{"investigation":{"slug":"cheesebank","entity_name":"CheeseBank","trust_score":18,"severity_base":null,"score_modifier":0,"confidence":0.78,"status":"published","content_type":"investigation","summary":"Cheese Bank was an Ethereum-based DeFi lending protocol that launched in September 2020 and suffered a $3.3 million exploit on November 6, 2020, caused by a flash loan attack combined with price oracle manipulation on Uniswap. The anonymous team claimed to have patched the vulnerability, but the protocol never recovered meaningful activity, the CHEESE token collapsed in value, and the project is widely considered abandoned. ZachXBT has flagged the entity as a high-risk project.","sections":[{"content":"Cheese Bank described itself as a decentralized autonomous digital bank on the Ethereum blockchain, offering lending, fund management, and insurance services. The protocol launched its yield farming in September 2020 and a 2.0 lending platform in October 2020. The native token, CHEESE, was an ERC-20 token with a total supply of 10 million, deployed to contract address 0xA04bDB1f11413a84D1F6C1d4d4FeD0208F2e68bF, with contract verification on Etherscan recorded on September 27, 2020. The project positioned itself as a community-driven initiative with no team allocation and no pre-mining, though its anonymous founding team and lack of disclosed audits made independent verification of these claims impossible. The protocol's architecture forked concepts from Compound Finance, relying on an AMM-based oracle to price collateral assets — a design choice that became the root cause of its eventual exploit.","heading":"Overview","sources":[{"url":"https://etherscan.io/token/0xA04bDB1f11413a84D1F6C1d4d4FeD0208F2e68bF","name":"etherscan.io","type":"other","credibility":3},{"url":"https://docs.cheesebank.io/","name":"docs.cheesebank.io","type":"other","credibility":3},{"url":"https://www.coincarp.com/currencies/cheesebank/","name":"coincarp.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On November 6, 2020, at approximately 19:22 UTC, Cheese Bank was exploited for approximately $3.3 million in stablecoins, comprising roughly 2,000,000 USDC, 1,230,000 USDT, and 87,000 DAI. The attacker executed a multi-step flash loan and price manipulation attack. First, the attacker borrowed 21,000 ETH via a flash loan from the dYdX protocol. They then swapped approximately 50 ETH for 107,000 CHEESE tokens on Uniswap V2, added these tokens and 78 ETH to the Uniswap V2 CHEESE-ETH liquidity pool, and received Uniswap V2 LP tokens in return. The attacker used these LP tokens to mint sUSD_V2 tokens as collateral within Cheese Bank and then executed a large swap — approximately 20,000 ETH for 288,000 CHEESE — causing a dramatic artificial inflation of the CHEESE/ETH Uniswap pool price. Because Cheese Bank's oracle calculated LP token collateral value as 'wEthBalance x 2 x ethPrice', this price manipulation caused the platform to dramatically overvalue the attacker's collateral. The attacker then called legitimate borrow() functions to drain the stablecoin reserves, repaid the flash loan, and consolidated the stolen funds to address 0x02b7165d0916e373f0235056a7e6fccdb82d2255. The exploit transaction hash is 0x600a869aa3a259158310a233b815ff67ca41eab8961a49918c2031297a02f1cc. Security firm PeckShield published a root cause analysis confirming the vulnerability shortly after the incident.","heading":"Incident Details","sources":[{"url":"https://peckshield.medium.com/cheese-bank-incident-root-cause-analysis-d076bf87a1e7","name":"peckshield.medium.com","type":"other","credibility":3},{"url":"https://blog.peckshield.com/2020/11/16/cheesebank/","name":"blog.peckshield.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/cheese-bank-s-multi-million-dollar-hack-explained-by-security-firm","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://ihodl.com/topnews/2020-11-17/defi-project-cheese-bank-loses-33m-after-hacker-attack/","name":"ihodl.com","type":"other","credibility":3},{"url":"https://insights.glassnode.com/defi-attacks-flash-loans-centralized-price-oracles/","name":"insights.glassnode.