{"investigation":{"slug":"clipper","entity_name":"Clipper","trust_score":33,"severity_base":null,"score_modifier":-15,"confidence":0.78,"status":"under_investigation","content_type":"investigation","summary":"Clipper is a decentralized exchange (DEX) built by Shipyard Software and governed by AdmiralDAO, designed to offer retail traders the lowest per-transaction costs on trades under $10,000 using a novel Formula Market Maker (FMM) mechanism. On December 1, 2024, a protocol logic exploit drained approximately $457,878 from its Optimism and Base liquidity pools by manipulating a single-asset deposit and withdrawal function; the attacker voluntarily returned 104 ETH in January 2025. While the protocol has legitimate venture backing and a documented technical architecture, the exploit revealed a gap between audited and deployed code, and the protocol has been flagged by on-chain investigator ZachXBT.","sections":[{"content":"Clipper is a decentralized exchange created by Shipyard Software Inc. and subsequently licensed to AdmiralDAO, a non-profit member-managed DAO LLC incorporated in the Marshall Islands. The protocol is specifically designed for retail traders executing trades below $10,000, optimizing for low slippage and gas costs rather than maximum liquidity depth. Clipper uses a proprietary automated market maker model called the Formula Market Maker (FMM), which differs from the Constant Product Market Maker (CPMM) used by protocols such as Uniswap. The FMM caps pool liquidity at a maximum of $20 million, arguing that excess liquidity beyond this threshold does not benefit small-trade execution. Price computation is performed off-chain and verified on-chain to reduce gas consumption. The protocol is live on Ethereum, Polygon, Optimism, Arbitrum, Base, and Mantle Network. Its governance token is SAIL, which grants holders voting rights within AdmiralDAO.","heading":"Protocol Overview and Design","sources":[{"url":"https://blog.clipper.exchange/what-is-clipper/","name":"blog.clipper.exchange","type":"other","credibility":3},{"url":"https://iq.wiki/wiki/clipper-dex","name":"iq.wiki","type":"other","credibility":3},{"url":"https://docs.clipper.exchange/","name":"docs.clipper.exchange","type":"other","credibility":3}],"severity":"medium"},{"content":"Clipper was founded by Mark Lurie (CEO), Zhen Liu, and Tiantian Kullander through Shipyard Software Inc. Mark Lurie and Abe Othman, Clipper's lead economist, are Harvard graduates with backgrounds in venture capital and prior startup exits. Abe Othman's PhD research on automated market making is cited in Uniswap's technical whitepapers. In January 2023, Shipyard Software raised $21 million in combined equity and liquidity commitments. The equity component of approximately $4 million was led by Polychain Capital, with participation from 0x Labs, 1inch, the DeFi Alliance, Quantstamp, MetaCartel DAO, FJLabs, Naval Ravikant, and Robert Leshner. An additional $17 million in liquidity pledges came from Polychain, Nascent, Three Arrows Capital (prior to its collapse), Electric Capital, LD Capital, and IOSG. The involvement of Three Arrows Capital as an early liquidity pledger is noted as a historical risk factor, given that firm's subsequent insolvency in 2022. Governance of the deployed protocol resides with AdmiralDAO, with the initial multisig including Shipyard Software and Polychain Capital.","heading":"Founding Team and Investors","sources":[{"url":"https://www.theblock.co/linked/111163/dex-developer-shipyard-software-raises-21-million-for-its-first-exchange-clipper","name":"theblock.co","type":"other","credibility":3},{"url":"https://www.banklesstimes.com/news/2023/01/31/shipyard-software-raises-21m-for-clipper-decentralized-exchange-ravikant-among-backers/","name":"banklesstimes.com","type":"other","credibility":3},{"url":"https://www.linkedin.com/pulse/clipper-dex-people-paul-veradittakit","name":"linkedin.