{"investigation":{"slug":"cork-v1","entity_name":"Cork V1","trust_score":10,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"Cork V1 is a DeFi depeg protection protocol built on Ethereum that launched its public beta on March 4, 2025 and was exploited for approximately $12 million on May 28, 2025, less than three months after launch. The exploit resulted from a lack of input validation in the CorkHook smart contract and permissionless market creation logic, a vulnerability that slipped past four separate security audits from Quantstamp, Cantina, Sherlock, and Runtime Verification — three of which explicitly excluded the vulnerable contract from scope. All protocol functions were paused following the incident, stolen funds were laundered through Tornado Cash, and no user compensation plan has been publicly confirmed.","sections":[{"content":"Cork Protocol describes itself as a programmable risk layer for on-chain assets, enabling users to price, hedge, and trade the risk of depeg events for pegged assets such as liquid staking tokens, yield-bearing stablecoins, and RWA vault tokens. The core primitive is the Depeg Swap (DS), a tokenized instrument modeled after traditional credit default swaps (CDS) that allows holders to exchange a pegged asset 1:1 for a base redemption asset in the event of a depeg. Cork V1 launched its public beta on Ethereum Mainnet on March 4, 2025, with launch partners Lido Finance, EtherFi, Ethena, and Sky. The protocol was founded in 2023 by Phil Fogel, Robert Schmitt, Anna Stone (COO), and David Stancel. In January 2026, Cork raised $5.5 million in seed funding led by a16z CSX and Road Capital, with additional participation from 432 Ventures, BitGo Ventures, IDEO Ventures, and others. Cork V1 operated exclusively on Ethereum and targeted the wstETH:weETH market as its flagship offering.","heading":"Background","sources":[{"url":"https://www.cork.tech/blog/beta","name":"","type":"other","credibility":3},{"url":"https://chainwire.org/2026/01/21/cork-raises-5-5m-backed-by-road-capital-a16z-csx-and-strategic-investors-to-build-tokenized-risk-infrastructure/","name":"","type":"other","credibility":3},{"url":"https://www.coinspeaker.com/cork-protocol-raises-5-5m-decentralized-risk-layer/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Cork V1 introduced two primary derivative tokens per market: Depeg Swap (DS) tokens, which confer the right to redeem a pegged asset for a redemption asset at 1:1 in a depeg event, and Cover Tokens (CT), which represent the counterparty position. Markets are created permissionlessly by specifying a pegged asset (PA), a redemption asset (RA), an expiry, and an exchange rate provider contract. Liquidity vaults aggregate deposited RA and pair it with CT tokens, providing yield to liquidity providers while enabling DS buyers to hedge depeg risk. The protocol integrated Uniswap V4 hooks via a custom CorkHook contract to route swaps between DS and CT tokens. This permissionless market creation model — combined with the absence of input validation on key parameters — ultimately became the attack surface exploited in May 2025. The protocol design depended on the assumption that all markets would be created with legitimate, non-derived assets as redemption assets, an assumption that was not enforced at the contract level.","heading":"Protocol Mechanics","sources":[{"url":"https://docs.cork.tech/core-concepts/collateral-asset","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-cork-protocol-hack-may-2025","name":"","type":"other","credibility":3},{"url":"https://slowmist.medium.com/exploit-analysis-cork-protocol-attacked-over-10-million-lost-75de9f229307","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Cork V1 underwent four separate security reviews prior to launch: Quantstamp, Cantina, Sherlock, and Runtime Verification. Despite this coverage, the critical vulnerability that led to the $12 million exploit was not caught by any of them. Three firms — Sherlock, Runtime Verification, and Quantstamp — explicitly excluded the CorkHook contract from their defined scope; Runtime Verification cited time constraints as justification. Cantina's scope boundaries were not publicly disclosed. The exploit, which occurred on May 28, 2025 at approximately 11:39 UTC, exploited two root-cause flaws: (1) the CorkHook contract's beforeSwap function lacked authorization checks, allowing any caller to inject arbitrary hook data; and (2) the protocol permitted creation of new markets using existing DS tokens from legitimate markets as redemption assets, a configuration that was never intended and not validated. The attacker exploited these in combination to mint counterfeit CT and DS tokens against a fraudulent market, then redeem them for real wstETH from the original vault. 