← Clober Liquidity Vault6 decisions on this page
Audit log
Every state-changing event for Clober Liquidity Vault: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-05-30 04:56:40ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 423,087,959
- sig
5FjSGga5ugR6…vVP9gZHCexplorer ↗- hash
5g3eCKv3AabC…CQmYcG6msha256 → base58
verifying row…full verify ↗canonical bytes (6889 B) ▸
{"actor":"system:backfill","investigation_id":"1a79704b-57a7-48c8-a46e-fc27bd4c6d12","kind":"publish","page_slug":"clober-liquidity-vault","published_at":"2026-05-30T04:56:40.499Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Clober Liquidity Vault","sections":[{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://rekt.news/cloberdex-rekt","type":"other","url":""},{"credibility":3,"name":"https://defillama.com/protocol/clober-liquidity-vault","type":"other","url":""},{"credibility":3,"name":"https://www.certik.com/resources/blog/clober-dex-incident-analysis","type":"other","url":""},{"credibility":3,"name":"https://x.com/CloberDEX/status/1863504665851433203","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.certik.com/resources/blog/clober-dex-incident-analysis","type":"other","url":""},{"credibility":3,"name":"https://rekt.news/cloberdex-rekt","type":"other","url":""},{"credibility":3,"name":"https://www.quillaudits.com/blog/hack-analysis/cloberdex-reentrancy-exploit-501k","type":"other","url":""},{"credibility":3,"name":"https://blog.solidityscan.com/cloberdex-liquidity-vault-hack-analysis-f22eb960aa6f","type":"other","url":""},{"credibility":3,"name":"https://x.com/peckshieldalert/status/1866434326596112705","type":"other","url":""},{"credibility":3,"name":"https://x.com/peckshield/status/1866443215186088048","type":"other","url":""},{"credibility":3,"name":"https://basescan.org/address/0x012fc6377f1c5ccf6e29967bce52e3629aaa6025","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://rekt.news/cloberdex-rekt","type":"other","url":""},{"credibility":3,"name":"https://www.certik.com/resources/blog/clober-dex-incident-analysis","type":"other","url":""},{"credibility":3,"name":"https://www.web3isgoinggreat.com/single/clober-dex-hack","type":"other","url":""},{"credibility":3,"name":"https://www.quillaudits.com/blog/hack-analysis/cloberdex-reentrancy-exploit-501k","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://x.com/peckshieldalert/status/1866434326596112705","type":"other","url":""},{"credibility":3,"name":"https://www.certik.com/resources/blog/clober-dex-incident-analysis","type":"other","url":""},{"credibility":3,"name":"https://rekt.news/cloberdex-rekt","type":"other","url":""},{"credibility":3,"name":"https://lunaray.medium.com/cloberdex-hack-analysis-04bc7cd3cbc4","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.certik.com/resources/blog/clober-dex-incident-analysis","type":"other","url":""},{"credibility":3,"name":"https://rekt.news/cloberdex-rekt","type":"other","url":""},{"credibility":3,"name":"https://defillama.com/protocol/clober-liquidity-vault","type":"other","url":""},{"credibility":3,"name":"https://www.cryptopolitan.com/clober-vault-exploited-team-offers-bounty/","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://x.com/peckshieldalert/status/1866434326596112705","type":"other","url":""},{"credibility":3,"name":"https://x.com/peckshield/status/1866443215186088048","type":"other","url":""},{"credibility":3,"name":"https://www.certik.com/resources/blog/clober-dex-incident-analysis","type":"other","url":""},{"credibility":3,"name":"https://www.quillaudits.com/blog/hack-analysis/cloberdex-reentrancy-exploit-501k","type":"other","url":""},{"credibility":3,"name":"https://blog.solidityscan.com/cloberdex-liquidity-vault-hack-analysis-f22eb960aa6f","type":"other","url":""},{"credibility":3,"name":"https://lunaray.medium.com/cloberdex-hack-analysis-04bc7cd3cbc4","type":"other","url":""},{"credibility":3,"name":"https://www.web3isgoinggreat.com/single/clober-dex-hack","type":"other","url":""},{"credibility":3,"name":"https://www.nominis.io/insights/crypto-security-incidents-december-2024","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://rekt.news/cloberdex-rekt","type":"other","url":""},{"credibility":3,"name":"https://www.certik.com/resources/blog/clober-dex-incident-analysis","type":"other","url":""},{"credibility":3,"name":"https://www.cryptopolitan.com/clober-vault-exploited-team-offers-bounty/","type":"other","url":""},{"credibility":3,"name":"https://www.mitrade.com/insights/news/live-news/article-3-515047-20241211","type":"other","url":""}]}],"sources_used":[],"summary":"Clober