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On December 1, 2024, beginning at approximately 04:00 UTC, an attacker exploited a vulnerability in Clipper's single-asset deposit and withdrawal function, draining approximately $457,878 from the protocol's Optimism and Base liquidity pools. This represented roughly 6% of Clipper's total value locked at the time. The exploit mechanism involved the attacker bundling a swap and a withdrawal into a single atomic transaction. By sending additional ETH alongside a swap input, the attacker inflated the pool token valuation, then requested withdrawal signatures for an amount of pool tokens reflecting the manipulated state. When the deposit and withdrawal were executed atomically, the attacker withdrew more assets than they had deposited. The Optimism pool was identified as particularly vulnerable due to a pool invariant value (k) five times lower than any other deployed chain, combined with the low transaction costs characteristic of Layer 2 networks. A secondary contributing factor was a recent database upgrade that introduced an unexpected interaction with Clipper's off-chain circuit-breaker safeguard, which had not been identified during testing. Immediately following the attack, AdmiralDAO activated emergency response procedures: swaps and deposits were suspended across all chains, and single-asset withdrawals were disabled. Users retained the ability to withdraw proportional mixes of pool assets. The Optimism and Base pools were the only ones affected; Ethereum, Polygon, Arbitrum, and Mantle pools were not compromised. Chaofan Shou of security firm Fuzzland publicly alleged at the time that the incident stemmed from a private key leak, enabling the attacker to sign fraudulent deposit and withdrawal requests. Clipper explicitly rejected this characterization, stating that its security architecture was designed to prevent such vulnerabilities and that the root cause was the withdrawal function logic, not key compromise. AdmiralDAO subsequently engaged ZeroShadow, an on-chain incident response firm, to trace and attempt to recover the stolen funds.","heading":"December 2024 Protocol Exploit","sources":[{"url":"https://cryptonews.com/news/clipper-dex-says-withdrawal-vulnerability-led-to-450k-hack-denies-private-key-leak/","name":"cryptonews.com","type":"other","credibility":3},{"url":"https://crypto.news/clipper-dex-liquidity-pools-exploited-for-450000/","name":"crypto.news","type":"other","credibility":3},{"url":"https://thecyberexpress.com/clipper-cyberattack/","name":"thecyberexpress.com","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/?id=clipper-dex-hack","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Clipper_Exchange_Asset_Deposit/Withdrawal_Manipulation","name":"quadrigainitiative.com","type":"other","credibility":3}],"severity":"medium"},{"content":"In January 2025, the individual responsible for the December 2024 exploit voluntarily returned 104 ETH to the Clipper treasury, citing personal health issues as the cause of a delay in doing so. The attacker stated they wished to return the entire amount extracted and indicated, to their knowledge, no further vulnerabilities remained in the contracts. Following receipt of the returned funds, AdmiralDAO began planning the most equitable method for distributing refunds to affected liquidity providers. The recovery of the majority of stolen funds is an unusual outcome in DeFi exploits and reflects a pattern seen in cases where the attacker appears to have treated the incident as a white-hat or grey-hat action. Clipper's team stated that the compensation plan specifics would depend on the final amount recovered. No law enforcement action or regulatory filing related to the exploit has been identified in available public records as of the time of this investigation.","heading":"Attacker Fund Return and Recovery","sources":[{"url":"https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Clipper_Exchange_Asset_Deposit/Withdrawal_Manipulation","name":"quadrigainitiative.com","type":"other","credibility":3},{"url":"https://www.bitcoinsensus.com/news/clipper-dex-seeks-negotiation-with-hacker-after-450000-exploit/","name":"bitcoinsensus.