3,761.878 wstETH (approximately $12 million at the time) was extracted and subsequently converted to ETH. A public bug bounty program was also maintained via Cantina at the time of the exploit. Following the incident, the hacker left on-chain messages criticizing the audit firms, stating 'Sherlock missed it.' A separate dispute between Sherlock CEO Jack Sanford and Spearbit/Cantina emerged publicly, with each party alleging the other missed the vulnerability or failed to disclose scope gaps. Post-incident, Cork announced it was working with Spearbit Labs, Quantstamp, and additional senior technical advisors to develop a safe remediation plan. The protocol acknowledged the audit gap in its post-mortem and stated it would improve naming conventions and contract structure to support future AI-assisted and human auditing. A Cantina bug bounty remained active as of the time of the exploit.","heading":"Security & Audits","sources":[{"url":"https://rekt.news/cork-protocol-rekt","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-cork-protocol-hack-may-2025","name":"","type":"other","credibility":3},{"url":"https://protos.com/sherlock-missed-it-cork-hacker-slams-audit-firms-in-on-chain-messages/","name":"","type":"other","credibility":3},{"url":"https://www.quillaudits.com/blog/hack-analysis/cork-protocol-hack-explained","name":"","type":"other","credibility":3},{"url":"https://slowmist.medium.com/exploit-analysis-cork-protocol-attacked-over-10-million-lost-75de9f229307","name":"","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/cork-protocol-incident-analysis","name":"","type":"other","credibility":3},{"url":"https://dedaub.com/blog/the-11m-cork-protocol-hack-a-critical-lesson-in-uniswap-v4-hook-security/","name":"","type":"other","credibility":3},{"url":"https://cantina.xyz/bounties/7e55cc61-e96c-4bda-a324-25b44d45e171","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Cork Protocol was co-founded by Phil Fogel (Co-Founder), Robert Schmitt (Co-Founder), Anna Stone (COO and Co-Founder), and David Stancel (Co-Founder). Phil Fogel previously co-founded FlowCarbon, a blockchain-based carbon credit platform. Robert Schmitt has a background in satellite data and AI before entering Web3. Anna Stone previously served as Executive Director at GoodDollar.org. David Stancel is listed as a co-founder with a history of speaking at blockchain industry events. The team is headquartered in New York. The protocol is backed by a16z CSX, the accelerator arm of Andreessen Horowitz's crypto division, as well as Road Capital, BitGo Ventures, 432 Ventures, IDEO Ventures, and multiple other institutional participants in a $5.5 million seed round announced in January 2026. The founding team has maintained public presence through official channels and responded publicly to the May 2025 exploit via blog and post-mortem publication. No allegations of fraud, exit scam, or team misconduct have been identified in available sources.","heading":"Team & Ownership","sources":[{"url":"https://www.crunchbase.com/organization/cork-protocol","name":"","type":"other","credibility":3},{"url":"https://www.crunchbase.com/person/phil-fogel-b52c","name":"","type":"other","credibility":3},{"url":"https://www.crunchbase.com/person/anna-stone","name":"","type":"other","credibility":3},{"url":"https://chainwire.org/2026/01/21/cork-raises-5-5m-backed-by-road-capital-a16z-csx-and-strategic-investors-to-build-tokenized-risk-infrastructure/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Cork V1 presents a critical risk profile for any remaining depositors. The protocol suffered a $12 million smart contract exploit on May 28, 2025, less than three months after public beta launch. All protocol contracts were paused following the incident and remained paused pending a remediation plan as of available reports. The exploited vulnerability — inadequate input validation