Cork V1 Hack
What happened
On 28 May 2025, Cork's wstETH:weETH Liquidity Vault lost 3,761 wstETH. The exploit combined manipulated rollover pricing with missing authorization in Cork's Uniswap v4 hook integration. Cork paused its contracts; its June 4 post-mortem reported approximately $20 million in unaffected vaults awaiting safe withdrawal.
Historical rollover pricing was vulnerable in thinly traded markets, while the hook integration failed to authenticate data reaching privileged swap logic. The two flaws together supplied both tokens required for redemption.
Case & protocol details
How it happened
- A low-volume trade before expiry skewed rollover pricing, allowing the attacker to acquire Cover Tokens unusually cheaply.
- A malicious hook manipulated Cork's
beforeSwappathway and bypassed authorization of hook data, extracting matching Depeg Swap tokens. - Combining Cover Tokens with Depeg Swaps allowed redemption of the vault's wstETH through the Peg Stability Module.
- The attacker exchanged the wstETH for ETH through 1inch.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
- report May 28 2025 Exploit Post-Mortem cork.tech
- analysis Website reference coindesk.com
- analysis Website reference cointelegraph.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.