Skip to main content
AVOID.NET
Clober Liquidity Vaultreviewed 2026-09-06 · 35 claims checked

Fact-check findings

What an automated fact-checker found when it re-read Clober Liquidity Vault against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed

3 claims

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #15[disputed][awaiting moderator]in section: Audit History and Post-Audit Code Changes
    Kupia Security completed their audit of the vault just two days before the December 10, 2024 exploit occurred.
    reviewerKupia Security completed their audit of the vault just two days before the December 10, 2024 exploit occurredThe cited Rekt News article does not give a specific number of days, and Kupia's own portfolio dates the audit to November 28, 2024 — about 12 days, not two days, before the December 10 exploit. The 'two days before' framing appears to be an invented specific that is not supported by, and is contradicted by, the best available primary record.
    Proposed correction (not yet applied)
    Kupia Security completed their audit of the vault on November 28, 2024, roughly two weeks before the December 10, 2024 exploit occurred.
  2. #29[disputed][awaiting moderator]in the timeline
    2024-12-08
    reviewerTimeline: Kupia Security completes audit of the Clober Liquidity Vault contracts, two days before the exploit (dated 2024-12-08)Same underlying error as the audit-history section finding: the stored date (Dec 8, 2024) implies 'two days before' the exploit, but Kupia's own portfolio lists Nov 28, 2024.
    Proposed correction (not yet applied)
    2024-11-28
  3. #30[disputed][awaiting moderator]in the timeline
    Kupia Security completes audit of the Clober Liquidity Vault contracts, two days before the exploit.
    reviewerTimeline event text: Kupia Security completes audit of the Clober Liquidity Vault contracts, two days before the exploitProse companion to the timeline[2].date defect; both should be corrected together under the same defect_group.
    Proposed correction (not yet applied)
    Kupia Security completes audit of the Clober Liquidity Vault contracts, approximately two weeks before the exploit.

unverifiable

3 claims

No source the reviewer could reach confirms or contradicts the claim.

  1. #9[unverifiable][awaiting moderator]in section: December 2024 Reentrancy Exploit
    The total stolen funds were 133.7 ETH, withdrawn twice (approximately 66.85 ETH per reentrant call).
    reviewerThe total stolen funds were 133.7 ETH, withdrawn twice (approximately 66.85 ETH per reentrant call)The overall reentrant double-withdrawal is well supported, but no source I could access confirms the specific even 66.85 ETH-per-call breakdown; this appears to be an inferred/derived figure (133.7 / 2) rather than one reported by any cited source, and downstream fund-split figures reported elsewhere are uneven, not a clean 50/50 split.
  2. #22[unverifiable][awaiting moderator]in section: Team Response and Fund Recovery
    There are no reports of user compensation, restitution, or a community fund used to cover the losses to liquidity providers. No regulatory filings or law enforcement actions have been publicly reported in connection with this incident.
    reviewerThere are no reports of user compensation, restitution, or a community fund used to cover the losses; no regulatory filings or law enforcement actions have been publicly reportedThis is a negative/absence claim. My searches turned up no evidence of compensation, restitution, or regulatory/law-enforcement action, which is consistent with the page, but absence of evidence in a search is not proof of absence; treated as unverifiable rather than confirmed.
  3. #27[unverifiable][awaiting moderator]in section: Ongoing Protocol Status
    No fraud allegations, regulatory actions, or SEC/CFTC proceedings have been identified against Clober or its team.
    reviewerNo fraud allegations, regulatory actions, or SEC/CFTC proceedings have been identified against Clober or its teamNo evidence of any regulatory action was found in searches, consistent with the claim, but this is a negative/absence claim that cannot be affirmatively confirmed.

partially supported

5 claims

The cited evidence supports part of the claim but not all of it.

