Cork V1 Hack

REPORTED LOSS $12.0M
High Access control bypass via hook ethereum

What happened

On 28 May 2025, Cork's wstETH:weETH Liquidity Vault lost 3,761 wstETH. The exploit combined manipulated rollover pricing with missing authorization in Cork's Uniswap v4 hook integration. Cork paused its contracts; its June 4 post-mortem reported approximately $20 million in unaffected vaults awaiting safe withdrawal.

Technical Root Cause

Historical rollover pricing was vulnerable in thinly traded markets, while the hook integration failed to authenticate data reaching privileged swap logic. The two flaws together supplied both tokens required for redemption.

Case & protocol details

Classification Protocol Logic / Yield Aggregator / Access Control
Protocol Type Insurance
Implementation language Solidity
Official Website www.cork.tech/
Protocol Twitter/X @corkprotocol?lang=en

How it happened

  1. A low-volume trade before expiry skewed rollover pricing, allowing the attacker to acquire Cover Tokens unusually cheaply.
  2. A malicious hook manipulated Cork's beforeSwap pathway and bypassed authorization of hook data, extracting matching Depeg Swap tokens.
  3. Combining Cover Tokens with Depeg Swaps allowed redemption of the vault's wstETH through the Peg Stability Module.
  4. The attacker exchanged the wstETH for ETH through 1inch.

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.