Cream priced Yearn vault shares as totalAssets / totalSupply, read live from the vault. A vault's asset balance counts tokens that were simply sent to it — no mint required. So the attacker used flash loans to shrink the vault's supply to about $8M, then donated ~$8M of yUSD straight into the vault, instantly doubling the price per share without a single trade. His $1.5B of crYUSD collateral was revalued at $3B, and he borrowed out everything Cream had on the shelf.
// Cream's price for a vault-share collateral token: function getUnderlyingPrice(CToken cToken) returns (uint) { ... return vault.getPricePerFullShare() * underlyingPrice / 1e18; } // yVault: function getPricePerFullShare() public view returns (uint) { return balance() * 1e18 / totalSupply; // ❌ balance() includes tokens TRANSFERRED in. // A plain ERC-20 transfer moves the price. No mint. No swap. No fee. } // The attack, in one transaction: flash-loan → burn shares until totalSupply ≈ $8M transfer $8M of yUSD directly to the vault → price per share ×2 collateral repriced $1.5B → $3B → borrow everything
balanceOf(address(this)).Entries in the SAFE database that describe this failure. These share its failure class.
Every figure on this page comes from the post-mortems above, not from us. Losses are US dollars at the time of the incident.
Oracle manipulation is one of the 203 classes the SaferICO scanner checks for. It will not review your signing process — but it will read your Solidity.