OAK — OnChain Attack Knowledge

Worked example · 2020-11

Cred Inc. custodial-fraud / counterparty-risk insolvency — multi-chain (custodial) — 2020-11-07

Loss
approximately $140M+ in customer crypto-asset mismanagement, by the most-cited contemporaneous reporting and bankruptcy-filing figures. Subsequent claims-process disclosures and forensic reporting expanded the headline figure to roughly $140M–$190M depending on whether peak deposit values, time-of-loss values, or claim-recognition values are used. The Chapter 11 case (US Bankruptcy Court, District of Delaware, Case No. 20-12836, filed 2020-11-07) and subsequent claims-and-distribution proceedings are the primary settled-record source.
Recovery
partial; through the bankruptcy-claims process, customer creditors received cents-on-the-dollar distributions over multi-year proceedings. The "third-party investment counterparty" — described in court filings as a Chinese-domiciled crypto-asset borrower (MoKredit) and other entities — disappeared with custodied customer funds; portions were partially traced via on-chain forensics but were not substantially recovered.
OAK Techniques observed
OAK-T11.010 (Off-chain Counterparty-Risk Insolvency — the canonical anchor. Cred's failure was a counterparty-credit-risk insolvency: the MoKredit default triggered a customer-asset coverage gap, and Cred's Chapter 11 filing was the formal recognition of an already-present counterparty-driven insolvency. See techniques/T11.010-off-chain-counterparty-risk-insolvency.md). OAK-T6.007 (Trust-Substrate Shift / Vendor-Promise Revocation — Cred's suspension of withdrawals and subsequent bankruptcy filing represents a trust-substrate shift: depositors who relied on Cred's yield promise and custody representations discovered the platform was insolvent).
Attribution
confirmed via US bankruptcy court proceedings (D. Del. Case No. 20-12836). The case names (a) Cred Inc. and its subsidiaries as the debtor parties, (b) MoKredit as the principal third-party investment counterparty, and (c) several individual former Cred officers in subsequent legal proceedings (litigation against former Cred officers Daniel Schatt and Joseph Podulka was pursued by the Trustee through 2021–2023). Criminal proceedings against former Cred Chief Capital Officer James Alexander (separate from the bankruptcy case, related to alleged BTC theft from Cred) produced a 2022 federal indictment in the Northern District of California. The attribution material is on the public judicial record and is available for any future OAK Technique-page citation.
Key teaching point
Cred November 2020 is the canonical T11.010 anchor — the foundational worked example establishing the Off-chain Counterparty-Risk Insolvency Technique class. The failure mode is an operator-side credit-risk-management failure: concentrated re-lending of customer deposits to a small set of offshore counterparties, counterparty default, and customer-facing insolvency resolved through the bankruptcy-claims process. The OAK-T11.010 Technique captures this pattern; Celsius, Voyager, BlockFi, Genesis, and FTX are structural descendants at larger loss magnitudes. See techniques/T11.010-off-chain-counterparty-risk-insolvency.md.

Summary

Cred Inc. (formerly Libra Credit; not affiliated with the Libra / Diem stablecoin project) was a US-incorporated custodial crypto-asset lending platform that operated a "CredEarn" yield product — customers deposited BTC, ETH, stablecoins, and other crypto assets with Cred, and Cred paid them yield ostensibly funded by re-lending the deposited assets to third-party borrowers and yield-investment counterparties. The platform was active through 2018–2020 and reached a peak headline AUM in the multi-hundred-million-dollar range. Cred filed for Chapter 11 bankruptcy protection on 2020-11-07 in the US Bankruptcy Court for the District of Delaware (Case No. 20-12836). The filing — and subsequent disclosures through the bankruptcy proceedings — described an aggregate customer-asset shortfall of roughly $140M+ at filing-time valuation, with the post-petition record expanding the figure as further claims and forensic findings entered the case file.

