{"investigation":{"slug":"alpha-homora","entity_name":"Alpha Homora","trust_score":38,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Alpha Homora is a leveraged yield farming protocol developed by Alpha Finance Lab (later rebranded to Alpha Venture DAO, then Stella) that allows users to take on leveraged positions in liquidity pools. On February 13, 2021, the protocol suffered a critical exploit in which an attacker drained approximately $37.5 million from Iron Bank (C.R.E.A.M. Finance) by exploiting multiple smart contract vulnerabilities in Alpha Homora V2, including a hidden undisclosed sUSD lending pool, a rounding miscalculation in the borrow function, and an unrestricted reserve function callable by anyone. The resulting bad debt between the two protocols remained largely unresolved for years, culminating in a public dispute in 2023 in which Iron Bank froze Alpha Homora user accounts, and Alpha Homora proposed surrendering approximately $32 million in user funds to satisfy the outstanding obligation.","sections":[{"content":"Alpha Homora is a DeFi protocol that enables leveraged yield farming by allowing users to borrow assets and multiply their liquidity mining positions. It was developed by Alpha Finance Lab, a Thailand-based DeFi company co-founded by Tascha Punyaneramitdee (CEO) and Nipun Pitimanaaree (lead engineer), and launched in late 2020. The protocol integrates with other DeFi protocols for borrowing, most notably Iron Bank (part of C.R.E.A.M. Finance), which granted Alpha Homora V2 a whitelist credit line allowing undercollateralized protocol-to-protocol lending. Alpha Homora V1 launched on Ethereum supporting ETH leverage; V2 expanded to support a broader array of LP tokens and assets. At its peak, the protocol held approximately $1.9 billion in total value locked (TVL). Alpha Finance Lab rebranded to Alpha Venture DAO in March 2022 and subsequently to Stella in 2023, with the ALPHA token retained throughout.","heading":"Protocol Overview","sources":[{"url":"https://blog.alphaventuredao.io/alpha-finance-lab-rebrands-expands-into-alpha-venture-dao-to-disrupt-web3-ecosystem/","name":"blog.alphaventuredao.io","type":"other","credibility":3},{"url":"https://alphafinancelab.gitbook.io/alpha-finance-lab/alpha-finance-lab-main/alpha-team","name":"alphafinancelab.gitbook.io","type":"other","credibility":3},{"url":"https://coinmarketcap.com/cmc-ai/alpha-finance-lab/what-is/","name":"coinmarketcap.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On February 13, 2021 at approximately 05:37 UTC, an attacker executed a multi-transaction exploit against Alpha Homora V2, extracting approximately $37.5 million in assets from Iron Bank. The attack exploited three compounding vulnerabilities. First, Alpha Finance had deployed an sUSD lending pool at the contract level in preparation for an upcoming product release, but had not yet made it publicly available through the UI or announced it; because the pool had zero liquidity at the time, the attacker could fully manipulate and inflate total debt amounts and debt shares. Second, a rounding miscalculation in the borrow function allowed the attacker to repay fractionally less than owed (e.g., 1000.000098548938710983 sUSD instead of 1000.000098548938710984 sUSD), creating a divergence between debt shares and actual debt recorded. Third, the resolveReserve function — intended to collect protocol revenue — was callable by anyone and could increase totalDebt without a corresponding increase in totalDebtShare, which the attacker leveraged to inflate recorded debt and borrow ever-larger sums. Using Aave flash loans, the attacker cycled through multiple borrow-and-repay loops, accumulating cySUSD collateral on Iron Bank, which was then used to draw down 13,200 WETH, 3.6 million USDC, 5.6 million USDT, and 4.2 million DAI. Stolen funds were routed through Tornado Cash and the Curve Aave pool to obscure their trail. The attacker also deployed a custom malicious 'spell' contract, exploiting Alpha Homora V2's permissive spell system, which accepted any custom spell provided collateral nominally exceeded borrowings.","heading":"February 2021 Exploit — Attack Mechanics","sources":[{"url":"https://blog.alphaventuredao.io/alpha-homora-v2-post-mortem/","name":"blog.alphaventuredao.io","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-alpha-homora-defi-hack-feb-2021","name":"halborn.com","type":"other","credibility":3},{"url":"https://medium.com/cream-finance/alpha-homora-v2-exploit-post-mortem-344d277bdea6","name":"medium.com","type":"other","credibility":3},{"url":"https://rekt.news/alpha-finance-rekt","name":"rekt.news","type":"other","credibility":3}],"severity":"medium"},{"content":"Multiple security researchers and commentators noted that the exploit required knowledge of an unreleased, unannounced sUSD