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Prior to its public launch, Clipper's codebase was audited by Quantstamp and Solidified, two established smart contract security firms. A bug bounty program was also conducted in partnership with Immunefi, offering up to $100,000 for critical vulnerability disclosures. At alpha launch, the protocol was prefunded with $1 million in liquidity positioned as a potential honeypot to attract and surface exploits in a controlled environment. The audits did not identify major flaws, though findings led to several architectural changes. Notably, Clipper's documentation acknowledged at launch that the deployed code differed from the audited code due to subsequent developer feedback received during the bug bounty period, and that updated audit reports were pending. This gap between audited and deployed code is a recognized risk factor in smart contract security. The December 2024 exploit specifically targeted logic within the single-asset withdrawal function — protections that had been applied to swap transactions were not extended to the combined deposit/withdrawal path. Post-exploit, Clipper committed to implementing on-chain pool invariant validations during single-asset withdrawals, integrating external price oracles, extending the circuit-breaker system to halt deposits and withdrawals on abnormal pool behavior, and improving API-layer behavioral monitoring to detect bot-like exploitation patterns.","heading":"Security Audit History and Architecture Gaps","sources":[{"url":"https://blog.clipper.exchange/after-rigorous-security-testing-clipper-dex-is-set-to-sail/","name":"blog.clipper.exchange","type":"other","credibility":3},{"url":"https://medium.com/@clipper_dex/after-rigorous-security-testing-clipper-dex-is-set-to-sail-b21e6be46c43","name":"medium.com","type":"other","credibility":3},{"url":"https://docs.clipper.exchange/audits","name":"docs.clipper.exchange","type":"other","credibility":3},{"url":"https://thecyberexpress.com/clipper-cyberattack/","name":"thecyberexpress.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On-chain investigator ZachXBT has flagged Clipper as a protocol of concern. The specific nature, timing, and evidence basis of ZachXBT's flag has not been independently confirmed in available public records at the time of this investigation; no detailed public report from ZachXBT specifically addressing Clipper DEX has been identified in available sources. The flag is treated here as an alert signal warranting elevated scrutiny rather than as independently verified evidence of wrongdoing. ZachXBT has a documented track record of identifying DEX protocols used to facilitate illicit fund flows — in a separate but structurally similar case, ZachXBT alleged that Tokenlon, another small DEX, processed millions of dollars in funds connected to romance scams, human trafficking, and investment fraud, with an alleged 57-60% of Tokenlon's 2022-2023 swap volume involving addresses linked to scam networks. Whether analogous on-chain flow concerns apply to Clipper has not been established in available public sources. The December 2024 exploit generated significant community and media attention and may have contributed to heightened investigator scrutiny of the platform.","heading":"ZachXBT Flag and Community Signals","sources":[{"url":"https://cryptopotato.com/zachxbt-targets-lesser-known-dex-in-fresh-allegations-over-illicit-crypto-flows/","name":"cryptopotato.com","type":"other","credibility":3},{"url":"https://www.banklesstimes.com/articles/2026/05/04/zachxbt-alleges-tokenlon-processed-millions-in-suspected-illicit-crypto-funds/","name":"banklesstimes.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Clipper's governance is administered by AdmiralDAO, a Marshall Islands non-profit member-managed DAO LLC. At launch, protocol governance was controlled by a multisig including Shipyard Software and Polychain Capital, with decentralized token holder participation through the SAIL governance token. The Marshall Islands DAO LLC structure is a relatively novel legal wrapper with limited regulatory precedent and unclear liability characteristics in the event of user loss or legal action. The off-chain component of Clipper's architecture — where price computation occurs off-chain before on-chain verification — introduces an element of centralized dependency in the signing and API layer. This off-chain API dependency was directly implicated in the