The proximate cause was a combination of (a) Cred's primary third-party investment counterparty — MoKredit, a Chinese-domiciled crypto-asset lending business — defaulting on its obligations to Cred during 2020, with the practical consequence that customer-deposited assets re-lent through MoKredit became unrecoverable; (b) alleged separate fraud / theft within Cred's own operations involving former Chief Capital Officer James Alexander, who was accused (in a 2022 federal indictment in the Northern District of California, US v. Alexander) of misappropriating approximately 800 BTC from Cred for personal benefit; and (c) broader operational-control and fiduciary failures that the bankruptcy Trustee subsequently litigated against Cred's former officers Daniel Schatt and Joseph Podulka through 2021–2023. The aggregate effect on Cred's ability to honour customer redemptions was that the platform became insolvent on a customer-asset-coverage basis well before the November 2020 Chapter 11 filing; the filing was the formal recognition of an already-present insolvency.

For OAK's purposes, the Cred case is a custodial-fraud / counterparty-risk insolvency event with on-chain components, not a primary on-chain Technique case. The on-chain footprint — customer-asset-to-MoKredit and customer-asset-to-Alexander-controlled addresses — is traceable on Bitcoin and Ethereum, and forensic firms (BitGo, Chainalysis, the bankruptcy Trustee's retained forensic teams) have published partial trace material in the case file. But the failure mode — a custodial operator extending unsecured credit to an offshore counterparty with insufficient due-diligence and inadequate risk controls, then absorbing the counterparty's default as a customer-facing solvency event — is not an on-chain Technique in OAK v0.1's sense. It is included here for the historical record because (i) the failure is contemporaneous with the high-profile DeFi-attack wave of November 2020 (Akropolis, OUSD, Pickle), reinforcing a failure-pattern theme across both DeFi and CeFi in the same period; (ii) the case is one of the cleanest worked examples in the OAK corpus for the counterparty-risk / yield-without-due-diligence failure pattern that recurs at scale across Celsius (2022), Voyager (2022), BlockFi (2022), Genesis (2023), and arguably FTX (2022); and (iii) it documents a category of failure that future OAK Technique-page work should consider whether to formalise.

Timeline (UTC)

When Event OAK ref
2018–2020 Cred operates CredEarn yield product; accepts customer crypto-asset deposits; re-lends a substantial portion to third-party investment counterparties including MoKredit (standing operational context — off-chain custodial-yield model)
2020 (Q1–Q3) MoKredit and other Cred counterparties experience financial distress in the broader 2020 macro environment; Cred's exposure to these counterparties begins to materialise as a customer-coverage gap (off-chain counterparty deterioration)
2020 (mid-year, alleged) Per subsequent indictment, former Cred CCO James Alexander allegedly misappropriates 800 BTC ($10M+ at then-current prices) from Cred holdings for personal benefit (alleged off-chain insider fraud — separately litigated, see US v. Alexander)
2020-10 Cred suspends customer withdrawals and "inflows / outflows on the platform" amid liquidity stress (operator-side acknowledgment of liquidity pressure)
2020-11-07 Cred Inc. and subsidiaries file Chapter 11 bankruptcy petition, US Bankruptcy Court, District of Delaware, Case No. 20-12836 (formal insolvency recognition)
2020-11 onward Bankruptcy proceedings disclose aggregate customer-asset shortfall of ~$140M+; MoKredit and other counterparty exposures named as principal causes (discovery / disclosure)
2020-11 onward Forensic firms (Chainalysis and others) and the Trustee's retained advisors begin tracing on-chain customer-asset movements to counterparty-controlled addresses (forensic trace — partial public release)
2021–2023 Bankruptcy Trustee pursues litigation against former Cred officers Daniel Schatt and Joseph Podulka for alleged fiduciary failures and operational misconduct (judicial proceedings — civil, against officers)
2022 (date in 2022) US federal indictment in Northern District of California, US v. Alexander, charges former Cred CCO James Alexander with wire fraud, money laundering, and related counts in connection with alleged BTC misappropriation from Cred (judicial proceedings — criminal, against Alexander)
2021–2024 Bankruptcy claims-and-distribution process produces partial distributions to Cred customer creditors at cents-on-the-dollar recovery rates; precise final distribution percentages depend on the proof-of-claim cohort and asset basket (recovery — bankruptcy claims process)
2020-11 onward Cred case is widely cited in industry analyses as an early canonical CeFi-yield-platform failure, foreshadowing the 2022–2023 CeFi-yield-platform collapse wave (Celsius, Voyager, BlockFi, Genesis) (historical-pattern record)