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The CHEESE token contract is deployed at Ethereum address 0xA04bDB1f11413a84D1F6C1d4d4FeD0208F2e68bF and is publicly verifiable on Etherscan. The exploit transaction, identified by PeckShield, carries hash 0x600a869aa3a259158310a233b815ff67ca41eab8961a49918c2031297a02f1cc. The attacker's receiving address was 0x02b7165d0916e373f0235056a7e6fccdb82d2255, where the stolen stablecoins were consolidated following the attack. The attacker leveraged dYdX flash loans for the 21,000 ETH position and interacted with the Uniswap V2 CHEESE-ETH pool for price manipulation. The drain was executed via Cheese Bank's own borrow() contract functions, meaning the on-chain calls appeared legitimate at a smart contract level and no reentrancy or direct code exploit was required — only the manipulation of the oracle pricing mechanism. Post-incident on-chain activity for the CHEESE token showed a near-total collapse in trading volume and liquidity, with the token's highest recorded price of $0.0001 reached as late as November 2022 before further decline. No documented fund recovery or return of stolen assets to victims has been observed on-chain.","heading":"On-Chain Evidence","sources":[{"url":"https://etherscan.io/token/0xA04bDB1f11413a84D1F6C1d4d4FeD0208F2e68bF","name":"etherscan.io","type":"other","credibility":3},{"url":"https://etherscan.io/address/0xa04bdb1f11413a84d1f6c1d4d4fed0208f2e68bf","name":"etherscan.io","type":"other","credibility":3},{"url":"https://peckshield.medium.com/cheese-bank-incident-root-cause-analysis-d076bf87a1e7","name":"peckshield.medium.com","type":"other","credibility":3},{"url":"https://insights.glassnode.com/defi-attacks-flash-loans-centralized-price-oracles/","name":"insights.glassnode.com","type":"other","credibility":3},{"url":"https://www.coincarp.com/currencies/cheesebank/","name":"coincarp.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The founding team behind Cheese Bank has remained entirely anonymous. The project's documentation stated that all participants were considered contributors and that development would be handed over to the community, with no team token allocation and no pre-mining. These claims could not be independently verified due to the anonymous nature of the team. The protocol launched with apparent connections to Chinese-speaking communities, as evidenced by bilingual (Chinese and English) announcements published on the official Medium blog in October 2020. The GitHub repository under the cheese-bank organization hosted the smart contract code, described as 'The Compound On-Chain Protocol,' indicating the protocol was substantially derived from Compound Finance's codebase. No independent smart contract audit from a recognized security firm was publicly disclosed prior to the November 2020 exploit. The absence of pre-launch auditing of the oracle pricing mechanism is noted as a significant oversight by security researchers who reviewed the incident. Following the exploit, the team published a statement on November 17, 2020, confirming the vulnerability had been patched and indicating that follow-up arrangements would be communicated. No further substantive communications from the team have been widely documented.","heading":"Team and Background","sources":[{"url":"https://cheesebank2020.medium.com/","name":"cheesebank2020.medium.com","type":"other","credibility":3},{"url":"https://github.com/cheese-bank/cheesebank","name":"github.com","type":"other","credibility":3},{"url":"https://docs.cheesebank.io/","name":"docs.cheesebank.io","type":"other","credibility":3},{"url":"https://ihodl.com/topnews/2020-11-17/defi-project-cheese-bank-loses-33m-after-hacker-attack/","name":"ihodl.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Cheese Bank represents a high-severity risk profile across multiple dimensions. The protocol suffered a complete loss of user funds — approximately $3.3 million — through a well-documented oracle manipulation exploit within weeks of its launch. No user compensation or fund recovery has been documented. The team was anonymous and has been effectively silent since November 2020, with no credible evidence of ongoing development or user support. The CHEESE token has no active exchange listings as of 2026, the project's documentation domain (docs.cheesebank.io) is no longer accessible, and the protocol's lending functions are listed as unavailable. PeckShield's post-mortem confirmed that the vulnerability — reliance on a single AMM-based oracle without time-weighting or multi-source averaging — was a known class of risk in DeFi at the time of deployment. The