Alpha Finance is the latest DeFi protocol to fall to a flash loan attack, costing it the loss of $37 million of its Alpha Homora V2 contract. 

According to a report issued by the protocol developers, Alpha Finance It is the latest protocol for decentralized finance (DeFi) to be affected by a flash loan exploit, one that analysts believe bears strong similarity to the Pickle Finance protocol hack that occurred in November of last year. 

Immediately upon discovering the attack, the protocol developers suspended activities on the Alpha Homora V2 contract system, and patched the bug. In addition, the developers began corresponding investigations to discover the modus operandi under which the attackers acted.

Alpha Finance developers are working together with Andrew Cronje, creator of the protocol Year Finance, which was also the victim of a recent flash loan attack, causing $11 million in losses to its yDAI v1 vault, and with the developers of cream finance, a decentralized protocol that merged with Yearn Finance late last year to boost its growth and development. 

It may interest you: Yearn Finance is the victim of a million-dollar flash loan attack, but all is not lost

A suspect in the crosshairs

In the tweet published by Alpha Finance, the developers report that they are also collaborating with different authorities to track down the person behind the attack, and they assure that they already have a suspect in their sights. However, at the time of this publication, the developers have not reported who is suspected of attacking the protocol, although the crypto community is beginning to speculate that it is an “inside job.” 

On the other hand, the developers published a report complete post mortem to detail the situation that occurred with Alpha Homora V2, and pointed out that the affected funds do not affect users, but rather it is between Alpha Homora V2 and Cream V2, so they are working with Cronje and Cream to find actions corrective measures and resolve the debt.

How did the attack occur?

First, it is estimated that the attack involved around 9 transactions, or more, that used flash loans. As the team reports, the attacked contract was neither available on the UI nor publicly announced, so there was no liquidity in it. This allowed the attacker to completely manipulate and inflate the total amount of the debt and the total share of the debt, which as already mentioned, amounted to $37 million. 

The attacker used Homora's sUSD pool's Iron Bank feature, which allows for leveraged lending, and introduced a spoofed custom contract, which the protocol thought was “theirs,” to execute the attack. The report explains that HomoraBankv2 accepts any custom “spell,” as long as the invariant checks that collateral > borrow. The “spell” in Alpha Finance is the term the protocol uses to define smart contracts (smart contracts). 

Alpha Finance Actions to Take

The protocol development team assures that they will continue auditing the protocol to discover possible vulnerabilities and exploits, and guarantee maximum security for protocol users. Alpha Finance has two audits by the firms Quantstamp y peckshield, and will continue to work with more auditing firms and developers to make the DeFi space safer and more reliable for users and investors. 

Users of the protocol are wondering if Alpha Finance will use minting to resolve debt to Cream, similar to how Yearn Finance did to replenish funds lost in the exploit it suffered a few days ago. At the moment, the Alpha developers have not made any statement in this regard. 

Continue reading: DeFi hacks continue to increase, risking investor and user funds