What defenders observed

  • The failure mode was off-chain counterparty default, surfacing as on-chain insolvency. Cred's customer-asset deposits arrived on-chain (BTC, ETH, stablecoin transactions to Cred-controlled custody addresses); the deposited assets were then transferred — also on-chain — to counterparty-controlled addresses (MoKredit, others) for yield-investment purposes; the counterparty default and asset disappearance happened across the off-chain custodial relationship between Cred and the counterparty, not at any on-chain Technique surface that OAK v0.1 enumerates. From a defender's perspective, this means standard on-chain-monitoring tooling (Forta, OpenZeppelin Defender, BlockSec PhalconHQ, Chainalysis Reactor at runtime) would not have surfaced the impending insolvency from on-chain signals alone — the relevant signal was the Cred-to-MoKredit asset flow itself, which on-chain looks like a normal counterparty-funding transfer and is not anomalous to a per-transaction monitor. The defender lesson is that counterparty-risk failure is a flow-level, longitudinal-relationship-level observable rather than a per-transaction observable, and on-chain-only monitoring is insufficient to surface it.
  • "Yield without counterparty-due-diligence" is the recurring pattern, not a Cred-specific failure. The same pattern recurs at Celsius 2022 (counterparty exposure to Three Arrows, FTX, and others), Voyager 2022 (Three Arrows exposure), BlockFi 2022 (Three Arrows and FTX exposure), Genesis 2023 (Three Arrows and FTX exposure), and arguably FTX 2022 (Alameda exposure). The structural feature shared across all these cases is a custodial-yield product whose yield is funded by re-lending customer deposits to a small set of high-leverage counterparties, with insufficient operator-side risk controls, insufficient external-disclosure of counterparty composition, and insufficient regulatory mandated capital-adequacy or segregation requirements. Cred is the earliest cleanly-documented case in OAK's corpus of this pattern; subsequent cases at much larger loss magnitudes (Celsius ~$1.2B+, FTX ~$8B+) are structurally lineal descendants. Contributors writing any future OAK material on the CeFi-yield-platform failure class should reference Cred as the historical anchor.
  • The judicial-record attribution tier matters. Cred is one of the relatively few cases in OAK's worked-examples corpus where the failure has been adjudicated through a US Bankruptcy Court (Case No. 20-12836), with separately-pursued civil litigation against named officers and a separate criminal indictment against a named individual former officer. This produces an attribution-strength tier substantially above pseudonymous or partially-fingerprinted cases — the failure mode is documented in court filings, the principal counterparty is named, and the principal alleged-individual-fraud component is on the criminal-indictment record. Contributors writing future cases involving bankruptcy / regulatory / criminal proceedings should treat the judicial-record tier as a meaningful attribution-strength category in its own right.
  • Customer-facing recovery via bankruptcy claims is materially different from on-chain or operator-funded recovery. Cred's customer creditors received distributions through the Chapter 11 process at cents-on-the-dollar rates over multi-year proceedings. This is a recovery-channel distinct from on-chain partial recovery (Harvest), distinct from negotiated full recovery (Lendf.me), distinct from operator-funded compensation (Akropolis, OUSD), and distinct from token-based compensation (Akropolis). The bankruptcy-claims-and-distribution channel reappears at Mt. Gox (the canonical OAK worked example), Cred (this case), Celsius, Voyager, BlockFi, FTX, and Genesis. Contributors writing future Technique pages on recovery-channel taxonomy should treat the bankruptcy-claims channel as its own category, and Mt. Gox / Cred as the foundational worked examples.
  • The TAXONOMY-GAPS.md flag is honest and load-bearing. OAK v0.1 does not have a Technique that cleanly captures Cred's failure mode. Stretching T11.x to cover off-chain counterparty default would dilute T11.x's meaning (which is properly about custody-and-signing key surfaces, not off-chain credit decisions); stretching T1.x economic-trust framings to cover counterparty-default events would dilute T1.x's meaning. The honest framing is that off-chain counterparty-risk failure is a category OAK v0.1 does not capture, and Cred is one of the cleanest evidence-points for why a future v0.x version might consider adding such a Technique. Contributors writing future cases that fit the same gap (Celsius, Voyager, BlockFi, FTX, Genesis) should preserve the same honest framing and add to the gap-record rather than over-fitting their cases to the existing Technique set.

