Cork Protocol (2025) — Crypto Hack
Funds UnmovedFake market creation and double-counting exploit drained 3,761 wstETH from vaults
Summary
Fake market creation and double-counting exploit drained 3,761 wstETH from vaults
How It Was Compromised — Smart Contract Exploit via Malicious contract interaction against vaults. Attacker exploited lack of parameter checks to set up a fake market, and the open access of CorkHook to induce double counting of derivative tokens, acquiring a large amount of derivatives which they redeemed for 3,761 wstETH.
On May 28, 2025, Cork Protocol suffered a ~$12M security breach. The attacker exploited two issues: first, Cork allowed users to create markets with arbitrary redemption assets, enabling the attacker to set DS as the RA. Second, any user could call CorkHook's beforeSwap function without authorization and pass custom hook data. The attacker purchased weETH8CT-2 tokens in a legitimate market, set up a fake market with weETH8DS-2 as RA, then used malicious hook data to trick CorkCall into executing arbitrary logic. This allowed them to transfer DS liquidity from the legitimate market into the fake market as RA and redeem it, effectively draining 3,761 wstETH from the original market.
Fund Flow & Laundering Analysis
The attacker converted the stolen 3,761 wstETH into 4,527 ETH through eight transactions. The initial funding came from a 4.861 ETH deposit from Swapuz.com. As of the report, 4,530.5955 ETH remained in the attacker's address. The funds have not been moved through mixers and remain consolidated in a single attacker wallet, making recovery possible if law enforcement acts.