in the CorkHook beforeSwap function and unrestricted redemption asset selection in market creation — passed through four separate professional security audits, three of which explicitly scoped out the vulnerable contract. Stolen funds (approximately 4,530.6 ETH converted from 3,761.878 wstETH) were subsequently laundered through Tornado Cash in batches, with the attacker also donating 10 ETH to the Roman Storm legal defense fund. Wallet 0xea6f30e360192bae715599e15e2f765b49e4da98 has been identified on-chain as the exploit address. No formal user compensation plan has been publicly announced. No evidence of a rug pull, insider theft, or team misconduct was identified; the loss appears attributable entirely to a smart contract vulnerability. The primary risks for users who interacted with Cork V1 are: (1) funds locked in paused contracts with no confirmed withdrawal timeline; (2) stolen funds considered unrecoverable given Tornado Cash laundering; (3) protocol continuity uncertain pending redeployment of V1 or transition to a future version. The protocol's institutional backing (a16z CSX) and transparent post-incident communication are partial mitigating signals, but do not reduce the severity of documented losses or the absence of compensation.","heading":"Risk Assessment","sources":[{"url":"https://www.coindesk.com/business/2025/05/28/a16z-backed-cork-protocol-suffers-usd12m-smart-contract-exploit","name":"","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/?id=cork-protocol-hack","name":"","type":"other","credibility":3},{"url":"https://protos.com/cork-hacker-sends-eth-to-tornado-cash-donates-to-roman-storms-fund/","name":"","type":"other","credibility":3},{"url":"https://www.bitget.com/news/detail/12560604835357","name":"","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/cork-protocol-hacked-contracts-paused","name":"","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2023","event":"Cork Protocol founded by Phil Fogel, Robert Schmitt, Anna Stone, and David Stancel.","source":"","date_original":"2023-01-01"},{"date":"2024-09-10","event":"Cork Protocol joins a16z Crypto's Fall 2024 accelerator cohort and secures initial funding.","source":""},{"date":"2025-01-08","event":"Cork Protocol launches Phoenix, described as one of the first risk management solutions operating as a decentralized layer on Ethereum.","source":""},{"date":"2025-03-04","event":"Cork V1 public beta goes live on Ethereum Mainnet with launch partners Lido Finance, EtherFi, Ethena, and Sky.","source":""},{"date":"2025-05-28","event":"Cork Protocol exploited for approximately $12 million (3,761.878 wstETH) via a flawed CorkHook access control and permissionless fake market creation. All contracts paused. Attacker wallet: 0xea6f30e360192bae715599e15e2f765b49e4da98.","source":""},{"date":"2025-05-29","event":"Multiple security firms (SlowMist, QuillAudits, Halborn, CertiK, Dedaub) publish exploit analysis reports. Post-mortem published by Cork team.","source":""},{"date":"2025-06-25","event":"Cork exploiter resurfaces and launders approximately 4,520 ETH (~$11 million) through Tornado Cash. Also donates 10 ETH to Roman Storm's legal defense fund. Sends on-chain messages criticizing audit firms, stating 'Sherlock missed it.'","source":""},{"date":"2026-01-21","event":"Cork raises $5.5M seed round led by a16z CSX and Road Capital to continue building tokenized risk infrastructure.","source":""}],"sources_used":[{"url":"https://www.cork.tech/blog/beta","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://chainwire.org/2026/01/21/cork-raises-5-5m-backed-by-road-capital-a16z-csx-and-strategic-investors-to-build-tokenized-risk-infrastructure/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260317131523/https://chainwire.org/2026/01/21/cork-raises-5-5m-backed-by-road-capital-a16z-csx-and-strategic-investors-to-build-tokenized-risk-infrastructure/","credibility":3,"archive_timestamp":"2026-03-17T13:15:23+00:00"},{"url":"https://www.coinspeaker.com/cork-protocol-raises-5-5m-decentralized-risk-layer/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260212161138/https://www.coinspeaker.com/cork-protocol-raises-5-5m-decentralized-risk-layer/","credibility":3,"archive_timestamp":"2026-02-12T16:11:38+00:00"},{"url":"https://docs.cork.tech/core-concepts/collateral-asset","