  1. #5[partially supported][awaiting moderator]in section: Protocol Overview
    As of early 2025, Clober had expanded to Starknet and was also active on the Monad testnet ecosystem.
    reviewerAs of early 2025, Clober had expanded to Starknet and was also active on the Monad testnet ecosystemIndependent GitHub and social evidence supports a genuine Starknet and Monad testnet presence, but the cited DefiLlama source does not itself list Starknet as a tracked chain, so the specific sourcing is weaker than the claim implies.
  2. #19[partially supported][awaiting moderator]in section: Team Response and Fund Recovery
    The team offered the attacker a 20% white-hat bounty (approximately $100,200 at the time) and committed to non-prosecution in exchange for return of the remaining funds.
    reviewerThe team offered the attacker a 20% white-hat bounty (approximately $100,200 at the time) and committed to non-prosecutionThe 20% figure and non-prosecution commitment are independently confirmed, but the '$100,200' figure is not stated in any cited source — it is a derived calculation (20% of the reported ~$501,000 loss) presented without noting it is an estimate.
  3. #24[partially supported][awaiting moderator]in section: Attacker Profile and Cross-Protocol Activity
    This suggests the attacker was a repeat exploiter targeting DeFi protocols in the same timeframe rather than an actor with any connection to the Clober team. The Clober team is considered a victim of an external exploit in both incidents documented above.
    reviewerThis suggests the attacker was a repeat exploiter rather than an actor with any connection to the Clober team; the Clober team is considered a victim in both incidentsThe underlying wallet-linkage fact is confirmed; the interpretive conclusion ('no connection to the Clober team') is a reasonable but not independently provable inference — no source explicitly rules out insider involvement, it is simply unaddressed in all reporting.
  4. #25[partially supported][awaiting moderator]in section: Ongoing Protocol Status
    As of publicly available data through early 2026, the core CloberDEX V2 protocol remains operational on Base and has expanded to additional networks including Starknet.
    reviewerAs of publicly available data through early 2026, the core CloberDEX V2 protocol remains operational on Base and has expanded to additional networks including StarknetBase operation is confirmed. The Starknet claim is directionally supported by GitHub evidence of a live Cairo deployment, but the specific cited DefiLlama source does not itself list Starknet, so the sourcing for that part of the sentence is weaker than presented.
  5. #34[partially supported][awaiting moderator]in the timeline
    Clober team publicly acknowledges the exploit via X, confirms core protocol is unaffected, and offers attacker a 20% white-hat bounty (~$100,200) with non-prosecution commitment. Team engages Match Systems for fund recovery efforts.
    reviewerTimeline: Clober team acknowledges exploit via X, confirms core protocol unaffected, offers 20% bounty (~$100,200), non-prosecution commitment, engages Match Systems (dated 2024-12-11)Same '$100,200' derivation issue as the corresponding section finding — accurate arithmetic, but not a figure any cited source states directly.

