CryptoReal
CASE FILE — Jul 4, 2022

Fake Tick Account Lets Attacker Siphon $8.8M From Crema Finance on Solana

Crema Finance, a concentrated-liquidity automated market maker built on Solana, was manipulated into generating and paying out millions of dollars in fabricated liquidity-provider fees.

The team disclosed the breach on Sunday at 04:07 UTC, though the actual attack had taken place a day earlier. Adding insult to injury, a prior audit had already flagged a closely related flaw elsewhere in the code — a detail that makes the incident sting even more for the Crema team.

According to the project's own account of events (corroborated by researcher PierreArowana), the root cause was inadequate owner-verification checks on one of Crema's on-chain accounts — specifically the one holding price-tick data that the protocol relies on to calculate LP fees.

The attacker took advantage of this gap by creating a counterfeit tick account populated with falsified data. Using flash-loaned capital, they supplied liquidity to the protocol, then withdrew that liquidity while simultaneously collecting the fees their doctored account made appear legitimately owed to them.

The stolen assets were converted into 69,422.9 SOL and 6,497,738 USDCet. The USDCet portion was later bridged over to Ethereum and swapped into ETH. Both totals are reported to remain sitting in the attacker's wallets:

Attacker's Solana address: Esmx2QjmDZMjJ15yBJ2nhqisjEt7Gqro4jSkofdoVsvY

Sums referenced in this case file

Attacker's Ethereum address: 0x8021b2962dB803b73Aa874030B0B42c202E8458F

Crema's team tried to open a dialogue with the attacker by embedding a message directly in Solana and Ethereum transaction data, offering a white-hat arrangement: the attacker could keep $800,000 as a bounty, provided the rest of the funds were returned within 72 hours.

The on-chain message read:

”To the Crema hacker: Your addresses on both Solana and Ethereum have been blacklisted and all eyes are on you right now. You have 72h from now to consider becoming a white hat and keeping 800k USD as the bounty. And transfer remaining funds back to our contract-update-authority address (DR1tLcKEmiNFxF5dxgdWCANdeBMNu9FjuHur2i4vAPHV) . Otherwise the police and legal force will officially get involved and there will be endless tracing waiting for you”

An earlier audit performed by Bramah Systems had already caught this exact type of vulnerability in Crema's swap method (see page 7), and that instance was patched. However, an identical weakness had gone unnoticed in a separate part of the codebase: the claim method.

This kind of insufficient validation has been a recurring culprit in several major Solana exploits this year. Wormhole lost $326 million because of broken signature verification on its bridge, while Cashio was drained of roughly $48 million after failing to properly validate the LP tokens accepted as collateral.

With the market's exuberance long gone, whether Crema Finance can weather this blow remains an open question.

Crema Finance
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.