ChainBleedv0.1 · open intel
← back to feed·ETHFLASHLOAN2021-02-13 · 5y ago
Incident · DEFILLAMA

Alpha Finance

Flashloan Pool Shares Exploit
Estimated loss
$37.50M
VERDICT —AUDIT-CATCHABLE
Share-vs-asset rounding direction in lending integration is a canonical invariant target. An invariant-extractor or attacker persona running `forge invariant` against `totalShares` vs `totalDebt` finds it; the inflation pattern is post-Compound-fork well known by 2021.
▰ METHOD
Flashloan Pool Shares Exploit
FLASHLOANBYTECODE CATCHABLEAI SCANNABLE
Root cause

Alpha Homora V2's `HomoraBank.sol` integrated with Iron Bank's `cyToken` for leveraged borrowing. The bug lived in two surfaces: (1) the `WERC20` wrapper allowed depositing borrowed sUSD to mint `cySUSD` shares whose accounting was rounded in a way that allowed a sub-1-wei deposit to mint a non-zero share, inflating `totalShare` cheaply; and (2) the `HomoraBank.execute()` flow allowed the attacker to repeatedly borrow tiny amounts of sUSD through `cySUSD`, exploiting an integer-rounding asymmetry so that each loop increased `cySUSD.totalSupply` while their own debt rounded down to zero. After many loops the attacker held nearly the entire `cySUSD` supply with negligible debt, then drew the full Iron Bank sUSD line of credit (~$37.5M across sUSD/USDC/USDT/DAI/WETH via similar paths). Root cause is a rounding-direction error in share-vs-debt accounting compounded across an unbounded loop the protocol allowed in a single transaction.

Forensic narrative

Classification: Ecosystem. Technique: Flashloan Pool Shares Exploit. Target type: DeFi Protocol. Affected chains: Ethereum. Implementation language: Solidity.

Primary source
https://blog.alphaventuredao.io/alpha-homora-v2-post-mortem/
Sourced from
DefiLlama Hacks dataset · api.llama.fi/hacks
Technical record
chain
ethereum
protocol
Alpha Finance
bug_class
flashloan
date_occurred
2021-02-13
loss_usd
$37,500,000
classification
Ecosystem
technique
Flashloan Pool Shares Exploit
target_type
DeFi Protocol
language
Solidity
source_id
dl:adhoc:alpha-finance:1613174400
Related — same bug class· flashloan
2026-05-11
1mo ago
POLY
Ink Finance
Contract Vulnerability
flashloan
$140.0K
UNRATED
2026-05-04
1mo ago
ETH
SmartCredit
Flashloan Exploit
flashloan
$72.0K
UNRATED
2026-05-04
1mo ago
SmartCredit
Flash Loan Exploit
flashloan
$72.0K
UNRATED
2026-04-28
1mo ago
BSC
JUDAO
Flashloan Exploit
flashloan
$228.0K
UNRATED
2026-04-28
1mo ago
JUDAO
Exploit
flashloan
$228.0K
UNRATED
2026-04-15
1mo ago
LootBot AI
Contract Vulnerability
flashloan
$9.6K
UNRATED
ChainBleed — live web3 threat intelligence