Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·5FjSGg…gZHCSummary
Clober Liquidity Vault is an automated market-making product built on top of CloberDEX, a fully on-chain central limit order book (CLOB) DEX deployed on Coinbase's Base network. On December 10, 2024, the Liquidity Vault suffered a reentrancy exploit that drained approximately 133.7 ETH (~$501,000) from the newly launched vault — one day after it received its first liquidity injection. The core CloberDEX protocol was unaffected, and the team offered a 20% white-hat bounty, which the attacker declined; funds were not recovered.
Connected Entities
1 entities · 10 linked investigationsTimeline(7 events)
2 January 2023
Spearbit begins security audit of Clober DEX core contracts; engagement runs through January 13, 2023. All critical and high findings reported as fixed.
Cantina / Spearbit audit portfolio4 December 2024
Wallet address 0x012Fc637... exploits ZeroLend's MAHA Lending Pool for approximately $77,000 — six days before the Clober exploit.
CertiK — Clober Dex Incident Analysis8 December 2024
Kupia Security completes audit of the Clober Liquidity Vault contracts, two days before the exploit.
Rekt News — Clober Dex9 December 2024
Clober Liquidity Vault receives its first liquidity injection from users.
Cryptopolitan — Clober liquidity vault exploited for 133 ETH10 December 2024
Attacker exploits reentrancy vulnerability in the Rebalancer contract's _burn() function, draining 133.7 ETH (~$501,000) from the Clober Liquidity Vault using a 267.4 ETH Morpho Blue flash loan and a malicious strategy contract. Stolen funds bridged to Ethereum via Across Protocol.
CertiK — Clober Dex Incident Analysis11 December 2024
Clober team publicly acknowledges the exploit via X, confirms core protocol is unaffected, and offers attacker a 20% white-hat bounty (~$100,200) with non-prosecution commitment. Team engages Match Systems for fund recovery efforts.
Cryptopolitan — Clober liquidity vault exploited for 133 ETH11 December 2024
Attacker declines bounty offer and retains stolen ETH. Funds not recovered.
Nominis — Crypto Security Incidents December 2024Decision Log
- hash: 37Wm4RucXB15jgraDWpYcuxYHbKnCBj8XQZqmwMZqLWD
- hash: HCry5b1JACvztJqK9tTUchtUVqyfCLCk6MZogyyghVQ6
- hash: 9aBdEqa7VY4mtsswqzm45TEipjfDMYAvazEYUVF2FLJx
- hash: 7D44QZyr2ekoMmffyqbXmybkE2wgJW6RNV6DjPmNnnVi
- hash: 5g3eCKv3AabC3jpc3Bz5jNaPb7yXg8tGQkXTCQmYcG6m
This investigation is cryptographically anchored to the Solana blockchain (5 events). 14 of 15 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:27 AM
last updated: 8/25/2026, 7:43:04 AM
avoid.net — verified advice for a post-truth world