{"investigation":{"slug":"clober-liquidity-vault","entity_name":"Clober Liquidity Vault","trust_score":52,"severity_base":null,"score_modifier":16,"confidence":0.75,"status":"published","content_type":"investigation","summary":"Clober Liquidity Vault is an automated market-making product built on top of CloberDEX, a fully on-chain central limit order book (CLOB) DEX deployed on Coinbase's Base network. On December 10, 2024, the Liquidity Vault suffered a reentrancy exploit that drained approximately 133.7 ETH (~$501,000) from the newly launched vault — one day after it received its first liquidity injection. The core CloberDEX protocol was unaffected, and the team offered a 20% white-hat bounty, which the attacker declined; funds were not recovered.","sections":[{"content":"Clober is a fully on-chain central limit order book (CLOB) DEX infrastructure built for the Ethereum ecosystem, operating primarily on Coinbase's Base Layer 2 network. It is powered by the LOBSTER algorithm (Limit Order Book with Segment Tree for Efficient oRder-matching), which enables on-chain order matching and settlement without relying on off-chain components. The Clober Liquidity Vault (also referred to as the Rebalancer) is an automated liquidity management product layered on top of CloberDEX. It accepts user funds and deploys them as limit orders (bids and asks) on the Clober orderbook, aiming to generate yield through market-making activity rather than the AMM model. According to DefiLlama, the Clober Liquidity Vault product had accumulated modest TVL prior to its December 2024 exploit. The broader Clober V2 protocol continued to operate after the incident. As of early 2025, Clober had expanded to Starknet and was also active on the Monad testnet ecosystem.","heading":"Protocol Overview","sources":[{"url":"https://docs.clober.io/concepts/introduction","name":"Clober Documentation — Introduction","type":"official","credibility":2},{"url":"https://defillama.com/protocol/clober-liquidity-vault","name":"Clober Liquidity Vault — DefiLlama","type":"research","credibility":2},{"url":"https://defillama.com/protocol/clober-v2","name":"Clober V2 TVL, Fees, Revenue & Volume — DefiLlama","type":"research","credibility":2}],"severity":"low"},{"content":"On December 10, 2024, the Clober Liquidity Vault on Base was exploited by an external attacker, resulting in the confirmed loss of approximately 133.7 ETH (roughly $501,000 at time of exploit). The vulnerability resided in the _burn() function of the Rebalancer contract. The contract violated the checks-effects-interactions pattern by invoking an external callback (pool.strategy.burnHook) before updating internal reserve variables (pool.reserveA and pool.reserveB). The open() function also accepted arbitrary, unvalidated strategy contract addresses, allowing the attacker to supply a malicious strategy contract of their own design. The attacker deployed a custom malicious token and paired it with WETH in a Clober pool, using their attack contract as the pool strategy. They then obtained a 267.4 ETH flash loan from Morpho Blue and called burn(). During execution, the malicious burnHook reentered the _burn function before state variables were updated, causing the contract to compute withdrawal amounts against stale reserve values and effectively double-paying the attacker. The total stolen funds were 133.7 ETH, withdrawn twice (approximately 66.85 ETH per reentrant call). The attacker funded the initial transaction with only 2.87 ETH sourced from Binance. Post-exploit, the stolen ETH was bridged from Base to Ethereum mainnet via the Across Protocol and distributed to two newly created addresses: 0x711C87A0767101Fa6f3893FACb670B5689621e23 and 0x7760d838192f6E526721a0f6b160627baE989a3e. The on-chain attacker wallet address on Base is 0x012Fc6377F1c5CCF6e29967Bce52e3629AaA6025. The exploit occurred approximately one day after the vault received its first liquidity injection (December 9, 2024), and about one week after the vault's initial launch. The core CloberDEX protocol was not affected by this incident.","heading":"December 2024 Reentrancy Exploit","sources":[{"url":"https://rekt.news/cloberdex-rekt","name":"Rekt News — Clober Dex","type":"news_article","credibility":2},{"url":"https://www.certik.com/blog/clober-dex-incident-analysis","name":"CertiK — Clober Dex Incident Analysis","type":"research","credibility":2},{"url":"https://blog.solidityscan.com/cloberdex-liquidity-vault-hack-analysis-f22eb960aa6f/","name":"SolidityScan — CloberDEX Liquidity Vault Hack Analysis","type":"research","credibility":2},{"url":"https://www.quillaudits.com/blog/hack-analysis/cloberdex-reentrancy-exploit-501k","name":"QuillAudits — Breaking Down CloberDEX's Costly $501K Exploit","type":"research","credibility":2},{"url":"https://www.cryptopolitan.com/clober-vault-exploited-team-offers-bounty/","name":"Cryptopolitan — Clober liquidity vault exploited for 133 ETH","type":"news_article","credibility":2},{"url":"https://www.web3isgoinggreat.com/single/clober-dex-hack","name":"Web3 Is Going Great — Clober Gets Clobbered","type":"news_article","credibility":2},{"url":"https://basescan.org/address/0x012fc6377f1c5ccf6e29967bce52e3629aaa6025","name":"Clober Liquidity Vault Exploiter — BaseScan","type":"on_chain","credibility":1},{"url":"https://x.com/peckshield/status/1866443215186088048","name":"PeckShield on X — Reentrancy confirmation","type":"social_media","credibility":3}],"severity":"high"},{"content":"The core CloberDEX contracts received a security audit from Spearbit in January–February 2023, covering the period January 2 to January 13, 2023. The Spearbit engagement identified 4 critical, 5 high, 5 medium, and 8 low risk findings, all of which were reported as fixed. The Liquidity Vault component was separately audited by Trust Security and by Kupia Security. Kupia Security completed their audit of the vault just two days before the December 10, 2024 exploit occurred. Multiple post-incident analyses from security researchers including CertiK, QuillAudits, and Web3 Is Going Great concluded that the reentrancy vulnerability that enabled the exploit was a post-audit code addition — meaning the vulnerable code was not present in the version reviewed by auditors. Trust Security publicly stated that a post-audit code change introducing the reentrancy vulnerability was audited by another firm. Kupia Security acknowledged they had flagged concerns about the risk of malicious strategy contracts; Clober disputed that this finding was directly related to the reentrancy attack vector that was ultimately exploited. The incident illustrates how protocol modifications made after an audit engagement can invalidate prior security assurances if the changes are not themselves subject to a new review.","heading":"Audit History and Post-Audit Code Changes","sources":[{"url":"https://cantina.xyz/portfolio/0b817edc-926e-4c77-ae4c-80a6e93b094a","name":"Cantina — Clober DEX audit portfolio (Spearbit)","type":"research","credibility":2},{"url":"https://rekt.news/cloberdex-rekt","name":"Rekt News — Clober Dex","type":"news_article","credibility":2},{"url":"https://www.quillaudits.com/blog/hack-analysis/cloberdex-reentrancy-exploit-501k","name":"QuillAudits — Breaking Down CloberDEX's Costly $501K Exploit","type":"research","credibility":2},{"url":"https://www.web3isgoinggreat.com/single/clober-dex-hack","name":"Web3 Is Going Great — Clober Gets Clobbered","type":"news_article","credibility":2}],"severity":"medium"},{"content":"Following the exploit, the Clober team publicly acknowledged the breach via their official X account (@CloberDEX) and confirmed that the core protocol remained fully operational. The team offered the attacker a 20% white-hat bounty (approximately $100,200 at the time) and committed to non-prosecution in exchange for return of the remaining funds. The team also engaged Match Systems, a blockchain forensics firm, to pursue recovery. The attacker did not respond to the bounty offer and retained the stolen ETH. As of available reporting through early 2025, the funds had not been recovered. There are no reports of user compensation, restitution, or a community fund used to cover the losses to liquidity providers. No regulatory filings or law enforcement actions have been publicly reported in connection with this incident.","heading":"Team Response and Fund Recovery","sources":[{"url":"https://www.cryptopolitan.com/clober-vault-exploited-team-offers-bounty/","name":"Cryptopolitan — Clober liquidity vault exploited for 133 ETH","type":"news_article","credibility":2},{"url":"https://www.mitrade.com/insights/news/live-news/article-3-515047-20241211","name":"Mitrade — Clober liquidity vault exploited, team offers bounty","type":"news_article","credibility":2},{"url":"https://nominis.io/post/crypto-security-incidents-december-2024","name":"Nominis — Crypto Security Incidents December 2024","type":"research","credibility":2}],"severity":"medium"},{"content":"The wallet address identified as the Clober