is a fully on-chain order book DEX (Decentralized Exchange) for EVM networks, built on the proprietary LOBSTER algorithm, which launched on February 14, 2023. Its Liquidity Vault product, a hybrid order-book/AMM product launched on Coinbase's Base network in December 2024, was exploited for approximately 133.7 ETH (~$501,000) within days of launch due to a reentrancy vulnerability introduced in post-audit code changes. The attacker ultimately moved the stolen funds through Tornado Cash after on-chain bounty negotiations failed.","timeline":[{"date":"2023-02-14","event":"Clober V1 launches as the first fully on-chain order book DEX for EVM, introducing the LOBSTER algorithm.","source":""},{"date":"2024-11-30","event":"Clober announces the Clober Liquidity Vault (CLV) going live on Base network, combining order book precision with AMM simplicity using Chainlink DataStream price feeds.","source":""},{"date":"2024-12-10","event":"Clober Liquidity Vault on Base is exploited via a reentrancy attack on the Rebalancer contract's _burn() function. Attacker uses a 267.4 ETH Morpho Blue flash loan and a malicious strategy contract. Approximately 133.7 ETH (~$501,000) is drained. PeckShield issues the first public alert.","source":""},{"date":"2024-12-10","event":"Stolen 133.7 ETH is bridged from Base to Ethereum mainnet via Across Protocol and split across two attacker-controlled addresses: 0x711C87A0767101Fa6f3893FACb670B5689621e23 and 0x7760d838192f6E526721a0f6b160627baE989a3e.","source":""},{"date":"2024-12-11","event":"Clober team issues a public statement confirming the exploit, asserting Core protocol and Arbitrum are unaffected, and sends an on-chain message offering the attacker a 20% white-hat bounty (~$100,000) with no legal repercussions.","source":""},{"date":"2024-12-11","event":"CertiK, QuillAudits, SolidityScan, and Lunaray publish independent technical post-mortems. Security researcher Raz0r of Decurity identifies the vulnerable burnHook as a post-audit code addition.","source":""},{"date":"2024-12-31","event":"Clober team confirms bounty negotiations with the attacker have failed and that the stolen assets have been moved into Tornado Cash, effectively laundering the funds.","source":""}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 8a5ac38b-87ef-4673-95ea-bd9596f567e3 - #2reviewby reviewerreviewer2026-08-18 21:01:33ZScore: 42 → 42 (no score change)The core facts of the Dec 10, 2024 Clober Liquidity Vault exploit — amount (~133.7 ETH / $501k), mechanism (reentrancy in a post-audit change to the Rebalancer _burn function), flash-loan details, and Clober's public 20% bounty offer — are well corroborated across independent post-mortems (rekt.news, CertiK, QuillAudits, SolidityScan). The page's closing claim that the attacker moved funds to Tornado Cash after bounty negotiations failed on Dec 31, 2024 could not be corroborated by any source checked and should be treated as unverified. The page also omits exculpatory context: the core Clober protocol and other chains were unaffected, and the project has continued active development and expansion (Monad, Starknet) with no reported repeat incidents through 2026, which is relevant to how severely this single, disclosed, contained incident should weigh against the entity today.anchoranchored
- chain
- ●mainnet-betaslot 443,508,874
- sig
2NxmdmG14Mc1…SSbppVNDexplorer ↗- hash
7D44QZyr2eko…jPmNnnVisha256 → base58
verifying row…full verify ↗canonical bytes (1245 B) ▸