project's failure to implement standard oracle safeguards prior to launch, combined with anonymous team structure, lack of audits, and absence of any compensation mechanism for affected users, collectively represent a pattern consistent with negligent or reckless protocol deployment. ZachXBT has flagged the entity, further elevating its risk profile within the crypto security community. Users should treat any interaction with Cheese Bank contracts, tokens, or claimed successors as high risk.","heading":"Risk Assessment","sources":[{"url":"https://peckshield.medium.com/cheese-bank-incident-root-cause-analysis-d076bf87a1e7","name":"peckshield.medium.com","type":"other","credibility":3},{"url":"https://www.quadrigainitiative.com/casestudy/cheesebankheist.php","name":"quadrigainitiative.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/cheese-bank-s-multi-million-dollar-hack-explained-by-security-firm","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.coincarp.com/currencies/cheesebank/","name":"coincarp.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The Cheese Bank exploit occurred during a period of elevated DeFi flash loan attacks in late 2020. Glassnode research published at the time identified Cheese Bank among a cluster of DeFi protocols that fell victim to the same class of AMM-based oracle manipulation vulnerability during this period, alongside other notable exploits. The attack methodology — flash loan from dYdX, spot price manipulation on Uniswap, inflated collateral borrowing — was a well-established attack pattern by the time Cheese Bank launched, first demonstrated at scale in earlier 2020 exploits against protocols including bZx. Security researchers and firms such as PeckShield consistently advised protocols to use time-weighted average prices (TWAPs) or multi-source oracles rather than instantaneous AMM spot prices. The Cheese Bank incident contributed to broader industry awareness of this vulnerability class and is frequently cited in academic and practitioner literature on DeFi security, including a 2024 arXiv paper on static analysis approaches to flash loan vulnerabilities. The incident is listed among the documented DeFi hacks of 2020 by DeFiPrime, a reputable DeFi industry reference source.","heading":"Industry Context and Comparable Incidents","sources":[{"url":"https://insights.glassnode.com/defi-attacks-flash-loans-centralized-price-oracles/","name":"insights.glassnode.com","type":"other","credibility":3},{"url":"https://arxiv.org/html/2411.01230v1","name":"arxiv.org","type":"other","credibility":3},{"url":"https://defiprime.com/hacks2020","name":"defiprime.com","type":"other","credibility":3},{"url":"https://hackernoon.com/how-dollar100m-got-stolen-from-defi-in-2021-price-oracle-manipulation-and-flash-loan-attacks-explained-3n6q33r1","name":"hackernoon.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2020-09-27","event":"CHEESE ERC-20 token contract (0xA04bDB1f11413a84D1F6C1d4d4FeD0208F2e68bF) verified and deployed on Ethereum mainnet.","source":""},{"date":"2020-09-30","event":"Cheese Bank yield farming officially launched.","source":""},{"date":"2020-10-15","event":"Cheese Bank Lending Protocol 2.0 officially launched.","source":""},{"date":"2020-10-19","event":"Cheese Bank announced the launch of a new UNI_V2-ETH-USDC liquidity pool.","source":""},{"date":"2020-11-06","event":"Flash loan oracle manipulation exploit executed at 19:22 UTC, draining approximately $3.3 million in USDC, USDT, and DAI from Cheese Bank lending pools. Attacker consolidated funds to 0x02b7165d0916e373f0235056a7e6fccdb82d2255.","source":""},{"date":"2020-11-16","event":"PeckShield published a root cause analysis of the Cheese Bank incident, identifying the AMM-based oracle pricing formula as the root vulnerability.","source":""},{"date":"2020-11-17","event":"Cheese Bank team published a statement on Medium acknowledging the incident and claiming the vulnerability had been patched. No compensation plan for affected users was announced.","source":""},{"date":"2022-11-05","event":"CHEESE token reached its recorded all-time high of $0.0001, indicating near-total value destruction since the 2020 exploit.","source":""},{"date":"2026-05","event":"Project documentation domain (docs.cheesebank.io) inaccessible; CHEESE token unlisted on major exchanges; protocol considered abandoned by market