Share this article

Crema Finance Attacker Returns Almost $8M, Keeps $1.7M Bounty

The protocol had more than $9 million worth of cryptocurrencies stolen from its platform over the weekend in a flash loan attack.

(Boonchai Wedmakawand/Getty Images)
(Boonchai Wedmakawand/Getty Images)

The attacker behind the exploit of Solana-based liquidity protocol Crema Finance returned more than $8 million worth of tokens, keeping roughly $1.68 million as a "white hat" bounty, Crema developers said Thursday.

The protocol had more than $9 million worth of cryptocurrencies stolen from its platform over the weekend in a flash loan attack. Flash loans allow traders to borrow unsecured loans from lenders by relying on smart contracts instead of third parties.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters

“The hacker agreed to take 45455 SOL as the white hat bounty,” the developers said in a tweet. “Now we have confirmed the receipt of 6064 ETH + 23967.9 SOL in the four transactions.”

The developers said a compensation plan will be released in 48 hours for users affected by the attacker.

The protocol allows liquidity providers to set specific price ranges, add single-sided liquidity and conduct range order trading. This makes for a sophisticated and decentralized trading platform.

The exploit involved the attacker creating a fake tick account on Crema. A tick account is "a dedicated account that stores price tick data in CLMM,” the developers said, referring to Crema's market-making protocol. After that, the attacker exploited a command by writing the data on the fake account and circumventing security measures.

A flash loan was then used to manipulate the prices of assets on liquidity pools. This, along with the false data entries, allowed the attacker to claim “a huge fee amount out from the pool,” as previously reported.

Shaurya Malwa

Shaurya is the Co-Leader of the CoinDesk tokens and data team in Asia with a focus on crypto derivatives, DeFi, market microstructure, and protocol analysis.

Shaurya holds over $1,000 in BTC, ETH, SOL, AVAX, SUSHI, CRV, NEAR, YFI, YFII, SHIB, DOGE, USDT, USDC, BNB, MANA, MLN, LINK, XMR, ALGO, VET, CAKE, AAVE, COMP, ROOK, TRX, SNX, RUNE, FTM, ZIL, KSM, ENJ, CKB, JOE, GHST, PERP, BTRFLY, OHM, BANANA, ROME, BURGER, SPIRIT, and ORCA.

He provides over $1,000 to liquidity pools on Compound, Curve, SushiSwap, PancakeSwap, BurgerSwap, Orca, AnySwap, SpiritSwap, Rook Protocol, Yearn Finance, Synthetix, Harvest, Redacted Cartel, OlympusDAO, Rome, Trader Joe, and SUN.

Shaurya Malwa