{"actor":"reviewer","decided_at":"2026-08-18T21:01:33.406Z","decision":"review","investigation_id":"1a79704b-57a7-48c8-a46e-fc27bd4c6d12","new_score":42,"page_slug":"clober-liquidity-vault","prev_score":42,"reason":"The core facts of the Dec 10, 2024 Clober Liquidity Vault exploit — amount (~133.7 ETH / $501k), mechanism (reentrancy in a post-audit change to the Rebalancer _burn function), flash-loan details, and Clober's public 20% bounty offer — are well corroborated across independent post-mortems (rekt.news, CertiK, QuillAudits, SolidityScan). The page's closing claim that the attacker moved funds to Tornado Cash after bounty negotiations failed on Dec 31, 2024 could not be corroborated by any source checked and should be treated as unverified. The page also omits exculpatory context: the core Clober protocol and other chains were unaffected, and the project has continued active development and expansion (Monad, Starknet) with no reported repeat incidents through 2026, which is relevant to how severely this single, disclosed, contained incident should weigh against the entity today.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision b6842d15-5371-4ccf-8e6a-036ee1faa0ee - #3review approve with notesby judgejudge2026-08-18 21:01:33ZScore: 42 → 58 (+16)This is a calibration-only adjudication: the page's core facts hold up (claim_findings[0,2,4,6,7] confirmed across independent post-mortems from CertiK, rekt.news, QuillAudits, SolidityScan; disputed_pct is 0), so no content-accuracy action is warranted beyond hedging language. The score, however, does not match the reviewer's calibration_assessment. The Dec 10, 2024 incident is attribution 'b' (suffered) per the reviewer: an external attacker exploited a reentrancy bug introduced in a post-audit code change, Clober disclosed quickly, confirmed the core protocol and other chains were unaffected, and offered a transparent on-chain bounty with no evidence of fraud, exit-scam behavior, or user deception. Per the rubric, a 'suffered' hack caps the entity at CAUTIONARY (50-69), not WARNING, so the current score of 42 is mis-banded relative to conduct. I agree with the reviewer's recommended score of 58: it sits in the lower-middle of CAUTIONARY, reflecting a material, negligence-flavored loss (~$501k from skipping re-audit of a late change, claim_findings[2]) offset by transparent disclosure, no fraud, and continued operation with no repeat incidents (coverage_gaps item 1). Notes: (Hedge or source the claim that the attacker moved funds to Tornado Cash and that negotiations failed on Dec 31, 2024 (claim_findings[3] and [8]) — no cited or independently searched source corroborates this; treat as unconfirmed until a source is found.) (Fix the internal date inconsistency between the summary ('launched ... in December 2024') and timeline[1] (announcement dated Nov 30, 2024) (claim_findings[1]).) (Add exculpatory/contextual coverage: Clober's core protocol and Arbitrum deployment were unaffected, and the project has continued active development and expanded to Monad and Starknet with no reported repeat incidents through 2026 (coverage_gaps, priority: high).) (Consider noting the attacker wallet's prior ~$77,000 ZeroLend/MAHA exploit (Dec 4, 2024) per CertiK, to help readers calibrate this as a serial-exploiter pattern rather than a Clober-specific security culture issue (coverage_gaps, priority: medium).) (Verify whether the live page sections render actual prose — all seven sections in the review input had empty content/heading fields (coverage_gaps, priority: medium).)anchoranchored
- chain
- ●mainnet-betaslot 443,508,878
- sig
3CmjhR8mqguv…ssJdH6ioexplorer ↗- hash
9aBdEqa7VY4m…UVF2FLJxsha256 → base58
verifying row…full verify ↗canonical bytes (2676 B) ▸
{"actor":"judge","decided_at":"2026-08-18T21:01:33.406Z","decision":"review_approve_with_notes","investigation_id":"1a79704b-57a7-48c8-a46e-fc27bd4c6d12","new_score":58,"page_slug":"clober-liquidity-vault","prev_score":42,"reason":"This is a calibration-only adjudication: the page's core facts hold up (claim_findings[0,2,4,6,7] confirmed across independent post-mortems from CertiK, rekt.news, QuillAudits, SolidityScan; disputed_pct is 0), so no content-accuracy action is warranted beyond hedging language. The score, however, does not match the reviewer's calibration_assessment. The Dec 10, 2024 incident is attribution 'b' (suffered) per the reviewer: an external attacker exploited a reentrancy bug introduced in a post-audit code change, Clober disclosed quickly, confirmed the core protocol and other chains were unaffected, and offered a transparent on-chain bounty with no evidence of fraud, exit-scam behavior, or user deception. Per the rubric, a 'suffered' hack caps the entity at CAUTIONARY (50-69), not WARNING, so the