What this example tells contributors writing future Technique pages

  • Be honest about weak Technique fit. Cred's primary failure mode is not on-chain. Future contributors writing similarly weak-fit cases — including the larger 2022 CeFi-yield-platform failures — should preserve the honest framing rather than stretching the existing T9.x / T11.x Technique surface to cover them. The OAK corpus's value as a defender / contributor / risk-modeller artefact depends on the Technique categories being meaningful, which requires preserving the distinction between cases that fit cleanly and cases that document a known taxonomy gap.
  • Bankruptcy-claims recovery is its own recovery-channel category. The category appears at Mt. Gox, Cred, Celsius, Voyager, BlockFi, FTX, Genesis; contributors writing any of these cases should record the recovery composition explicitly: filing-time-loss figure vs. claim-recognition figure vs. final-distribution figure, with the per-creditor-class distribution percentage (where disclosed) and the timeline-to-distribution. This information is materially load-bearing for downstream risk modelling that uses OAK as a reference, and is often summarised inadequately in non-judicial sources.
  • Counterparty-risk pattern is contemporaneous with on-chain attack patterns, not subsequent to them. The Cred case is not a 2022-CeFi-collapse-wave-precursor in any retrospective sense; it is a case from the same November 2020 month as Akropolis, OUSD, and Pickle. The structural lesson is that DeFi-on-chain-attacks and CeFi-counterparty-failures are concurrent failure-mode populations, both producing customer-asset losses, with structurally different attack / failure surfaces but overlapping defender-relevant lessons. Contributors writing any future OAK material on the historical-pattern view of crypto-asset losses should preserve this concurrency and not impose a misleading "DeFi era → CeFi era" temporal-sequencing narrative on the corpus.
  • Court filings are first-class citations. Cred's principal authoritative source is the bankruptcy court file (Case No. 20-12836, D. Del.) and its docket — not the contemporaneous CoinDesk / The Block coverage, useful as those are. The same principle applies to any case that has produced US federal court proceedings: court filings are the canonical record, and contributors should cite the specific case number and court rather than relying solely on press-summarised accounts. This is the citation discipline OAK applies to the Mt. Gox bankruptcy proceedings, the FTX bankruptcy proceedings, and the various USDOJ criminal indictments cited elsewhere in the worked-examples corpus; Cred fits the same pattern.

