defi lending · Global

C.R.E.A.M. Finance

Permissionless non-custodial DeFi lending protocol. Its Ethereum V1 markets suffered a major exploit on 2021-10-27, while other markets were reported unaffected and C.R.E.A.M. later continued operating lending interfaces and documentation across multiple networks.

Also known as: CREAM Finance, C.R.E.A.M.

Status
Active
Outcome
Unknown
Confidence
High
Last verified
2026-09-01
Launch
End
Failure reasonUnknown
Events1
Evidence4
Products1

Case summary

What happened

On 2021-10-27, an attacker exploited C.R.E.A.M. Finance's Ethereum V1 markets and removed approximately USD 130 million of assets. C.R.E.A.M. suspended interactions with the affected Ethereum V1 markets, locked their crTokens, patched the identified vulnerability and later announced a compensation mechanism allocating 1,453,415 CREAM tokens to impacted users. The incident is recorded as a severe historical impairment of the affected V1 deployment rather than as permanent termination of the entire protocol.

Customer result

Customer outcome

Unknown

The compensation mechanism and one-year claim window are documented, but CYA does not have sufficient evidence to assign a universal realized recovery percentage or to conclude that every affected user was made whole. Token allocation value also should not be equated mechanically with the USD value removed during the exploit.

Estimated recovery
Unknown
Repayment started
Repayment completed
Confidence
High

Claim or case process →

Asset treatment

Terms risk

Customer-owned

The non-custodial protocol model does not eliminate loss risk. The October 2021 exploit demonstrated that smart-contract and market-design failures can still impair user positions materially.

Affected product
C.R.E.A.M. Finance lending markets
Confidence
High

C.R.E.A.M. Finance describes its lending protocol as non-custodial. User positions are represented through smart-contract lending markets rather than a centralized custodial yield account, although users remain exposed to protocol, collateral, oracle and smart-contract risk.

Source: C.R.E.A.M. Finance documentation overview

Known unknowns

Uncertainty

CYA has first-party evidence for the exploit, affected-market suspension and announced CREAM-token compensation process, but not for a universal realized recovery percentage across all affected positions. Current official surfaces remain live, so the historical Ethereum V1 exploit is not treated as proof of protocol-wide shutdown.

Chronology

Historical record

exploitCritical impact3 sources

C.R.E.A.M. Finance Ethereum V1 exploit removes approximately USD 130 million

C.R.E.A.M. Finance reported that its Ethereum V1 markets were exploited on 2021-10-27, allowing an attacker to remove approximately USD 130 million of assets. The protocol suspended interactions with the affected Ethereum V1 markets and locked their crTokens. C.R.E.A.M. stated that other V1 markets and Iron Bank were not affected by this specific exploit and later announced a CREAM-token compensation mechanism for impacted users.

The USD 130 million figure is the reported value removed from the affected Ethereum V1 markets, not a universal final customer-loss or recovery figure. The event is bounded to the affected deployment.

Source record

Evidence dossier

Filter by claim, reliability, source type, and whether evidence is linked to a specific event.

Showing 4 of 4 evidence records

customer outcome

1 sources
Official statementHighEvent linked

Moving Forward: Post Exploit Next Steps for C.R.E.A.M. Finance

C.R.E.A.M. Finance · 2021-11-13

First-party follow-up announces allocation of 1,453,415 CREAM tokens to impacted users and a one-year claim process. It does not establish a universal realized recovery percentage.

Entity

1 sources
Official statementHigh

C.R.E.A.M. Finance documentation overview

C.R.E.A.M. Finance

Current first-party documentation describes C.R.E.A.M. Finance as a permissionless, transparent and non-custodial lending protocol and documents live protocol markets.

Event

2 sources
Official statementHighEvent linked

C.R.E.A.M. Finance Post Mortem: Flash Loan Exploit Oct 27

C.R.E.A.M. Finance · 2021-10-31

First-party post-mortem states that approximately USD 130 million was removed from Ethereum V1 markets, that interactions with those markets were suspended, and that other C.R.E.A.M. V1 markets and Iron Bank were not impacted by this specific exploit.

News articleMediumEvent linked

CREAM V1 Exploit: Loss Event Details & Claims Filing

Nexus Mutual · 2021-10-30

Independent ecosystem reporting contemporaneously corroborating the October 27 CREAM V1 loss event and approximately USD 130 million removed from the lending market.

Comparative records

Independent archive

Help maintain customer-outcome records

Support court-document review, source preservation, corrections, broken-link replacement, and long-term archive maintenance. Support does not influence classifications or evidence standards.

Support CYA

Record maintenance

Report this record

Report incorrect dates, status, customer outcome, terms-risk interpretation, URL history, or missing evidence.

Submit correction →