SlowMist: An Analysis of the Attack on Alpha Finance & Cream Exploit (Released in 2021)
According to SlowMist Zone, on February 13, 2021, Ethereum DeFi Alpha Finance was attacked. The SlowMist Security Team followed up and analyzed the incident in real-time, sharing it in a brief format for everyone to study.
1. The attacker added liquidity to the Uniswap WETH-UNI pool with a portion of WETH, exchanged some WETH for sUSD, and added liquidity to Cream to obtain cySUSD credentials.
2. The attacker borrowed sUSD from IronBank through Alpha Homora V2 and deposited LP into WERC20 as collateral for subsequent leverage.
3. The attacker returned the borrowed sUSD to IronBank through Alpha Homora V2.
4. The above steps seem to be probing.
5. The attacker then began to use Alpha Homora V2’s leveraged lending to cyclically borrow sUSD from IronBank, doubling the amount borrowed each time. The borrowed sUSD was then added to Cream for liquidity to obtain cySUSD credentials.
6. The attacker was not satisfied with this inefficient leveraged lending cycle and started using flash loans to speed up the process.
7. The attacker borrowed 1.8 million USDC through a flash loan from AAVE and exchanged USDC for sUSD through Curve. At this point, the attacker obtained a large amount of sUSD.
8. The attacker first added liquidity to Cream with sUSD and obtained cySUSD vouchers. Then, they continued to use Alpha Homora V2’s leveraged lending to cyclically borrow sUSD from IronBank, eventually using the borrowed sUSD to repay the flash loan (including a portion of sUSD from previous steps as interest).
9. Repeating the previous step, the attacker borrowed 10 million USDC through a flash loan, exchanged it for sUSD, added liquidity to Cream, and obtained cySUSD. After continued leveraged borrowing, the attacker emptied the pool and repaid the flash loan.
10. The attacker borrowed another 10 million through a flash loan and repeated the process of adding liquidity, borrowing, obtaining cySUSD, and repaying the flash loan.
11. As the attacker had already obtained a large amount of cySUSD, they began directly borrowing WETH, USDC, USDT, DAI, and sUSD from Cream.
In conclusion, the attacker used flash loans to carry out leveraged lending on Alpha Finance and repaid the flash loans using Alpha Finance’s Cream IronBank credit. During the process, the attacker obtained a large amount of cySUSD by adding liquidity to Cream, allowing them to carry out further borrowing in Cream Finance. Due to the issues in Alpha Finance, both protocols suffered losses simultaneously.
About SlowMist
SlowMist is a blockchain security firm established in January 2018. The firm was started by a team with over ten years of network security experience to become a global force. Our goal is to make the blockchain ecosystem as secure as possible for everyone. We are now a renowned international blockchain security firm that has worked on various well-known projects such as Huobi, OKX, Binance, imToken, Crypto.com, Amber Group, Klaytn, EOS, 1inch, PancakeSwap, TUSD, Alpaca Finance, MultiChain, O3Swap, etc.
Website:
https://www.slowmist.com
Twitter:
https://twitter.com/SlowMist_Team
Github:
https://github.com/slowmist/