Public references

  • US Bankruptcy Court, District of Delaware. In re: Cred Inc. et al., Case No. 20-12836. 2020-11-07 filing and subsequent docket — [crebankruptcy2020]. The canonical primary source for the Cred insolvency: petition filings, schedules of customer claims, Trustee reports, and disclosure statements through the Chapter 11 proceedings.
  • US District Court, Northern District of California. United States v. James Alexander, federal indictment, 2022 — [usalexander2022]. The criminal-indictment record for alleged BTC misappropriation from Cred by former CCO James Alexander.
  • The Block. "Cred files for Chapter 11 bankruptcy after suffering 'irregularities' in handling of corporate funds." The Block, 2020-11-08 — [theblockcred2020]. Contemporaneous mainstream-press reporting on the bankruptcy filing; cited for the "irregularities" framing and the November 2020 industry-context.
  • CoinDesk. "Crypto Lender Cred Files for Bankruptcy." CoinDesk, 2020-11-08 — [coindeskcred2020]. CoinDesk's contemporaneous reporting on the bankruptcy filing; cited for the customer-impact framing.
  • Decrypt. "Crypto Lender Cred Owes $140 Million to Customers, Bankruptcy Filing Reveals." Decrypt, 2020-11 — [decryptcred2020]. Decrypt's contemporaneous reporting on the headline customer-asset shortfall figure.
  • The Block. "Cred's former chief capital officer charged with wire fraud over alleged 800 BTC theft." The Block, 2022 — [theblockalexander2022]. Contemporaneous reporting on the Alexander criminal indictment.
  • Chainalysis. Crypto Crime Report 2021 (relevant chapter on CeFi insolvencies) — [chainalysiscrimereport2021]. Chainalysis's industry-analysis framing of the 2020 CeFi-yield-platform failure pattern; cites Cred as one of the pattern's documented cases.
  • Companion-citation note: subsequent CeFi-yield-platform failures (Celsius, Voyager, BlockFi, Genesis, FTX) are not cited individually in this Cred-specific bibliography but should be cross-referenced when contributors write the corresponding individual worked examples; this Cred page should appear in the Discussion sections of those subsequent cases as the historical anchor for the counterparty-risk pattern.

Proposed new BibTeX entries

@misc{crebankruptcy2020,
  author       = {{US Bankruptcy Court, District of Delaware}},
  title        = {In re: {Cred Inc.} et al., Case No. 20-12836},
  year         = {2020},
  howpublished = {US Bankruptcy Court filing and docket},
  url          = {https://www.deb.uscourts.gov/},
  note         = {OAK v0.1 — proposed. Canonical primary source for the Cred insolvency: petition filings, schedules, Trustee reports, and disclosure statements through Chapter 11 proceedings beginning 2020-11-07.}
}

@misc{usalexander2022,
  author       = {{US District Court, Northern District of California}},
  title        = {United States v. {James Alexander}, federal indictment},
  year         = {2022},
  howpublished = {US federal indictment, N.D. Cal.},
  url          = {https://www.justice.gov/usao-ndca},
  note         = {OAK v0.1 — proposed. Criminal-indictment record for alleged BTC misappropriation from Cred by former CCO James Alexander; indictment date in 2022, separate from the Cred bankruptcy proceedings.}
}

@misc{theblockcred2020,
  author       = {{The Block}},
  title        = {{Cred} files for Chapter 11 bankruptcy after suffering 'irregularities' in handling of corporate funds},
  year         = {2020},
  howpublished = {News article, The Block},
  url          = {https://www.theblock.co/post/83802/cred-files-bankruptcy-irregularities},
  note         = {OAK v0.1 — proposed. Contemporaneous mainstream-press reporting on the Cred Chapter 11 filing; cited for the "irregularities" framing.}
}

@misc{coindeskcred2020,
  author       = {{CoinDesk}},
  title        = {Crypto Lender {Cred} Files for Bankruptcy},
  year         = {2020},
  howpublished = {News article, CoinDesk},
  url          = {https://www.coindesk.com/business/2020/11/08/crypto-lender-cred-files-for-bankruptcy},
  note         = {OAK v0.1 — proposed. CoinDesk's contemporaneous reporting on the Cred bankruptcy filing; cited for customer-impact framing.}
}

@misc{decryptcred2020,
  author       = {{Decrypt}},
  title        = {Crypto Lender {Cred} Owes $140 Million to Customers, Bankruptcy Filing Reveals},
  year         = {2020},
  howpublished = {News article, Decrypt},
  url          = {https://decrypt.co/},
  note         = {OAK v0.1 — proposed. Decrypt's contemporaneous reporting on the headline customer-asset shortfall figure for the Cred bankruptcy.}
}

@misc{theblockalexander2022,
  author       = {{The Block}},
  title        = {{Cred}'s former chief capital officer charged with wire fraud over alleged 800 {BTC} theft},
  year         = {2022},
  howpublished = {News article, The Block},
  url          = {https://www.theblock.co/},
  note         = {OAK v0.1 — proposed. Contemporaneous reporting on the federal indictment of former Cred CCO James Alexander for alleged BTC misappropriation from Cred; relates to but is separate from the Cred bankruptcy proceedings.}
}