current score of 42 is mis-banded relative to conduct. I agree with the reviewer's recommended score of 58: it sits in the lower-middle of CAUTIONARY, reflecting a material, negligence-flavored loss (~$501k from skipping re-audit of a late change, claim_findings[2]) offset by transparent disclosure, no fraud, and continued operation with no repeat incidents (coverage_gaps item 1). Notes: (Hedge or source the claim that the attacker moved funds to Tornado Cash and that negotiations failed on Dec 31, 2024 (claim_findings[3] and [8]) — no cited or independently searched source corroborates this; treat as unconfirmed until a source is found.) (Fix the internal date inconsistency between the summary ('launched ... in December 2024') and timeline[1] (announcement dated Nov 30, 2024) (claim_findings[1]).) (Add exculpatory/contextual coverage: Clober's core protocol and Arbitrum deployment were unaffected, and the project has continued active development and expanded to Monad and Starknet with no reported repeat incidents through 2026 (coverage_gaps, priority: high).) (Consider noting the attacker wallet's prior ~$77,000 ZeroLend/MAHA exploit (Dec 4, 2024) per CertiK, to help readers calibrate this as a serial-exploiter pattern rather than a Clober-specific security culture issue (coverage_gaps, priority: medium).) (Verify whether the live page sections render actual prose — all seven sections in the review input had empty content/heading fields (coverage_gaps, priority: medium).)","score_delta":16,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision a2c162f0-1100-47d1-a968-54e4ef464676 - #4reviewby reviewerreviewer2026-08-25 07:43:04ZScore: 52 → 52 (no score change)The page's core narrative — a December 10, 2024 reentrancy exploit draining ~133.7 ETH (~$501,000) from the newly launched Clober Liquidity Vault via a post-audit code change in the _burn() function, with a declined 20% white-hat bounty and unrecovered funds — is well-corroborated across CertiK, Rekt News, SolidityScan, PeckShield, BaseScan, and DefiLlama's live API. The main issues found are secondary: one section misattributes the 'post-audit code addition' conclusion to CertiK and QuillAudits when neither article actually makes that claim, several citations (Nominis, Cryptopolitan, Mitrade) are used for specific sub-facts (bounty decline, non-prosecution) that those particular articles do not contain even though the facts are true and sourced elsewhere on the page, and one operational-status claim about 'modest' TVL is accurate for its stated 'early 2026' window but is now outdated relative to substantially higher live TVL.anchoranchored
- chain
- ●mainnet-betaslot 443,512,461
- sig
2xxpL1F5v1R2…5r1w98Adexplorer ↗- hash
HCry5b1JACvz…gyyghVQ6sha256 → base58
verifying row…full verify ↗canonical bytes (1298 B) ▸
{"actor":"reviewer","decided_at":"2026-08-25T07:43:04.209Z","decision":"review","investigation_id":"1a79704b-57a7-48c8-a46e-fc27bd4c6d12","new_score":52,"page_slug":"clober-liquidity-vault","prev_score":52,"reason":"The page's core narrative — a December 10, 2024 reentrancy exploit draining ~133.7 ETH (~$501,000) from the newly launched Clober Liquidity Vault via a post-audit code change in the _burn() function, with a declined 20% white-hat bounty and unrecovered funds — is well-corroborated across CertiK, Rekt News, SolidityScan, PeckShield, BaseScan, and DefiLlama's live API. The main issues found are secondary: one section misattributes the 'post-audit code addition' conclusion to CertiK and QuillAudits when neither article actually makes that claim, several citations (Nominis, Cryptopolitan, Mitrade) are used for specific sub-facts (bounty decline, non-prosecution) that those particular articles do not contain even though the facts are true and sourced elsewhere on the page, and one operational-status claim about 'modest' TVL is accurate for its stated 'early 2026' window but is now outdated relative to substantially higher live TVL.","score_delta":0,"sequence_num":4,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision 93165b70-54c0-4caf-a004-e780e4244aea - #5review approveby judgejudge2026-08-25 07:43:04ZScore: 52 → 52 (no score change)The reviewer found zero disputed claims out of 47, with a disputed_pct of 8.5%, well within the approve