A series of malicious transactions began draining Crema Finance, a concentrated-liquidity protocol on Solana, at approximately 20:08 UTC on July 2, 2022. Security firm CertiK later estimated the assets removed at approximately $8.78 million.
The incident was not publicly confirmed by Crema until July 3, when the project said it had suspended its program and was investigating an apparent hack. The transactions themselves nevertheless place the beginning of the exploit on July 2, making that the appropriate event date while preserving the distinction between occurrence and disclosure.
Crema allowed liquidity providers to deposit assets within selected price ranges. Its contracts relied on specialized “tick” accounts to record information used when calculating trading fees. Preliminary analysis indicated that the attacker supplied falsified tick-account data, making the protocol calculate fees that had not actually been earned.
How the transactions worked
CertiK’s July 3 incident analysis described multiple attacks using flash loans obtained through Solend. A flash loan makes assets available within one blockchain transaction and requires repayment before that transaction finishes. The mechanism is not inherently malicious, but it can give an attacker enough temporary capital to amplify a vulnerable calculation.
According to that analysis, the attacker created or supplied a false tick account, borrowed the required assets, deposited liquidity into Crema and invoked the protocol’s fee-claiming function. The falsified account caused the claim calculation to return more assets than the position had earned. The attacker then withdrew the deposited assets and repaid the flash loan, retaining the improperly claimed funds.
CertiK characterized this as the apparent attack flow, not a completed audit. The firm said Crema’s source code was private and therefore declined to state conclusively whether the defect sat in the claim function, the withdrawal function or their interaction. Crema later attributed the theft to authentic transaction-fee data being replaced by false tick-account data.
That limitation matters. The surviving evidence supports the conclusion that account validation and fee accounting were exploited, but it does not support treating every preliminary technical explanation as a final root-cause determination available on July 2.
Measuring the loss
CertiK’s approximately $8.78 million figure was a rough valuation assembled on July 3 from traced assets. Its analysis identified approximately 6.50 million USDC transferred through the Wormhole bridge and substantial holdings of SOL and ether associated with the attacker. Because token prices move continuously, the dollar total depends on the assets counted, their valuation timestamps and the price sources used.
The estimate was therefore not an audited July 2 closing balance. No exact end time for the complete transaction sequence, unified valuation timestamp or contemporaneous protocol accounting statement was preserved in the reviewed sources. Coinburn consequently treats $8.78 million as an attributed estimate rather than a precisely verified loss.
Crema’s subsequent compensation notice identified five affected pools: USDT-USDC, mSOL-SOL, stSOL-SOL, PAI-USDC and USDH-USDC. That later first-party record confirms that the incident reached several pools and affected liquidity providers, although it does not establish what users knew before Crema’s July 3 warning.
Why the exploit mattered
The incident demonstrated that settlement on a public blockchain does not make an application’s internal accounting correct. Solana processed the submitted instructions as programmed; the failure described by investigators concerned which account data Crema accepted when computing fee entitlements.
It also illustrated composability’s double edge. Solend’s flash-loan facility and Crema’s liquidity contracts could interact within a single transaction, increasing capital efficiency for ordinary activity while allowing a validation error to be exercised at much greater scale.
As July 2 ended, the defensible record was limited: malicious transactions had removed assets from Crema, but the protocol had not yet publicly announced the breach, published a loss estimate or explained the vulnerability.
Later context
Crema reported on July 8 that it had recovered most of the stolen assets and published a compensation plan. Those developments clarify the incident’s consequences but were not knowable on July 2 and do not alter this event-day framing.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

