CSIDB logo
Incident

Akropolis

Incident posture

Attack window
Nov 2020
Location
-
Status
Historical
CIA posture
Available to members
Updated
2025-11-21 00:00

Linked entities

Victim
Akropolis
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Nov 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cryptocurrency lending platform suffered a flash loan attack resulting in the theft of approximately $2 million in Dai. The attacker exploited vulnerabilities in the platform's code to bypass repayment mechanisms, a common method targeting decentralized finance services. Platform administrators halted all transactions to mitigate further losses and engaged two external firms to investigate, though neither identified the specific attack vectors. The stolen funds were traced to an Ethereum wallet, with notifications sent to major exchanges to attempt freezing assets and prevent laundering. Efforts to reimburse affected users were underway following the incident.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On November 11, 2020, cryptocurrency borrowing and lending service Akropolis suffered a security breach in which a hacker executed a flash loan attack against its decentralized finance (DeFi) platform, resulting in the theft of approximately $2 million worth of Dai cryptocurrency. The attack occurred during the afternoon GMT timeframe, prompting Akropolis administrators to suspend all platform transactions immediately to prevent additional losses. Flash loan attacks involve borrowing funds from a DeFi platform while exploiting vulnerabilities in its smart contract code to bypass repayment mechanisms and abscond with the assets. This incident followed a broader trend of similar attacks targeting DeFi platforms throughout 2020, including a $24 million theft from Harvest Finance in October. Akropolis engaged two external firms to investigate the breach, though neither successfully identified the specific technical vectors exploited by the attacker.

Akropolis confirmed the attacker’s Ethereum wallet address, enabling blockchain tracking of the stolen funds. The company notified major cryptocurrency exchanges about the compromised wallet to facilitate freezing attempts and disrupt potential money laundering through cryptocurrency conversions or cash-outs. The platform acknowledged operational disruption from the transaction suspension and committed to exploring user reimbursement options for the stolen assets. No technical specifics regarding the exploited vulnerabilities or platform functionality were disclosed, as investigators failed to determine the precise attack methodology. The incident underscored the persistent security challenges facing DeFi platforms utilizing flash loan mechanisms during this period.

Sources

Sources available to members: 1 source.

CSIDB