pool that was not visible in the UI, as well as intimate familiarity with a subtle rounding miscalculation only exploitable when the attacker was the sole borrower of a pool. The security analysis blog rekt.news stated that the setup required insider information and that 'no way this could be found by someone casually looking at the contracts, especially the unannounced stuff.' Alpha Finance Lab's own post-mortem acknowledged this concern and stated the team had identified a 'prime suspect.' Notably, following the exploit the attacker sent 1,000 ETH to Alpha's deployer address, 1,000 ETH to C.R.E.A.M. Finance's deployer address, 100 ETH to Tornado Cash, and 100 ETH to a Gitcoin grant for Tornado Cash — an unusual pattern that further fueled speculation. No public criminal charges or definitive attribution has been made as of the writing of this report. These allegations are unverified and should be treated as alleged.","heading":"Insider Knowledge Allegations","sources":[{"url":"https://rekt.news/alpha-finance-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://nodesblock.com/news/review-of-the-37-5-million-theft-of-alpha-finance-hackers-have-inside-information/","name":"nodesblock.com","type":"other","credibility":3},{"url":"https://blog.alphaventuredao.io/alpha-homora-v2-post-mortem/","name":"blog.alphaventuredao.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Alpha Homora V2 underwent two formal security audits prior to the February 2021 exploit: one by Quantstamp (completed January 14, 2021, involving three auditors over six weeks) and one by PeckShield. The Quantstamp audit identified 15 issues in total, including four categorized as high severity — all of which were reported as fixed before launch. QSP-3, one of the high-severity findings, specifically involved an incorrect math calculation where variables totalShare and totalDebt were interchanged, which is directly related to the class of vulnerability ultimately exploited. However, the precise attack vector — dependent on the interaction between the hidden sUSD pool, rounding behavior under sole-borrower conditions, and the publicly callable resolveReserve function — was not identified by either auditor. An OpenZeppelin audit was also conducted and completed in the period after the exploit. Security researchers noted that the exploited scenario was not a common Solidity coding pitfall detectable by automated tooling, but rather an emergent vulnerability arising from a complex combination of business logic, specific pool conditions, and cross-protocol interactions. A third audit by OpenZeppelin was completed after the exploit occurred.","heading":"Pre-Exploit Audit Failures","sources":[{"url":"https://blog.alphaventuredao.io/alpha-homora-v2-post-mortem/","name":"blog.alphaventuredao.io","type":"other","credibility":3},{"url":"https://secureum.substack.com/p/making-alpha-safu-secureum-9","name":"secureum.substack.com","type":"other","credibility":3},{"url":"https://twitter.com/alphafinancelab/status/1351892956077150210","name":"twitter.com","type":"other","credibility":3},{"url":"https://www.investing.com/news/cryptocurrency-news/openzeppelin-completes-an-audit-of-alpha-homora-v2-2468376","name":"investing.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Because Alpha Homora V2 held a whitelisted credit line with Iron Bank, the $37.5 million in exploited assets represented debt owed by Alpha Homora V2 as a protocol to Iron Bank, not directly by individual users to Alpha Homora V2. In the immediate aftermath, Alpha Finance Lab and C.R.E.A.M. Finance reached a remediation agreement: Alpha agreed to divert 20% of future protocol fees toward debt repayment and post 50 million ALPHA tokens (worth approximately $109 million at the time) as collateral. However, as the crypto market declined, the value of the ALPHA token collateral fell from roughly $109 million to approximately $6 million by early 2023, leaving the debt severely undercollateralized. By March 2023, the outstanding balance had only been reduced by approximately $481,746 over 25 months — an average of roughly $5,000 per month against a balance of over $31.9 million. In March 2023, Iron Bank publicly called on Alpha Homora to take responsibility for the bad debt and unilaterally paused Alpha Homora's lending accounts by altering code in its smart contracts, preventing Alpha Homora from withdrawing user-deposited assets. Alpha Homora publicly disputed this action, characterizing it as Iron Bank using user funds as leverage in a bilateral protocol dispute. Alpha Homora subsequently proposed that Iron Bank retain approximately $32 million in Alpha users' deposited assets to satisfy the outstanding debt, with any excess above the debt amount returned to users. As of available reporting, no final resolution had been publicly