Understanding Cream: a beginner’s guide and review
How Cream Finance's no-audit stance and yield-on-yield design played out across three 2021 exploits.If you've watched a DeFi team ship new features every other week and wondered whether anything moving that fast can be safe, this rewrite of our 2020 Cream Finance review has the answer. You'll learn how a founder's public refusal to audit preceded three exploits worth over $185M in a single year, why stacking yield on yield-bearing collateral widens the attack surface, and how to spot a zombie protocol before you build on one.

This is a substantial revision of our September 2020 review of Cream Finance. The original described a fast-moving Compound fork whose founder publicly dismissed the need for audits. Within roughly a year, the protocol was exploited three times for a combined total above $185M, and it has seen no meaningful development since. Rather than erase the original, we have rewritten the piece to read its claims against what happened. Nothing here is a recommendation or investment advice.
The pitch we reviewed
Cream Finance (stylized C.R.E.A.M., for Crypto Rules Everything Around Me) launched in July 2020 as a fork of the Compound lending protocol, created by Jeffrey Huang. Huang was no anonymous dev: a long-time Ethereum entrepreneur, he had previously created the Ethereum-based social network and cryptocurrency Mithril, and outside crypto he founded the Taiwanese hip-hop group Machi and built a media and e-sports empire in Taiwan under that name. Rob Leshner, the founder of Compound, advised the project.
What stood out in 2020 was velocity:
Every other week, it seems, Cream will release some new functionality to its platform, becoming some sort of Swiss Army knife of DeFi.
Lending and borrowing like Compound, a Balancer-style AMM, a Curve-like multi-stablecoin pool called creamY, 20 supported assets where Compound listed 7, and farms to match:
Currently, the APY on all these farms is quite high, almost all of them are >100%.
The audit stance
The original review reported the founder's security position as a controversy rather than a dealbreaker:
In spite of its traction, Huang has made the controversial statement that he does not believe his code needs to be audited unless the auditor will be the Compound team itself (for the code that came out of Compound).
Here is how that stance played out. In February 2021, Cream was exploited for roughly $37M. In August 2021, attackers took another $18.8M. And on October 27, 2021, a flash-loan attack drained $130M, one of the largest DeFi exploits of that year and the protocol's third hack in twelve months.
An audit is not a guarantee; audited protocols get exploited too. But a founder who states in public that audits are unnecessary is telling you how the whole organization prices risk. We reported the quote in 2020. We should have weighted it.
The composability we celebrated
The most enthusiastic passage in the original described stacking yield on top of yield:
What this means is you can multiply your exposure to these pools by earning interest over an asset that is itself earning yield.
That is rehypothecation: yield-bearing tokens accepted as collateral for further borrowing. It is also, in different ways, what each exploit abused. The three attacks were not one bug repeated: the February 2021 loss stemmed from the debt accounting between Cream's Iron Bank and Alpha Homora, the August attack exploited an ERC-777 reentrancy hook to re-borrow before balances updated, and only the October raid fit the classic pattern of flash loans distorting the oracle prices of layered collateral. What they shared was surface area: every wrapped or lent layer added another price to report and another contract to value it correctly. The feature we described as multiplying your exposure multiplied the protocol's attack surface at the same rate.
Where Cream stands now
The original signed off with momentum:
Stay tuned, this project moves fast!
The project stopped moving. The contracts remain on-chain and the site is still up, but development is minimal and the team's last Medium post dates to early 2024. Independent reviewers now describe Cream as a legacy protocol struggling for relevance: a zombie protocol, neither shut down nor maintained.
What we take from it
The cheapest due-diligence signal is what a founder says about security. Huang's audit stance was public months before the first exploit; anyone could read it. The original review did, and moved on.
Composability compounds risk exactly as fast as it compounds yield. Each layer of wrapped, yield-bearing collateral is another oracle to game and another contract to break. When a protocol advertises yield on yield, the right question is who values each layer, and how.
And fast shipping without security investment buys reach, not durability. Cream out-shipped Compound on features and asset count, then paid for it three times in one year. Compound remains a reference protocol; Cream is a case study. For founders, that gap is the cost of treating audits as optional.