exploiter (0x012Fc6377F1c5CCF6e29967Bce52e3629AaA6025) was also linked by CertiK's incident analysis to a prior exploit of ZeroLend's MAHA Lending Pool on December 4, 2024, which resulted in approximately $77,000 in losses. This suggests the attacker was a repeat exploiter targeting DeFi protocols in the same timeframe rather than an actor with any connection to the Clober team. The Clober team is considered a victim of an external exploit in both incidents documented above.","heading":"Attacker Profile and Cross-Protocol Activity","sources":[{"url":"https://www.certik.com/blog/clober-dex-incident-analysis","name":"CertiK — Clober Dex Incident Analysis","type":"research","credibility":2},{"url":"https://basescan.org/address/0x012fc6377f1c5ccf6e29967bce52e3629aaa6025","name":"Clober Liquidity Vault Exploiter — BaseScan","type":"on_chain","credibility":1}],"severity":"medium"},{"content":"As of publicly available data through early 2026, the core CloberDEX V2 protocol remains operational on Base and has expanded to additional networks including Starknet. The Clober Liquidity Vault product had resumed accumulating TVL post-exploit, though at a modest level. No fraud allegations, regulatory actions, or SEC/CFTC proceedings have been identified against Clober or its team. The team members are not publicly named in available sources, and no governance token or ICO has been identified in connection with this protocol.","heading":"Ongoing Protocol Status","sources":[{"url":"https://defillama.com/protocol/clober-v2","name":"Clober V2 TVL, Fees, Revenue & Volume — DefiLlama","type":"research","credibility":2},{"url":"https://defillama.com/protocol/clober","name":"Clober TVL, Fees, Revenue & Volume — DefiLlama","type":"research","credibility":2}],"severity":"low"}],"timeline":[{"date":"2023-01-02","event":"Spearbit begins security audit of Clober DEX core contracts; engagement runs through January 13, 2023. All critical and high findings reported as fixed.","source":"Cantina / Spearbit audit portfolio","source_url":"https://cantina.xyz/portfolio/0b817edc-926e-4c77-ae4c-80a6e93b094a"},{"date":"2024-12-04","event":"Wallet address 0x012Fc637... exploits ZeroLend's MAHA Lending Pool for approximately $77,000 — six days before the Clober exploit.","source":"CertiK — Clober Dex Incident Analysis","source_url":"https://www.certik.com/blog/clober-dex-incident-analysis"},{"date":"2024-12-08","event":"Kupia Security completes audit of the Clober Liquidity Vault contracts, two days before the exploit.","source":"Rekt News — Clober Dex","source_url":"https://rekt.news/cloberdex-rekt"},{"date":"2024-12-09","event":"Clober Liquidity Vault receives its first liquidity injection from users.","source":"Cryptopolitan — Clober liquidity vault exploited for 133 ETH","source_url":"https://www.cryptopolitan.com/clober-vault-exploited-team-offers-bounty/"},{"date":"2024-12-10","event":"Attacker exploits reentrancy vulnerability in the Rebalancer contract's _burn() function, draining 133.7 ETH (~$501,000) from the Clober Liquidity Vault using a 267.4 ETH Morpho Blue flash loan and a malicious strategy contract. Stolen funds bridged to Ethereum via Across Protocol.","source":"CertiK — Clober Dex Incident Analysis","source_url":"https://www.certik.com/blog/clober-dex-incident-analysis"},{"date":"2024-12-11","event":"Clober team publicly acknowledges the exploit via X, confirms core protocol is unaffected, and offers attacker a 20% white-hat bounty (~$100,200) with non-prosecution commitment. Team engages Match Systems for fund recovery efforts.","source":"Cryptopolitan — Clober liquidity vault exploited for 133 ETH","source_url":"https://www.cryptopolitan.com/clober-vault-exploited-team-offers-bounty/"},{"date":"2024-12-11","event":"Attacker declines bounty offer and retains stolen ETH. Funds not recovered.","source":"Nominis — Crypto Security Incidents December 2024","source_url":"https://nominis.io/post/crypto-security-incidents-december-2024"}],"sources_used":[{"url":"https://rekt.news/cloberdex-rekt","name":"Rekt News — Clober Dex","type":"news_article","archive_url":"http://web.archive.org/web/20260310091516/https://rekt.news/cloberdex-rekt","credibility":2,"archive_timestamp":"2026-03-10T09:15:16+00:00"},{"url":"https://www.certik.com/blog/clober-dex-incident-analysis","name":"CertiK — Clober Dex Incident Analysis","type":"research","archive_url":"http://web.archive.org/web/20260601210639/https://www.certik.com/blog/clober-dex-incident-analysis","credibility":2,"archive_timestamp":"2026-06-01T21:06:39+00:00"},{"url":"https://blog.solidityscan.com/cloberdex-liquidity-vault-hack-analysis-f22eb960aa6f/","name":"SolidityScan — CloberDEX Liquidity Vault Hack Analysis","type":"research","archive_url":"https://web.archive.org/web/20260819125255/https://blog.solidityscan.com/cloberdex-liquidity-vault-hack-analysis-f22eb960aa6f/","credibility":2,"archive_timestamp":"2026-08-19T12:52:55+00:00"},{"url":"https://www.quillaudits.com/blog/hack-analysis/cloberdex-reentrancy-exploit-501k","name":"QuillAudits — Breaking Down CloberDEX's Costly $501K Exploit","type":"research","archive_url":"http://web.archive.org/web/20260417064413/https://www.quillaudits.com/blog/hack-analysis/cloberdex-reentrancy-exploit-501k","credibility":2,"archive_timestamp":"2026-04-17T06:44:13+00:00"},{"url":"https://www.cryptopolitan.com/clober-vault-exploited-team-offers-bounty/","name":"Cryptopolitan — Clober liquidity vault exploited for 133 ETH","type":"news_article","archive_url":"https://web.archive.org/web/20260819194912/https://www.cryptopolitan.com/clober-vault-exploited-team-offers-bounty/","credibility":2,"archive_timestamp":"2026-08-19T19:49:12+00:00"},{"url":"https://www.web3isgoinggreat.com/single/clober-dex-hack","name":"Web3 Is Going Great — Clober Gets Clobbered","type":"news_article","archive_url":"https://web.archive.org/web/20260819195220/https://www.web3isgoinggreat.com/single/clober-dex-hack","credibility":2,"archive_timestamp":"2026-08-19T19:52:20+00:00"},{"url":"https://basescan.org/address/0x012fc6377f1c5ccf6e29967bce52e3629aaa6025","name":"Clober Liquidity Vault Exploiter — BaseScan","type":"on_chain","archive_url":"http://web.archive.org/web/20251007142402/https://basescan.org/address/0x012fc6377f1c5ccf6e29967bce52e3629aaa6025","credibility":1,"archive_timestamp":"2025-10-07T14:24:02+00:00"},{"url":"https://www.mitrade.com/insights/news/live-news/article-3-515047-20241211","name":"Mitrade — Clober liquidity vault exploited, team offers bounty","type":"news_article","archive_url":"https://web.archive.org/web/20260819194936/https://www.mitrade.com/insights/news/live-news/article-3-515047-20241211","credibility":2,"archive_timestamp":"2026-08-19T19:49:36+00:00"},{"url":"https://nominis.io/post/crypto-security-incidents-december-2024","name":"Nominis — Crypto Security Incidents December 2024","type":"research","archive_url":"https://web.archive.org/web/20260819150925/https://www.nominis.io/insights/crypto-security-incidents-december-2024","credibility":2,"archive_timestamp":"2026-08-19T15:09:25+00:00"},{"url":"https://cantina.xyz/portfolio/0b817edc-926e-4c77-ae4c-80a6e93b094a","name":"Cantina — Clober DEX audit portfolio (Spearbit)","type":"research","archive_url":"http://web.archive.org/web/20260215050922/https://cantina.xyz/portfolio/0b817edc-926e-4c77-ae4c-80a6e93b094a","credibility":2,"archive_timestamp":"2026-02-15T05:09:22+00:00"},{"url":"https://defillama.com/protocol/clober-liquidity-vault","name":"Clober Liquidity Vault — DefiLlama","type":"research","archive_url":"http://web.archive.org/web/20250913234346/https://defillama.com/protocol/clober-liquidity-vault","credibility":2,"archive_timestamp":"2025-09-13T23:43:46+00:00"},{"url":"https://defillama.com/protocol/clober-v2","name":"Clober V2 TVL, Fees, Revenue & Volume — DefiLlama","type":"research","archive_url":"http://web.archive.org/web/20250907090906/https://defillama.com/protocol/clober-v2","credibility":2,"archive_timestamp":"2025-09-07T09:09:06+00:00"},{"url":"https://docs.clober.io/developers/rebalancer-integration-guide/liquidity-vault","name":"Clober Documentation — Liquidity Vault Integration Guide","type":"official","archive_url":"http://web.archive.org/web/20260519161114/https://docs.clober.io/developers/rebalancer-integration-guide/liquidity-vault","credibility":2,"archive_timestamp":"2026-05-19T16:11:14+00:00"},{"url":"https://x.com/peckshield/status/1866443215186088048","name":"PeckShield on X — Reentrancy confirmation","type":"social_media","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://github.com/clober-dex/clober-liquidity-vault","name":"Clober GitHub — clober-liquidity-vault repository","type":"official","archive_url":"https://web.archive.org/web/20260819172852/https://github.com/clober-dex/clober-liquidity-vault","credibility":2,"archive_timestamp":"2026-08-19T17:28:52+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":true,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:27.01183+00:00","updated_at":"2026-08-25T07:43:04.209+00:00"}}