confirmed.","heading":"Protocol-to-Protocol Debt and Iron Bank Dispute","sources":[{"url":"https://www.theblock.co/post/216536/iron-bank-freezes-alpha-homora-lending-accounts-over-bad-debt-dispute","name":"theblock.co","type":"other","credibility":3},{"url":"https://www.theblock.co/post/216832/iron-bank-tells-alpha-homora-to-take-ownership-of-its-bad-debt","name":"theblock.co","type":"other","credibility":3},{"url":"https://thedefiant.io/news/defi/alpha-homora-cedes-32m-user-funds-iron-bank","name":"thedefiant.io","type":"other","credibility":3},{"url":"https://blog.alphaventuredao.io/an-open-letter-to-iron-bank/","name":"blog.alphaventuredao.io","type":"other","credibility":3},{"url":"https://medium.com/@ibdotxyz/timeline-between-iron-bank-alpha-homora-v2-e0bfe75467b8","name":"medium.com","type":"other","credibility":3},{"url":"https://www.dlnews.com/articles/defi/defi-partners-clash-over-32m-bad-debt-iron-bank-alpha-homora/","name":"dlnews.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, Alpha Finance Lab undertook a phased rebranding. In March 2022, the company rebranded to Alpha Venture DAO, repositioning around a decentralized venture capital and incubation model while retaining the ALPHA token. In 2023, the core leveraged yield farming product line was rebranded again as Stella, which launched on Arbitrum with a novel 0% cost-to-borrow model under a Pay-As-You-Earn (PAYE) structure. Stella reported a TVL of approximately $6 million as of early 2024. The rebranding has allowed the team to distance the product from the Alpha Homora exploit while maintaining continuity of the underlying technology and token. The ALPHA token has experienced significant value deterioration since its early 2021 highs, in part attributed to the unresolved Iron Bank debt situation and broader crypto market conditions.","heading":"Rebranding and Continued Operations","sources":[{"url":"https://blog.alphaventuredao.io/alpha-finance-lab-rebrands-expands-into-alpha-venture-dao-to-disrupt-web3-ecosystem/","name":"blog.alphaventuredao.io","type":"other","credibility":3},{"url":"https://medium.com/@stellaxyz_/stella-the-leveraged-strategies-protocol-with-0-cost-to-borrow-bad4f89d5cd3","name":"medium.com","type":"other","credibility":3},{"url":"https://www.gate.com/crypto-wiki/article/stella-alpha-summary-leveraged-yield-farming-reimagined","name":"gate.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The Iron Bank dispute introduced substantial risk for Alpha Homora V2 depositors, whose assets were frozen by Iron Bank during the 2023 dispute without their direct involvement in or consent to the underlying debt arrangement. Alpha Homora's proposal to use $32 million in user-deposited assets to settle the debt represented a scenario in which depositors faced the effective loss of funds due to a protocol-level liability they did not individually incur. The incident illustrates a systemic risk in DeFi: whitelisted protocol-to-protocol credit lines can create off-balance-sheet liabilities that materially affect end users in the event of an exploit or insolvency. Separately, the original exploit did not result in direct user fund losses from Alpha Homora V2 positions themselves at the time of the attack, as the debt was structured between protocols. However, the long-tail consequence — the multi-year debt dispute and eventual proposed seizure of user assets — represents a material harm to depositors.","heading":"User and Depositor Risk Assessment","sources":[{"url":"https://www.dlnews.com/articles/defi/defi-partners-clash-over-32m-bad-debt-iron-bank-alpha-homora/","name":"dlnews.com","type":"other","credibility":3},{"url":"https://thedefiant.io/news/defi/alpha-homora-cedes-32m-user-funds-iron-bank","name":"thedefiant.io","type":"other","credibility":3},{"url":"https://blockbytes.com/2023/03/08/iron-bank-vs-alpha-homora-protocol-exploits-protocol/","name":"blockbytes.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2020-10","event":"Alpha Homora V1 launches on Ethereum, enabling leveraged ETH yield farming.","source":"","date_original":"2020-10-01"},{"date":"2021-01-14","event":"Quantstamp completes audit of Alpha Homora V2, identifying 4 high-severity issues all reported as fixed.","source":""},{"date":"2021-01-20","event":"PeckShield completes audit of Alpha Homora V2; no high-severity issues reported.","source":""},{"date":"2021-01-28","event":"Alpha Homora V2 launches on Ethereum mainnet, integrated with Iron Bank for protocol-to-protocol borrowing.","source":""},{"date":"2021-02-13","event":"Exploit occurs at 05:37 UTC: attacker drains approximately $37.5 million from Iron Bank via Alpha Homora V2 using a multi-transaction attack exploiting the hidden sUSD pool, a rounding miscalculation, and the publicly callable resolveReserve function.","source":""},{"date":"2021-02-13","event":"C.R.E.A.M. Finance