logo

Cork Protocol Incident Analysis

ID: 9ff5b7f7-95c6-5011-9b43-e70e6c6563c3

STIX ID: report--9ff5b7f7-95c6-5011-9b43-e70e6c6563c3

Feed Name: CertiK Blog

Threat Score
80/100

Date Published: 2025-05-29

Date Updated: 2026-06-11

...
...

On May 28, 2025 Cork Protocol suffered a ~$12M loss when an attacker exploited missing parameter checks and the lack of access controls on a Uniswap v4 hook extension (CorkHook) to create a fake market, double-count derivative tokens (weETH8DS-2 / weETH8CT-2 / wstETH derivatives), mint extra tokens and redeem them for 3,761 wstETH. The report provides a detailed step-by-step attack flow, affected contract IDs and addresses, key transactions, and how crafted hook calldata and a malicious exchange rate provider enabled unauthorized minting and fund extraction.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.