How Cork Protocol's $12M Hacker Ended Up Correcting Its Auditors
Cork Protocol lost $12 million on May 28, 2025, when an attacker exploited two separate flaws to drain its wstETH:weETH market. The technical breakdown that followed should have closed the story. Instead, it opened a much messier one about who in the audit industry actually did their job — and the person who stole the money weighed in directly, in permanent, on-chain ink.
The exploiter goes on the record

On June 11, the attacker sent a zero-value transaction from their wallet carrying a message: "sherlock missed it. ct > ds. uniswap hook is not problem." It was a direct rebuttal of Cork's own post-mortem, which had pinned the breach on an "access control vulnerability in the Cork Hook."
A second message followed hours later, this time written in Estonian, accusing security firms of publishing fast for "promotion" rather than accuracy, without ever grasping the real vulnerability. The attacker also disputed that the Uniswap hook was the core issue, claiming there were "many ways to take DS, not just the Uniswap hook," and singled out Cover Tokens as "the most important" piece of the exploit. Cork's post-mortem later confirmed the breach had in fact combined two distinct attack vectors — lending unexpected credibility to the hacker's on-chain commentary.
The same attacker later sent 10 ETH to the legal defense fund of Tornado Cash developers Roman Storm and Alexey Pertsev. Storm returned the donation, citing legal constraints, after which Cork co-founder Phil Fogel publicly thanked him and made his own contribution to the fund.
A fight breaks out among the auditors
Before the hacker ever spoke up, Sherlock CEO Jack Sanford published an analysis questioning why the firms responsible for reviewing Cork's code had missed the vulnerability entirely. His focus fell squarely on Cantina and Spearbit, which had merged in late May 2025 into what the two firms called a unified platform.
Sanford noted that three of the audit firms involved had published clear scope documentation — commit hashes, public repos, defined boundaries. Cantina and Spearbit's records, by contrast, relied on private repositories with no commit hashes, which Sanford read as scope obfuscation.
He also compared results: Sherlock's 12-day public contest drew 39 researchers who flagged 10 critical bugs. Cantina's 22-day private review, finished in January 2025, caught other issues but none of those critical ones. Cork's own post-mortem had already acknowledged that the "access control vulnerability in the Cork Hook" went unflagged by multiple audits — yet some of the firms involved maintained the vulnerable code fell outside their scope.
Trust Security joined the criticism too, calling out industry practices where platforms "default to client's perspective" and grant clients an annual allowance to quietly absorb bug-bounty disputes.
Silence from some, stonewalling from others
Sherlock, Quantstamp, and Runtime Verification each released their full reports — commit hashes, scope, the works — leaving the material open to outside scrutiny. Quantstamp and Runtime Verification otherwise stayed out of the public dispute.

Rekt News asked Hari, CEO of Cantina/Spearbit, to respond. He disputed Sanford's piece as "a gross misrepresentation of facts" but said confidentiality agreements prevented him from detailing why, adding only that undisclosed facts would come out "in the future" and that "the situation is even more complicated." Pressed on which specific claims could be corrected without breaching confidentiality, he repeated that nothing could be shared.
What the episode exposes
A handful of security researchers privately echoed Sanford's concerns after Rekt's initial Cork coverage, but most declined to go on record — not for lack of opinion, but because the confidential reports and unresolved scope disputes made firm conclusions hard to reach. Sanford himself argued that the information needed to settle the matter had simply been withheld.
The broader issue isn't which specific firm is at fault. It's whether the current audit ecosystem — where scope can be quietly redefined after the fact, and criticism gets absorbed into vague talk of "ongoing" confidentiality — gives anyone outside the firms a real way to verify what happened. Protocols continue to market audit badges as proof of security, users continue to rely on those badges, and when a breach occurs, the underlying evidence often stays out of reach. Cork's $12 million loss may end up mattering less for the exploit itself than for what it revealed about how little of the audit process is actually verifiable after something goes wrong.
Get new scam files the moment we publish them — usually 2–3 emails a week.