pauses all Iron Bank markets and sets Alpha Homora V2 credit limit to zero pending investigation.","source":""},{"date":"2021-02-13","event":"Stolen funds routed through Tornado Cash and Curve Aave pool. Attacker sends 1,000 ETH each to Alpha and C.R.E.A.M. deployer addresses.","source":""},{"date":"2021-02-14","event":"Alpha Finance Lab releases post-mortem; confirms team has identified a 'prime suspect'; agrees to 20% protocol fee diversion and 50 million ALPHA token collateral to cover Iron Bank debt.","source":""},{"date":"2021-03","event":"Alpha Homora V2 relaunches with restricted token support (ETH, DAI, USDC, USDT) and additional security mitigations.","source":"","date_original":"2021-03-01"},{"date":"2022-03-31","event":"Alpha Finance Lab rebrands to Alpha Venture DAO, pivoting to a Web3 incubation and DAO governance model while retaining the ALPHA token.","source":""},{"date":"2023-03-02","event":"Iron Bank publicly reports Alpha Homora's outstanding debt at $31,947,429, with only $481,746 repaid in 25 months. Iron Bank freezes Alpha Homora's lending accounts by altering smart contract code.","source":""},{"date":"2023-03","event":"Alpha Venture DAO publishes open letter to Iron Bank, characterizing the account freeze as an unauthorized seizure of user funds.","source":"","date_original":"2023-03-01"},{"date":"2023-03","event":"Alpha Homora proposes that Iron Bank retain approximately $32 million in user-deposited assets to satisfy the outstanding debt obligation.","source":"","date_original":"2023-03-01"},{"date":"2023-06","event":"Core development team relaunches leveraged DeFi product as Stella on Arbitrum, with a 0% cost-to-borrow Pay-As-You-Earn model.","source":"","date_original":"2023-06-01"}],"sources_used":[{"url":"https://blog.alphaventuredao.io/alpha-finance-lab-rebrands-expands-into-alpha-venture-dao-to-disrupt-web3-ecosystem/","name":"blog.alphaventuredao.io","type":"other","credibility":3},{"url":"https://alphafinancelab.gitbook.io/alpha-finance-lab/alpha-finance-lab-main/alpha-team","name":"alphafinancelab.gitbook.io","type":"other","credibility":3},{"url":"https://coinmarketcap.com/cmc-ai/alpha-finance-lab/what-is/","name":"coinmarketcap.com","type":"other","credibility":3},{"url":"https://blog.alphaventuredao.io/alpha-homora-v2-post-mortem/","name":"blog.alphaventuredao.io","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-alpha-homora-defi-hack-feb-2021","name":"halborn.com","type":"other","credibility":3},{"url":"https://medium.com/cream-finance/alpha-homora-v2-exploit-post-mortem-344d277bdea6","name":"medium.com","type":"other","credibility":3},{"url":"https://rekt.news/alpha-finance-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://nodesblock.com/news/review-of-the-37-5-million-theft-of-alpha-finance-hackers-have-inside-information/","name":"nodesblock.com","type":"other","credibility":3},{"url":"https://secureum.substack.com/p/making-alpha-safu-secureum-9","name":"secureum.substack.com","type":"other","credibility":3},{"url":"https://twitter.com/alphafinancelab/status/1351892956077150210","name":"twitter.com","type":"other","credibility":3},{"url":"https://www.investing.com/news/cryptocurrency-news/openzeppelin-completes-an-audit-of-alpha-homora-v2-2468376","name":"investing.com","type":"other","credibility":3},{"url":"https://www.theblock.co/post/216536/iron-bank-freezes-alpha-homora-lending-accounts-over-bad-debt-dispute","name":"theblock.co","type":"other","credibility":3},{"url":"https://www.theblock.co/post/216832/iron-bank-tells-alpha-homora-to-take-ownership-of-its-bad-debt","name":"theblock.co","type":"other","credibility":3},{"url":"https://thedefiant.io/news/defi/alpha-homora-cedes-32m-user-funds-iron-bank","name":"thedefiant.io","type":"other","credibility":3},{"url":"https://blog.alphaventuredao.io/an-open-letter-to-iron-bank/","name":"blog.alphaventuredao.io","type":"other","credibility":3},{"url":"https://medium.com/@ibdotxyz/timeline-between-iron-bank-alpha-homora-v2-e0bfe75467b8","name":"medium.com","type":"other","credibility":3},{"url":"https://www.dlnews.com/articles/defi/defi-partners-clash-over-32m-bad-debt-iron-bank-alpha-homora/","name":"dlnews.com","type":"other","credibility":3},{"url":"https://medium.com/@stellaxyz_/stella-the-leveraged-strategies-protocol-with-0-cost-to-borrow-bad4f89d5cd3","name":"medium.com","type":"other","credibility":3},{"url":"https://www.gate.com/crypto-wiki/article/stella-alpha-summary-leveraged-yield-farming-reimagined","name":"gate.com","type":"other","credibility":3},{"url":"https://blockbytes.com/2023/03/08/iron-bank-vs-alpha-homora-protocol-exploits-protocol/","name":"blockbytes.com","type":"other","credibility":3}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-30T19:10:41.350788+00:00","updated_at":"2026-08-29T01:35:08.493+00:00"}}