CryptoReal
CASE FILE — Nov 17, 2020

Cheese Bank and Origin Protocol Losses Push November's DeFi Damage Past $45 Million

Two more DeFi protocols were exploited within roughly a day of each other in mid-November 2020, extending a month-long run of flash-loan-driven attacks.

Cheese Bank lost $3.3 million to a flash loan attack that manipulated an AMM price oracle. Origin Protocol lost $8 million through a combination of a flash loan and a fake-token re-entrancy exploit.

Counting these two incidents, DeFi users had lost more than $45 million over the preceding 30 days to protocols with inadequate security. Earlier losses in that same window included Harvest Finance ($25 million), Value DeFi ($7 million), and Akropolis (~$2 million).

A repeating pattern

Each new exploit tends to draw attention — and, uncomfortably, a degree of admiration for the technical skill involved — which in turn appears to inform the next attacker's approach. The visibility of one hack effectively functions as a blueprint for the next, and the frequency of these incidents has been climbing as a result.

Sums referenced in this case file

It's worth resisting any framing of these attackers as some kind of equalizing force; the funds being drained belong to protocol users, many of whom have far less to lose than the hackers stand to gain. At the same time, each incident does yield real information about where DeFi's defenses are thin, even if that isn't sufficient justification for the theft itself.

Where the responsibility lies

No single party in this cycle is blameless, even though the degree of culpability differs sharply between them:

  • Users who deposit into unaudited or newly launched protocols are betting on unproven code, drawn by the track record of early participants in past protocols being rewarded handsomely.
  • Development teams that rush code to market without a completed security audit are prioritizing speed and first-mover advantage over the safety of the funds they're custodying.
  • Attackers who identify and exploit these gaps are applying real technical expertise toward extracting value that isn't theirs, often keeping the entire haul rather than returning any portion of it.

If some hackers genuinely intend their exploits as a wake-up call for weak code, a full return of stolen funds — rather than an attacker's own judgment about who deserves reimbursement — would be a more convincing demonstration of that intent. Equally, teams that skip pre-launch audits to move faster are taking a comparable gamble, just with other people's money.

The case for prevention

Security audits remain far cheaper than the cost of a successful exploit, in dollars and in reputation. As losses accumulate heading into a broader market downturn, the pattern so far suggests more protocols will be caught out unless code review becomes a non-negotiable step before launch rather than an afterthought.

cheese bankflash loanhackorigin
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.