From the article:
C.R.E.A.M. was targeted by what is known as a flash loan attack. Flash loans are uncollateralized cryptocurrency loans structured so that they must be paid back instantly using smart contracts, making them attractive for things like arbitrage across exchanges. If the loan isn’t paid back, then it never happens, because both occur in the same transaction.
Analysts on social media who pored over the details of the attack suggested that the hacker exploited C.R.E.A.M. in an incredibly complex transaction for a flash loan that ultimately allowed the hacker to drain C.R.E.A.M.’s Ethereum-based lending pools, leading to a gain of around $130 million in different tokens. The attack cost the hacker roughly 9 ETH in network fees, or around $36,000.