December 2024 exploit, as the attacker used the API to obtain withdrawal signatures for a manipulated pool state. Critics of hybrid on-chain/off-chain AMM designs note that such architectures create attack surfaces not present in fully on-chain AMMs, though they offer gas efficiency advantages. Shipyard Software created and maintains the protocol software under license to AdmiralDAO, meaning ongoing development remains dependent on a centralized corporate entity.","heading":"Governance and Decentralization Considerations","sources":[{"url":"https://www.admiraldao.xyz/","name":"admiraldao.xyz","type":"other","credibility":3},{"url":"https://docs.clipper.exchange/governance-token/sail-supply-and-circulation","name":"docs.clipper.exchange","type":"other","credibility":3},{"url":"https://iq.wiki/wiki/clipper-dex","name":"iq.wiki","type":"other","credibility":3},{"url":"https://thecyberexpress.com/clipper-cyberattack/","name":"thecyberexpress.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021-06-30","event":"Clipper DEX launches on Ethereum mainnet, developed by Shipyard Software. Protocol is prefunded with $1 million in alpha liquidity.","source":""},{"date":"2021-07","event":"Within two weeks of launch, Clipper reports $14 million per week in trading volume across approximately 1,800 traders and 5,000 transactions.","source":"","date_original":"2021-07-01"},{"date":"2023-01-31","event":"Shipyard Software announces $21 million in combined equity and liquidity funding. Polychain Capital leads the equity round. Three Arrows Capital is among the liquidity pledgers (Three Arrows Capital had already collapsed in June 2022).","source":""},{"date":"2024-11-30","event":"Attacker begins exploit on Clipper's Base network pool at approximately 8:22 PM MST, followed by the Optimism pool at approximately 9:15 PM MST.","source":""},{"date":"2024-12","event":"Clipper publicly confirms the exploit. Total loss reported at approximately $457,878, affecting Optimism and Base pools and representing roughly 6% of TVL. Swaps and deposits are suspended across all chains. Single-asset withdrawals are disabled.","source":"","date_original":"2024-12-01"},{"date":"2024-12","event":"Chaofan Shou of security firm Fuzzland publicly alleges the incident resulted from a private key leak. Clipper explicitly denies this characterization, attributing the exploit to a withdrawal function logic vulnerability.","source":"","date_original":"2024-12-01"},{"date":"2024-12-04","event":"Clipper publishes official post-mortem detailing the exploit mechanism, root causes including the circuit-breaker database interaction, and remediation plans.","source":""},{"date":"2025-01-15","event":"The attacker voluntarily returns 104 ETH to the Clipper treasury, citing personal health issues for the delay and stating no further vulnerabilities are known to remain. AdmiralDAO begins planning LP refund distribution.","source":""}],"sources_used":[{"url":"https://blog.clipper.exchange/what-is-clipper/","name":"blog.clipper.exchange","type":"other","archive_url":"http://web.archive.org/web/20251111104715/https://blog.clipper.exchange/what-is-clipper/","credibility":3,"archive_timestamp":"2025-11-11T10:47:15+00:00"},{"url":"https://iq.wiki/wiki/clipper-dex","name":"iq.wiki","type":"other","archive_url":"http://web.archive.org/web/20260114045631/https://iq.wiki/wiki/clipper-dex","credibility":3,"archive_timestamp":"2026-01-14T04:56:31+00:00"},{"url":"https://docs.clipper.exchange/","name":"docs.clipper.exchange","type":"other","archive_url":"http://web.archive.org/web/20260607173505/https://docs.clipper.exchange/","credibility":3,"archive_timestamp":"2026-06-07T17:35:05+00:00"},{"url":"https://www.theblock.co/linked/111163/dex-developer-shipyard-software-raises-21-million-for-its-first-exchange-clipper","name":"theblock.co","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.banklesstimes.com/news/2023/01/31/shipyard-software-raises-21m-for-clipper-decentralized-exchange-ravikant-among-backers/","name":"banklesstimes.com","type":"other","archive_url":"http://web.archive.org/web/20260415194948/https://www.banklesstimes.com/news/2023/01/31/shipyard-software-raises-21m-for-clipper-decentralized-exchange-ravikant-among-backers/","credibility":3,"archive_timestamp":"2026-04-15T19:49:48+00:00"},{"url":"https://www.linkedin.com/pulse/clipper-dex-people-paul-veradittakit","name":"linkedin.