CryptoReal
CASE FILE — Dec 11, 2024

Post-Audit Code Change Opens the Door to a $500K Reentrancy Hit on Clober DEX

Clober DEX's Liquidity Vault lost roughly $500,000 in a reentrancy exploit that struck the day before this report - a vulnerability class that has been documented in DeFi for years. The root cause traced back to a code change the team had shipped after its original security audit, reopening an attack surface that review had previously closed.

Both Trust Security and Kupia Security had examined the original vault contract and found it sound. But the modifications applied afterward were never subjected to the same level of scrutiny, and it was inside that unreviewed code that the exploit ultimately surfaced.

How the exploit worked

While much of the market slept, an attacker drained approximately 133 ETH from the vault. According to a breakdown from researcher Nick Franklin, the exploit targeted an unguarded _burn function that could be triggered through its burnHook callback. Using a custom malicious token contract paired with a purpose-built strategy, the attacker repeatedly withdrew funds by exploiting incomplete state updates between calls - the defining mechanic of reentrancy - and walked away with 133 ETH.

Attack transaction: 0x8fcdfcded45100437ff94801090355f2f689941dca75de9a702e01670f361c04

Attacker address: 0x012Fc6377F1c5CCF6e29967Bce52e3629AaA6025

Clober's team confirmed the incident on X shortly afterward, stating that the Liquidity Vault had been compromised while the core protocol remained unaffected.

PeckShield subsequently tracked the stolen funds as the attacker bridged the 133 ETH from Base to Ethereum mainnet and split it between two addresses:

0x711C87A0767101Fa6f3893FACb670B5689621e23

0x7760d838192f6E526721a0f6b160627baE989a3e

A tangled audit trail

Attention quickly turned to who had - and hadn't - reviewed the vulnerable code. Trust Security, which had audited the original contract, moved to distance itself from the incident, stating: "A post-audit code change introducing the reentrancy attack was audited by another firm." Its original audit report is publicly available.

That other firm was Kupia Security, which had completed its own review of the Rebalancer contract just days before the exploit. Kupia said it had raised concerns about potential issues involving malicious strategies in that contract, though Clober stated publicly that this finding was "NOT related to the reentrancy attack." Kupia's audit report is likewise public.

Adding another data point, researcher Raz0r of Decurity noted that the vulnerable burnHook call appeared to have been introduced after the audit process concluded - a detail that would help explain how such a well-documented class of vulnerability slipped through.

Aftermath

In a now-familiar resolution, Clober offered its attacker a 20% bounty in exchange for returning the remaining funds, along with a pledge not to pursue legal action.

The episode illustrates a recurring pattern in DeFi security: an audit covers a snapshot of code, and any change made after that snapshot - however small - falls outside its guarantees. Both Trust Security and Kupia Security appear to have done credible work on what was placed in front of them; the gap opened only after their reports were filed, when Clober's subsequent modifications went live without a comparable review.

Clober DexReentrancy
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.