confirmed

24 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in the summary
    On December 10, 2024, the Liquidity Vault suffered a reentrancy exploit that drained approximately 133.7 ETH (~$501,000) from the newly launched vault
    reviewerOn December 10, 2024, the Liquidity Vault suffered a reentrancy exploit draining approximately 133.7 ETH (~$501,000)Multiple independent security-research and news sources corroborate the date and amount precisely.
  2. #2[confirmed][no action needed]in the summary
    the team offered a 20% white-hat bounty, which the attacker declined; funds were not recovered.
    reviewerThe team offered a 20% white-hat bounty, which the attacker declined, and funds were not recoveredConsistently reported across Rekt News, Cryptopolitan, and Mitrade.
  3. #3[confirmed][no action needed]in the summary
    The core CloberDEX protocol was unaffected
    reviewerThe core CloberDEX protocol was unaffected by the exploitReported consistently that only the Liquidity Vault/Rebalancer was affected.
  4. #4[confirmed][no action needed]in section: Protocol Overview
    The Clober Liquidity Vault (also referred to as the Rebalancer) is an automated liquidity management product layered on top of CloberDEX. It accepts user funds and deploys them as limit orders (bids and asks) on the Clober orderbook, aiming to generate yield through market-making activity rather than the AMM model.
    reviewerClober Liquidity Vault (also referred to as the Rebalancer) accepts user funds and deploys them as limit orders to generate yield through market-making rather than the AMM modelConsistent with Clober's own documentation and with post-incident analyses describing the Rebalancer contract's function.
  5. #6[confirmed][no action needed]in section: December 2024 Reentrancy Exploit
    The vulnerability resided in the _burn() function of the Rebalancer contract. The contract violated the checks-effects-interactions pattern by invoking an external callback (pool.strategy.burnHook) before updating internal reserve variables (pool.reserveA and pool.reserveB).
    reviewerThe vulnerability resided in the _burn() function of the Rebalancer contract, violating checks-effects-interactions by invoking pool.strategy.burnHook before updating pool.reserveA and pool.reserveBTechnical mechanism matches multiple independent security-research write-ups closely, including variable names.
  6. #7[confirmed][no action needed]in section: December 2024 Reentrancy Exploit
    The open() function also accepted arbitrary, unvalidated strategy contract addresses, allowing the attacker to supply a malicious strategy contract of their own design.
    reviewerThe open() function accepted arbitrary, unvalidated strategy contract addresses, allowing the attacker to supply a malicious strategy contractDirectly corroborated by QuillAudits' technical write-up.
  7. #8[confirmed][no action needed]in section: December 2024 Reentrancy Exploit
    They then obtained a 267.4 ETH flash loan from Morpho Blue and called burn(). During execution, the malicious burnHook reentered the _burn function before state variables were updated, causing the contract to compute withdrawal amounts against stale reserve values and effectively double-paying the attacker.
    reviewerThe attacker obtained a 267.4 ETH flash loan from Morpho Blue and called burn(), causing the malicious burnHook to reenter _burn before state was updated, double-paying the attackerFlash loan size, source, and reentrancy sequence match CertiK's incident analysis.
  8. #10[confirmed][no action needed]in section: December 2024 Reentrancy Exploit
    The attacker funded the initial transaction with only 2.87 ETH sourced from Binance.
    reviewerThe attacker funded the initial transaction with only 2.87 ETH sourced from BinanceMatches CertiK's incident analysis exactly.
  9. #11[confirmed][no action needed]in section: December 2024 Reentrancy Exploit
    Post-exploit, the stolen ETH was bridged from Base to Ethereum mainnet via the Across Protocol and distributed to two newly created addresses: 0x711C87A0767101Fa6f3893FACb670B5689621e23 and 0x7760d838192f6E526721a0f6b160627baE989a3e.
    reviewerStolen ETH was bridged from Base to Ethereum via Across Protocol and distributed to two newly created addresses: 0x711C87A0767101Fa6f3893FACb670B5689621e23 and 0x7760d838192f6E526721a0f6b160627baE989a3eAddresses and bridging route match CertiK's analysis exactly (case differences aside).
  10. #12[confirmed][no action needed]in section: December 2024 Reentrancy Exploit
    The on-chain attacker wallet address on Base is 0x012Fc6377F1c5CCF6e29967Bce52e3629AaA6025.
    reviewerThe on-chain attacker wallet address on Base is 0x012Fc6377F1c5CCF6e29967Bce52e3629AaA6025Confirmed directly on-chain via BaseScan's community label.
  11. #13[confirmed][no action needed]in section: December 2024 Reentrancy Exploit
    The exploit occurred approximately one day after the vault received its first liquidity injection (December 9, 2024), and about one week after the vault's initial launch.
    reviewerThe exploit occurred approximately one day after the vault's first liquidity injection (December 9, 2024), and about one week after the vault's initial launchBoth the one-day and roughly-one-week framings are consistent with Cryptopolitan's reported launch and first-liquidity dates.
  12. #14[confirmed][no action needed]in section: Audit History and Post-Audit Code Changes
    The core CloberDEX contracts received a security audit from Spearbit in January–February 2023, covering the period January 2 to January 13, 2023. The Spearbit engagement identified 4 critical, 5 high, 5 medium, and 8 low risk findings, all of which were reported as fixed.