participants.","source":"","date_original":"2026-05-01"}],"sources_used":[{"url":"https://etherscan.io/token/0xA04bDB1f11413a84D1F6C1d4d4FeD0208F2e68bF","name":"etherscan.io","type":"other","archive_url":"https://web.archive.org/web/20260829192842/https://etherscan.io/token/0xA04bDB1f11413a84D1F6C1d4d4FeD0208F2e68bF","credibility":3,"archive_timestamp":"2026-08-29T19:28:42+00:00"},{"url":"https://docs.cheesebank.io/","name":"docs.cheesebank.io","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-job","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.coincarp.com/currencies/cheesebank/","name":"coincarp.com","type":"other","archive_url":"https://web.archive.org/web/20260830092550/https://www.coincarp.com/currencies/cheesebank/","credibility":3,"archive_timestamp":"2026-08-30T09:25:50+00:00"},{"url":"https://peckshield.medium.com/cheese-bank-incident-root-cause-analysis-d076bf87a1e7","name":"peckshield.medium.com","type":"other","archive_url":"http://web.archive.org/web/20250910050526/https://peckshield.medium.com/cheese-bank-incident-root-cause-analysis-d076bf87a1e7","credibility":3,"archive_timestamp":"2025-09-10T05:05:26+00:00"},{"url":"https://blog.peckshield.com/2020/11/16/cheesebank/","name":"blog.peckshield.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-job","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cointelegraph.com/news/cheese-bank-s-multi-million-dollar-hack-explained-by-security-firm","name":"cointelegraph.com","type":"other","archive_url":"https://web.archive.org/web/20260829191718/https://cointelegraph.com/news/cheese-bank-s-multi-million-dollar-hack-explained-by-security-firm","credibility":3,"archive_timestamp":"2026-08-29T19:17:18+00:00"},{"url":"https://ihodl.com/topnews/2020-11-17/defi-project-cheese-bank-loses-33m-after-hacker-attack/","name":"ihodl.com","type":"other","archive_url":"http://web.archive.org/web/20260830085931/https://ihodl.com/topnews/2020-11-17/defi-project-cheese-bank-loses-33m-after-hacker-attack/","credibility":3,"archive_timestamp":"2026-08-30T08:59:31+00:00"},{"url":"https://insights.glassnode.com/defi-attacks-flash-loans-centralized-price-oracles/","name":"insights.glassnode.com","type":"other","archive_url":"http://web.archive.org/web/20260518061522/https://insights.glassnode.com/defi-attacks-flash-loans-centralized-price-oracles/","credibility":3,"archive_timestamp":"2026-05-18T06:15:22+00:00"},{"url":"https://etherscan.io/address/0xa04bdb1f11413a84d1f6c1d4d4fed0208f2e68bf","name":"etherscan.io","type":"other","archive_url":"http://web.archive.org/web/20260830085246/https://etherscan.io/address/0xa04bdb1f11413a84d1f6c1d4d4fed0208f2e68bf","credibility":3,"archive_timestamp":"2026-08-30T08:52:46+00:00"},{"url":"https://cheesebank2020.medium.com/","name":"cheesebank2020.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://github.com/cheese-bank/cheesebank","name":"github.com","type":"other","archive_url":"https://web.archive.org/web/20260829193116/https://github.com/cheese-bank/cheesebank","credibility":3,"archive_timestamp":"2026-08-29T19:31:16+00:00"},{"url":"https://www.quadrigainitiative.com/casestudy/cheesebankheist.php","name":"quadrigainitiative.com","type":"other","archive_url":"http://web.archive.org/web/20251116193734/https://quadrigainitiative.com/casestudy/cheesebankheist.php","credibility":3,"archive_timestamp":"2025-11-16T19:37:34+00:00"},{"url":"https://arxiv.org/html/2411.01230v1","name":"arxiv.org","type":"other","archive_url":"http://web.archive.org/web/20260830082657/https://arxiv.org/html/2411.01230v1","credibility":3,"archive_timestamp":"2026-08-30T08:26:57+00:00"},{"url":"https://defiprime.com/hacks2020","name":"defiprime.com","type":"other","archive_url":"http://web.archive.org/web/20260420182903/https://defiprime.com/hacks2020","credibility":3,"archive_timestamp":"2026-04-20T18:29:03+00:00"},{"url":"https://hackernoon.com/how-dollar100m-got-stolen-from-defi-in-2021-price-oracle-manipulation-and-flash-loan-attacks-explained-3n6q33r1","name":"hackernoon.com","type":"other","archive_url":"https://web.archive.org/web/20260829193355/https://hackernoon.com/how-dollar100m-got-stolen-from-defi-in-2021-price-oracle-manipulation-and-flash-loan-attacks-explained-3n6q33r1","credibility":3,"archive_timestamp":"2026-08-29T19:33:55+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:55:00.266134+00:00","updated_at":"2026-09-01T04:16:58.168671+00:00"}}