threshold. The page's core narrative — the December 10, 2024 reentrancy exploit, the ~133.7 ETH loss, the technical mechanism, the declined bounty, and the unrecovered funds — is independently corroborated across CertiK, Rekt News, SolidityScan, PeckShield, BaseScan, and live DefiLlama on-chain TVL data (claim_findings[1], [43]). The issues raised are citation-attribution problems rather than factual errors: claim_findings[24] shows a real conclusion (that the vulnerability was a post-audit code addition) misattributed to CertiK and QuillAudits when it actually traces to Trust Security and Web3 Is Going Great, and claim_findings[29], [43], [44] show true facts (non-prosecution commitment, bounty decline) cited to articles that don't contain them even though the facts are corroborated elsewhere on the page. The one stale finding, claim_findings[38], understates the protocol's current TVL rather than overstating risk, so it does not weigh toward a penalty. The single high-priority coverage gap (on-chain forensic tracing of the stolen funds in the ~20 months since the exploit) is a suggestion for further investigation, not a documented discrepancy the reviewer actually found, so per standing practice it does not override an otherwise clean disputed-claim record.anchoranchored
- chain
- ●mainnet-betaslot 443,512,464
- sig
3qmeYCECYWoC…gnU4t8w2explorer ↗- hash
37Wm4RucXB15…mwMZqLWDsha256 → base58
verifying row…full verify ↗canonical bytes (1746 B) ▸
{"actor":"judge","decided_at":"2026-08-25T07:43:04.209Z","decision":"review_approve","investigation_id":"1a79704b-57a7-48c8-a46e-fc27bd4c6d12","new_score":52,"page_slug":"clober-liquidity-vault","prev_score":52,"reason":"The reviewer found zero disputed claims out of 47, with a disputed_pct of 8.5%, well within the approve threshold. The page's core narrative — the December 10, 2024 reentrancy exploit, the ~133.7 ETH loss, the technical mechanism, the declined bounty, and the unrecovered funds — is independently corroborated across CertiK, Rekt News, SolidityScan, PeckShield, BaseScan, and live DefiLlama on-chain TVL data (claim_findings[1], [43]). The issues raised are citation-attribution problems rather than factual errors: claim_findings[24] shows a real conclusion (that the vulnerability was a post-audit code addition) misattributed to CertiK and QuillAudits when it actually traces to Trust Security and Web3 Is Going Great, and claim_findings[29], [43], [44] show true facts (non-prosecution commitment, bounty decline) cited to articles that don't contain them even though the facts are corroborated elsewhere on the page. The one stale finding, claim_findings[38], understates the protocol's current TVL rather than overstating risk, so it does not weigh toward a penalty. The single high-priority coverage gap (on-chain forensic tracing of the stolen funds in the ~20 months since the exploit) is a suggestion for further investigation, not a documented discrepancy the reviewer actually found, so per standing practice it does not override an otherwise clean disputed-claim record.","score_delta":0,"sequence_num":5,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision 839d7e8d-16a8-49a7-bd14-2c0c8734ea5b - #6reviewby reviewerreviewer2026-09-09 03:05:30ZScore: 52 → 52 (no score change)Findings-only fact-check (retroactive anchor of stored findings)anchoranchored
- chain
- ●mainnet-betaslot 445,508,107
- sig
3PJT2z9V3N8V…Z1yfZvUGexplorer ↗- hash
BmDXF4kdQnkx…J6Xuvmq5sha256 → base58
verifying row…full verify ↗canonical bytes (715 B) ▸
{"actor":"reviewer","artifact_identity":"cf7b7fbb314741fb4c4e8ceee1442499","decided_at":"2026-09-06T16:36:16.956722+00:00","decision":"review","findings_count":35,"findings_rows_hash":"4ff331241707b5a69f2664470d302b9da3dbf063381b8a5638722ce858cb669b","investigation_id":"1a79704b-57a7-48c8-a46e-fc27bd4c6d12","mode":"findings_only_retroactive","new_score":52,"page_content_hash":"69a5dfb46e992260d7cd78c4c2cd5e964fd48b10aa48f812cb984a411d5bcb31","page_slug":"clober-liquidity-vault","prev_score":52,"reason":"Findings-only fact-check (retroactive anchor of stored findings)","score_delta":0,"sequence_num":6,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision f05c9890-4451-4825-9323-b19f1598a2a5
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.