Case summary
What happened
On 2021-10-27, an attacker exploited C.R.E.A.M. Finance's Ethereum V1 markets and removed approximately USD 130 million of assets. C.R.E.A.M. suspended interactions with the affected Ethereum V1 markets, locked their crTokens, patched the identified vulnerability and later announced a compensation mechanism allocating 1,453,415 CREAM tokens to impacted users. The incident is recorded as a severe historical impairment of the affected V1 deployment rather than as permanent termination of the entire protocol.
Customer result
Customer outcome
Unknown
The compensation mechanism and one-year claim window are documented, but CYA does not have sufficient evidence to assign a universal realized recovery percentage or to conclude that every affected user was made whole. Token allocation value also should not be equated mechanically with the USD value removed during the exploit.
- Estimated recovery
- Unknown
- Repayment started
- —
- Repayment completed
- —
- Confidence
- High
Asset treatment
Terms risk
Customer-owned
The non-custodial protocol model does not eliminate loss risk. The October 2021 exploit demonstrated that smart-contract and market-design failures can still impair user positions materially.
- Affected product
- C.R.E.A.M. Finance lending markets
- Confidence
- High
C.R.E.A.M. Finance describes its lending protocol as non-custodial. User positions are represented through smart-contract lending markets rather than a centralized custodial yield account, although users remain exposed to protocol, collateral, oracle and smart-contract risk.
Known unknowns
Uncertainty
CYA has first-party evidence for the exploit, affected-market suspension and announced CREAM-token compensation process, but not for a universal realized recovery percentage across all affected positions. Current official surfaces remain live, so the historical Ethereum V1 exploit is not treated as proof of protocol-wide shutdown.
Chronology
Historical record
C.R.E.A.M. Finance Ethereum V1 exploit removes approximately USD 130 million
C.R.E.A.M. Finance reported that its Ethereum V1 markets were exploited on 2021-10-27, allowing an attacker to remove approximately USD 130 million of assets. The protocol suspended interactions with the affected Ethereum V1 markets and locked their crTokens. C.R.E.A.M. stated that other V1 markets and Iron Bank were not affected by this specific exploit and later announced a CREAM-token compensation mechanism for impacted users.
The USD 130 million figure is the reported value removed from the affected Ethereum V1 markets, not a universal final customer-loss or recovery figure. The event is bounded to the affected deployment.
Source record
Evidence dossier
Filter by claim, reliability, source type, and whether evidence is linked to a specific event.
customer outcome
1 sourcesMoving Forward: Post Exploit Next Steps for C.R.E.A.M. Finance
C.R.E.A.M. Finance · 2021-11-13
First-party follow-up announces allocation of 1,453,415 CREAM tokens to impacted users and a one-year claim process. It does not establish a universal realized recovery percentage.
Entity
1 sourcesC.R.E.A.M. Finance documentation overview
C.R.E.A.M. Finance
Current first-party documentation describes C.R.E.A.M. Finance as a permissionless, transparent and non-custodial lending protocol and documents live protocol markets.
Event
2 sourcesC.R.E.A.M. Finance Post Mortem: Flash Loan Exploit Oct 27
C.R.E.A.M. Finance · 2021-10-31
First-party post-mortem states that approximately USD 130 million was removed from Ethereum V1 markets, that interactions with those markets were suspended, and that other C.R.E.A.M. V1 markets and Iron Bank were not impacted by this specific exploit.
CREAM V1 Exploit: Loss Event Details & Claims Filing
Nexus Mutual · 2021-10-30
Independent ecosystem reporting contemporaneously corroborating the October 27 CREAM V1 loss event and approximately USD 130 million removed from the lending market.
No evidence records match the current filters.
Comparative records