Summary
Clipper is a decentralized exchange (DEX) built by Shipyard Software and governed by AdmiralDAO, designed to offer retail traders the lowest per-transaction costs on trades under $10,000 using a novel Formula Market Maker (FMM) mechanism. On December 1, 2024, a protocol logic exploit drained approximately $457,878 from its Optimism and Base liquidity pools by manipulating a single-asset deposit and withdrawal function; the attacker voluntarily returned 104 ETH in January 2025. While the protocol has legitimate venture backing and a documented technical architecture, the exploit revealed a gap between audited and deployed code, and the protocol has been flagged by on-chain investigator ZachXBT.
Connected Entities
1 entitiesTimeline(8 events)
2021-06-30
Clipper DEX launches on Ethereum mainnet, developed by Shipyard Software. Protocol is prefunded with $1 million in alpha liquidity.
2021-07-01
Within two weeks of launch, Clipper reports $14 million per week in trading volume across approximately 1,800 traders and 5,000 transactions.
2023-01-31
Shipyard Software announces $21 million in combined equity and liquidity funding. Polychain Capital leads the equity round. Three Arrows Capital is among the liquidity pledgers (Three Arrows Capital had already collapsed in June 2022).
2024-11-30
Attacker begins exploit on Clipper's Base network pool at approximately 8:22 PM MST, followed by the Optimism pool at approximately 9:15 PM MST.
2024-12-01
Clipper publicly confirms the exploit. Total loss reported at approximately $457,878, affecting Optimism and Base pools and representing roughly 6% of TVL. Swaps and deposits are suspended across all chains. Single-asset withdrawals are disabled.
2024-12-01
Chaofan Shou of security firm Fuzzland publicly alleges the incident resulted from a private key leak. Clipper explicitly denies this characterization, attributing the exploit to a withdrawal function logic vulnerability.
2024-12-04
Clipper publishes official post-mortem detailing the exploit mechanism, root causes including the circuit-breaker database interaction, and remediation plans.
2025-01-15
The attacker voluntarily returns 104 ETH to the Clipper treasury, citing personal health issues for the delay and stating no further vulnerabilities are known to remain. AdmiralDAO begins planning LP refund distribution.
Decision Log
- hash: AzSLPtiBy5a3U2DX1h9CaT2LBbgkdjCW4armWn28ez3M
- hash: 5owf6yhPBSj18BR3DHtiwxdD7JVtL43kph3S2273gF21
- hash: AodQbyRB9knanMAF3YJwVm139F2YnekNz84UGGQUpqT2
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:27 AM
last updated: 6/3/2026, 2:53:56 AM
avoid.net — verified advice for a post-truth world