Cork Protocol Incident Analysis
ID: 9ff5b7f7-95c6-5011-9b43-e70e6c6563c3
STIX ID: report--9ff5b7f7-95c6-5011-9b43-e70e6c6563c3
Feed Name: CertiK Blog
On May 28, 2025 Cork Protocol suffered a ~$12M loss when an attacker exploited missing parameter checks and the lack of access controls on a Uniswap v4 hook extension (CorkHook) to create a fake market, double-count derivative tokens (weETH8DS-2 / weETH8CT-2 / wstETH derivatives), mint extra tokens and redeem them for 3,761 wstETH. The report provides a detailed step-by-step attack flow, affected contract IDs and addresses, key transactions, and how crafted hook calldata and a malicious exchange rate provider enabled unauthorized minting and fund extraction.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