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cryptonews.com/news/clipper-dex-says-withdrawal-vulnerability-led-to-450k-hack-denies-private-key-leak/","name":"cryptonews.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://crypto.news/clipper-dex-liquidity-pools-exploited-for-450000/","name":"crypto.news","type":"other","archive_url":"http://web.archive.org/web/20251017165232/https://crypto.news/clipper-dex-liquidity-pools-exploited-for-450000/","credibility":3,"archive_timestamp":"2025-10-17T16:52:32+00:00"},{"url":"https://thecyberexpress.com/clipper-cyberattack/","name":"thecyberexpress.com","type":"other","archive_url":"https://web.archive.org/web/20260829081934/https://thecyberexpress.com/clipper-cyberattack/","credibility":3,"archive_timestamp":"2026-08-29T08:19:34+00:00"},{"url":"https://www.web3isgoinggreat.com/?id=clipper-dex-hack","name":"web3isgoinggreat.com","type":"other","archive_url":"http://web.archive.org/web/20251215231833/https://www.web3isgoinggreat.com/?id=clipper-dex-hack","credibility":3,"archive_timestamp":"2025-12-15T23:18:33+00:00"},{"url":"https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Clipper_Exchange_Asset_Deposit/Withdrawal_Manipulation","name":"quadrigainitiative.com","type":"other","archive_url":"http://web.archive.org/web/20260208171228/https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Clipper_Exchange_Asset_Deposit/Withdrawal_Manipulation","credibility":3,"archive_timestamp":"2026-02-08T17:12:28+00:00"},{"url":"https://www.bitcoinsensus.com/news/clipper-dex-seeks-negotiation-with-hacker-after-450000-exploit/","name":"bitcoinsensus.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:gone","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://blog.clipper.exchange/after-rigorous-security-testing-clipper-dex-is-set-to-sail/","name":"blog.clipper.exchange","type":"other","archive_url":"http://web.archive.org/web/20251111113511/https://blog.clipper.exchange/after-rigorous-security-testing-clipper-dex-is-set-to-sail/","credibility":3,"archive_timestamp":"2025-11-11T11:35:11+00:00"},{"url":"https://medium.com/@clipper_dex/after-rigorous-security-testing-clipper-dex-is-set-to-sail-b21e6be46c43","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://docs.clipper.exchange/audits","name":"docs.clipper.exchange","type":"other","archive_url":"https://web.archive.org/web/20260829075517/https://docs.clipper.exchange/disclaimers-and-technical/audits","credibility":3,"archive_timestamp":"2026-08-29T07:55:17+00:00"},{"url":"https://cryptopotato.com/zachxbt-targets-lesser-known-dex-in-fresh-allegations-over-illicit-crypto-flows/","name":"cryptopotato.com","type":"other","archive_url":"http://web.archive.org/web/20260525183235/https://cryptopotato.com/zachxbt-targets-lesser-known-dex-in-fresh-allegations-over-illicit-crypto-flows/","credibility":3,"archive_timestamp":"2026-05-25T18:32:35+00:00"},{"url":"https://www.banklesstimes.com/articles/2026/05/04/zachxbt-alleges-tokenlon-processed-millions-in-suspected-illicit-crypto-funds/","name":"banklesstimes.com","type":"other","archive_url":"http://web.archive.org/web/20260515141019/https://www.banklesstimes.com/articles/2026/05/04/zachxbt-alleges-tokenlon-processed-millions-in-suspected-illicit-crypto-funds/","credibility":3,"archive_timestamp":"2026-05-15T14:10:19+00:00"},{"url":"https://www.admiraldao.xyz/","name":"admiraldao.xyz","type":"other","archive_url":"http://web.archive.org/web/20260317084246/https://www.admiraldao.xyz/","credibility":3,"archive_timestamp":"2026-03-17T08:42:46+00:00"},{"url":"https://docs.clipper.exchange/governance-token/sail-supply-and-circulation","name":"docs.clipper.exchange","type":"other","archive_url":"https://web.archive.org/web/20260829032024/https://docs.clipper.exchange/governance-token/sail-primer/sail-supply-and-circulation","credibility":3,"archive_timestamp":"2026-08-29T03:20:24+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:27.215336+00:00","updated_at":"2026-08-29T09:21:05.645945+00:00"}}