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.halborn.com/blog/post/explained-the-cork-protocol-hack-may-2025","name":"","type":"other","archive_url":"http://web.archive.org/web/20260414125627/https://www.halborn.com/blog/post/explained-the-cork-protocol-hack-may-2025","credibility":3,"archive_timestamp":"2026-04-14T12:56:27+00:00"},{"url":"https://slowmist.medium.com/exploit-analysis-cork-protocol-attacked-over-10-million-lost-75de9f229307","name":"","type":"other","archive_url":"http://web.archive.org/web/20251113081358/https://slowmist.medium.com/exploit-analysis-cork-protocol-attacked-over-10-million-lost-75de9f229307","credibility":3,"archive_timestamp":"2025-11-13T08:13:58+00:00"},{"url":"https://rekt.news/cork-protocol-rekt","name":"","type":"other","archive_url":"http://web.archive.org/web/20260608202810/https://rekt.news/cork-protocol-rekt","credibility":3,"archive_timestamp":"2026-06-08T20:28:10+00:00"},{"url":"https://protos.com/sherlock-missed-it-cork-hacker-slams-audit-firms-in-on-chain-messages/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260517183847/https://protos.com/sherlock-missed-it-cork-hacker-slams-audit-firms-in-on-chain-messages/","credibility":3,"archive_timestamp":"2026-05-17T18:38:47+00:00"},{"url":"https://www.quillaudits.com/blog/hack-analysis/cork-protocol-hack-explained","name":"","type":"other","archive_url":"http://web.archive.org/web/20260626173340/https://www.quillaudits.com/blog/hack-analysis/cork-protocol-hack-explained","credibility":3,"archive_timestamp":"2026-06-26T17:33:40+00:00"},{"url":"https://www.certik.com/resources/blog/cork-protocol-incident-analysis","name":"","type":"other","archive_url":"http://web.archive.org/web/20250930033436/https://www.certik.com/resources/blog/cork-protocol-incident-analysis","credibility":3,"archive_timestamp":"2025-09-30T03:34:36+00:00"},{"url":"https://dedaub.com/blog/the-11m-cork-protocol-hack-a-critical-lesson-in-uniswap-v4-hook-security/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260816142824/https://dedaub.com/blog/the-11m-cork-protocol-hack-a-critical-lesson-in-uniswap-v4-hook-security/","credibility":3,"archive_timestamp":"2026-08-16T14:28:24+00:00"},{"url":"https://cantina.xyz/bounties/7e55cc61-e96c-4bda-a324-25b44d45e171","name":"","type":"other","archive_url":"http://web.archive.org/web/20260215052210/https://cantina.xyz/bounties/7e55cc61-e96c-4bda-a324-25b44d45e171","credibility":3,"archive_timestamp":"2026-02-15T05:22:10+00:00"},{"url":"https://www.crunchbase.com/organization/cork-protocol","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.crunchbase.com/person/phil-fogel-b52c","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.crunchbase.com/person/anna-stone","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.coindesk.com/business/2025/05/28/a16z-backed-cork-protocol-suffers-usd12m-smart-contract-exploit","name":"","type":"other","archive_url":"http://web.archive.org/web/20260511093038/https://www.coindesk.com/business/2025/05/28/a16z-backed-cork-protocol-suffers-usd12m-smart-contract-exploit","credibility":3,"archive_timestamp":"2026-05-11T09:30:38+00:00"},{"url":"https://www.web3isgoinggreat.com/?id=cork-protocol-hack","name":"","type":"other","archive_url":"http://web.archive.org/web/20251212162037/https://www.web3isgoinggreat.com/?id=cork-protocol-hack","credibility":3,"archive_timestamp":"2025-12-12T16:20:37+00:00"},{"url":"https://protos.com/cork-hacker-sends-eth-to-tornado-cash-donates-to-roman-storms-fund/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260609053240/https://protos.com/cork-hacker-sends-eth-to-tornado-cash-donates-to-roman-storms-fund/","credibility":3,"archive_timestamp":"2026-06-09T05:32:40+00:00"},{"url":"https://www.bitget.com/news/detail/12560604835357","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829044216/https://www.bitget.com/news/detail/12560604835357","credibility":3,"archive_timestamp":"2026-08-29T04:42:16+00:00"},{"url":"https://cointelegraph.com/news/cork-protocol-hacked-contracts-paused","name":"","type":"other","archive_url":"http://web.archive.org/web/20251005225324/https://cointelegraph.com/news/cork-protocol-hacked-contracts-paused","credibility":3,"archive_timestamp":"2025-10-05T22:53:24+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:23.189238+00:00","updated_at":"2026-08-29T12:34:18.949719+00:00"}}