing Address A held $3 billion in crYUSD collateral. Of that phantom sum, $2 billion was withdrawn as ETH to settle Address B's flash loan, and about $500 million in redeemed yUSD covered Address A's original DAI loan — leaving roughly $1 billion in excess borrowing power, more than enough to borrow out (and default on) the full $130 million Cream actually had available to lend.

A breakdown of the stolen assets — more than 2,760 ETH, a combined 76 BTC across renBTC, WBTC and HBTC, plus tens of millions in stablecoins and other tokens — was compiled by SlowMist.

Movement of funds afterward

Once the exploit concluded, funds were moved from the exploit contract back to the second wallet, which had itself received Tornado Cash funding roughly 30 minutes before the attack, across two transactions. Since then, the attacker has routed funds through renBridge toward BTC and added over $40 million of CRETH2 as single-sided liquidity to Uniswap's ETH-CRETH2 pool — likely an attempt to offload the token before any potential remediation, since CRETH2 was flagged as possibly salvageable.

Attempted negotiation and unresolved questions

Cream Finance's deployer address was one of several accounts that tried reaching the attacker on-chain, sending a message reading: "you win. we're rekt. please return funds and we will honor a 10% bounty."

Separately, cryptic text embedded in the main exploit transaction's input data name-checked other protocols: "gÃTµ Baave lucky, iron bank lucky, cream not. ydev : incest bad, dont do."

Security researcher Mudit Gupta published an analysis arguing the attacker's methodology pointed to an experienced DeFi developer rather than a typical opportunistic exploiter. Taken together, the message and the technical sophistication suggested the incident may have reflected rivalries within the DeFi development community rather than a straightforward smash-and-grab — leaving open who, if anyone, ultimately gained from a $130 million loss that neither side of any such dispute could claim as a win.

(Original credit for early analysis: @Mudit__Gupta and @cryptofishx.)

CreamYearn
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.