T
iTokenly

Cork Protocol hack — May 2025

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedMay 28, 2025
Target typeOther
Loss$12,000,000Published estimates range $12,000,000 to $14,500,000Price at time of incident
MethodAccess control flawMalicious Uniswap v4 hook spoofed callback data to bypass authorization in Cork's hook and FlashSwapRouter, combined with manipulation of the rollover risk-premium formula just before market expiry
ChainsEthereum
Audited beforehandSherlock, Quantstamp, Runtime Verification, Cantina (per Cork's post-mortem)
OutcomeUnresolved

What happened

Cork Protocol, an Ethereum protocol selling Depeg Swaps — hedges against liquid staking tokens losing their peg — was drained of 3,761 wstETH from its wstETH:weETH liquidity vault on 28 May 2025. Cork's own post-mortem times the first attack transaction at 11:39 UTC and values the loss at about $14.5 million. CoinDesk, citing monitoring firm Cyvers, reported roughly $12 million the same day, and that lower figure is the one most widely repeated. The stolen wstETH was swapped to ETH through the 1inch aggregator and held at a single attacker address.

Cork's post-mortem describes two chained flaws. First, the rollover pricing mechanism used a risk-premium calculation whose time-to-expiry term approaches zero. By buying 2.5 Depeg Swaps 19 minutes before a market expired, the attacker drove the computed risk premium to roughly 1,779.7 quadrillion per cent, skewing the historical implied-yield average so that the successor market initialised with Cover Tokens priced at 0.000002 wstETH each instead of fair value. Second, Cork's hook was built on a 30 January 2025 snapshot of Uniswap v4 periphery code that predated an explicit caller-authorization check added upstream on 6 February 2025. The attacker deployed a malicious hook contract that spoofed callback data, bypassing access control in Cork's hook and extracting 3,761 Depeg Swaps held in the FlashSwapRouter reserve, which were then redeemed for the underlying asset.

Cork had been reviewed by Sherlock, Quantstamp, Runtime Verification and Cantina, and parts of the system were formally verified; rekt.news reported that at least three of the four firms had the vulnerable CorkHook contract outside their defined scope. Cork paused all contracts within 57 minutes, said about $20 million remained locked across unaffected vaults, and engaged recovery partners. As of the post-mortem the stolen ETH was still unspent at the attacker's address, and no recovery has been reported.

Law enforcement

Cork Protocol said it was working with US law enforcement to pursue the exploiter; no charges reported.

On-chain references

Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.

Attacker addresses

  • 0xea6f30e360192bae715599e15e2f765b49e4da98

Sources

  1. Cork ProtocolPrimary · retrieved 2026-08-01
  2. Cork ProtocolPrimary · retrieved 2026-08-01
  3. CoinDeskSecondary · retrieved 2026-08-01

Official post-mortem: https://www.cork.tech/blog/post-mortem

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Cork Protocol hack — May 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/cork-protocol
https://itokenly.com/hacks/cork-protocol

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.