@misc{chainalysiscrimereport2021,
  author       = {{Chainalysis}},
  title        = {Crypto Crime Report 2021},
  year         = {2021},
  howpublished = {Industry annual report, Chainalysis Inc.},
  url          = {https://www.chainalysis.com/reports/},
  note         = {OAK v0.1 — proposed. Chainalysis's industry-analysis framing of the 2020 CeFi-yield-platform failure pattern; cites Cred among the pattern's documented cases.}
}

Discussion

Cred November 2020 is the canonical T11.010 anchor — the foundational worked example establishing the Off-chain Counterparty-Risk Insolvency Technique class in OAK. The case is documented under OAK-T11.010 with the honest framing that the failure mode is off-chain counterparty-credit-risk insolvency with on-chain components, not a primary on-chain exploit. The OAK-T11.010 Technique captures the structural pattern — custodial yield platform → concentrated re-lending to offshore counterparties → counterparty default → customer-facing solvency event → bankruptcy-claims recovery — that recurs at larger scale across Celsius, Voyager, BlockFi, Genesis, and FTX. See techniques/T11.010-off-chain-counterparty-risk-insolvency.md.

The contemporaneity with the November 2020 DeFi-attack wave is the load-bearing teaching point. Akropolis (2020-11-12), OUSD (2020-11-17), and Pickle (2020-11-21) were three on-chain T9.005 + T9.002 yield-aggregator-class incidents, and Cred (2020-11-07) was an off-chain custodial-fraud / counterparty-risk insolvency — all within a single November 2020 month. From a customer-asset-loss perspective, all four produced material losses to depositors / users; from a Technique-classification perspective, three are on-chain DeFi failures and one is an off-chain CeFi failure. The structural lesson is that crypto-asset-loss-pattern populations operate concurrently across DeFi and CeFi, with structurally different attack / failure surfaces but overlapping defender-relevant lessons. The "yield-without-counterparty-due-diligence" pattern Cred exemplifies is a CeFi-side analogue of the "yield-aggregator-without-reentrancy-discipline" pattern the November 2020 DeFi cluster exemplifies; both produce comparable customer-asset losses, both reflect insufficient operator-side risk controls, and both reappear at scale in subsequent years (the 2022 CeFi-yield-platform collapse wave; the 2021 cross-chain-bridge collapse wave).

The judicial-record attribution tier deserves explicit framing. Cred is one of the relatively few worked examples in the OAK corpus whose failure has been adjudicated through (a) a US Bankruptcy Court (Case No. 20-12836), (b) civil litigation against named former officers, and (c) a separate criminal indictment against a named individual former officer. This produces an attribution-strength tier substantially above the pseudonymous-attacker baseline for most DeFi-attack worked examples, and the corresponding citation discipline — citing court filings as canonical primary sources rather than press-summarised accounts — is the discipline contributors writing other judicially-adjudicated cases (Mt. Gox, FTX, Bitfinex 2016 with the 2023 Lichtenstein / Morgan pleas) should follow.

A final framing note. Cred's headline figure — ~$140M+ — is materially smaller than the 2022 CeFi-yield-platform collapses (Celsius ~$1.2B+, FTX ~$8B+, Voyager ~$1B+, BlockFi ~$1B+, Genesis ~$2B+ in subsequent disclosed customer-asset shortfalls). The case's value to the OAK corpus is as the foundational worked example for the counterparty-risk pattern, not as the largest case. Worked examples should not optimise the choice of foundational-case status purely on dollar magnitude; the structural-anchor role — earliest cleanly-documented case of a recurring failure pattern, with judicial-record attribution and concurrency with the on-chain-attack cluster of the same month — is independently valuable to OAK's defender-side teaching mission. Contributors writing the larger 2022 CeFi-collapse cases should reference Cred as the historical anchor, not as a small-dollar-figure precursor that can be elided.

Techniques demonstrated (2)