    reviewerThe core CloberDEX contracts received a Spearbit audit January 2–13, 2023, with 4 critical, 5 high, 5 medium, and 8 low risk findings, all reported as fixedExact match to the Cantina/Spearbit audit portfolio record, including finding counts.
  13. #16[confirmed][no action needed]in section: Audit History and Post-Audit Code Changes
    Multiple post-incident analyses from security researchers including CertiK, QuillAudits, and Web3 Is Going Great concluded that the reentrancy vulnerability that enabled the exploit was a post-audit code addition — meaning the vulnerable code was not present in the version reviewed by auditors.
    reviewerMultiple post-incident analyses concluded the reentrancy vulnerability was a post-audit code addition not present in the audited versionAll three named outlets, plus Rekt News, independently support this characterization.
  14. #17[confirmed][no action needed]in section: Audit History and Post-Audit Code Changes
    Trust Security publicly stated that a post-audit code change introducing the reentrancy vulnerability was audited by another firm.
    reviewerTrust Security publicly stated that a post-audit code change introducing the reentrancy vulnerability was audited by another firmNear-verbatim match to the quoted Trust Security statement reported by Rekt News.
  15. #18[confirmed][no action needed]in section: Audit History and Post-Audit Code Changes
    Kupia Security acknowledged they had flagged concerns about the risk of malicious strategy contracts; Clober disputed that this finding was directly related to the reentrancy attack vector that was ultimately exploited.
    reviewerKupia Security acknowledged flagging concerns about malicious strategy contracts; Clober disputed the finding was directly related to the exploited reentrancy vectorMatches Rekt News' account of the dispute between Kupia and Clober.
  16. #20[confirmed][no action needed]in section: Team Response and Fund Recovery
    The team also engaged Match Systems, a blockchain forensics firm, to pursue recovery.
    reviewerThe team engaged Match Systems, a blockchain forensics firm, to pursue recoveryConfirmed by both Cryptopolitan and Mitrade.
  17. #21[confirmed][no action needed]in section: Team Response and Fund Recovery
    The attacker did not respond to the bounty offer and retained the stolen ETH. As of available reporting through early 2025, the funds had not been recovered.
    reviewerThe attacker did not respond to the bounty offer and retained the stolen ETH; as of available reporting through early 2025, funds had not been recoveredConsistent across sources; no later reporting of recovery was found.
  18. #23[confirmed][no action needed]in section: Attacker Profile and Cross-Protocol Activity
    The wallet address identified as the Clober exploiter (0x012Fc6377F1c5CCF6e29967Bce52e3629AaA6025) was also linked by CertiK's incident analysis to a prior exploit of ZeroLend's MAHA Lending Pool on December 4, 2024, which resulted in approximately $77,000 in losses.
    reviewerThe exploiter wallet was linked by CertiK to a prior exploit of ZeroLend's MAHA Lending Pool on December 4, 2024, resulting in approximately $77,000 in lossesDirectly corroborated by CertiK's incident analysis.
  19. #26[confirmed][no action needed]in section: Ongoing Protocol Status
    The Clober Liquidity Vault product had resumed accumulating TVL post-exploit, though at a modest level.
    reviewerThe Clober Liquidity Vault product had resumed accumulating TVL post-exploit, though at a modest levelConfirmed via DefiLlama's own time series data for this protocol slug.
  20. #28[confirmed][no action needed]in section: Ongoing Protocol Status
    The team members are not publicly named in available sources, and no governance token or ICO has been identified in connection with this protocol.
    reviewerThe team members are not publicly named in available sources, and no governance token or ICO has been identified in connection with this protocolChecked ICOholder and CoinMarketCap listings for a CLOB token or ICO; found none, supporting the claim.
  21. #31[confirmed][no action needed]in the timeline
    Wallet address 0x012Fc637... exploits ZeroLend's MAHA Lending Pool for approximately $77,000 — six days before the Clober exploit.
    reviewerTimeline: wallet 0x012Fc637... exploits ZeroLend's MAHA Lending Pool for approximately $77,000, six days before the Clober exploit (dated 2024-12-04)Date arithmetic (Dec 4 to Dec 10 = six days) and figures both check out.
  22. #32[confirmed][no action needed]in the timeline
    Clober Liquidity Vault receives its first liquidity injection from users.
    reviewerTimeline: Clober Liquidity Vault receives its first liquidity injection from users (dated 2024-12-09)Confirmed.
  23. #33[confirmed][no action needed]in the timeline
    Attacker exploits reentrancy vulnerability in the Rebalancer contract's _burn() function, draining 133.7 ETH (~$501,000) from the Clober Liquidity Vault using a 267.4 ETH Morpho Blue flash loan and a malicious strategy contract. Stolen funds bridged to Ethereum via Across Protocol.
    reviewerTimeline: attacker exploits reentrancy vulnerability draining 133.7 ETH using a 267.4 ETH Morpho Blue flash loan, funds bridged via Across Protocol (dated 2024-12-10)Consistent with the sections[1] finding on the same facts.
  24. #35[confirmed][no action needed]in the timeline
    Attacker declines bounty offer and retains stolen ETH. Funds not recovered.
    reviewerTimeline: attacker declines bounty offer and retains stolen ETH; funds not recovered (dated 2024-12-11)Confirmed by Mitrade; Nominis source itself does not detail this but the fact is corroborated elsewhere.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.