Cork Protocol suffered a smart contract exploit that allowed an attacker to withdraw about $12 million from the DeFi platform. Multiple reports said the protocol halted activity and suspended affected smart contracts after the breach, as the team moved to contain the incident and assess losses.
Follow-up reporting said Cork Protocol began recovery efforts and planned to redeploy its market infrastructure after the hack. Coverage of the incident consistently identified the breach as a smart contract exploit, with the attacker extracting funds before protocol operations were paused and remediation work began.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Later follow-up reporting indicated Cork Protocol was moving ahead with redeploying its market infrastructure after the attack. This reflected an ongoing recovery phase beyond the initial suspension and response.
After the incident, Cork Protocol said it would redeploy the market/protocol and pursue recovery of the stolen funds. Follow-up coverage framed this as the project's next step toward restoring operations after the hack.
Following the exploit, Cork Protocol paused or suspended affected smart contracts and protocol operations to contain the incident. Reports published the same day and shortly after describe the shutdown as an immediate response to the hack.
An attacker exploited a smart-contract vulnerability in Cork Protocol and drained roughly $12 million in crypto assets. Multiple reports describe the incident as a protocol hack or exploit affecting Cork's markets/contracts.
6 references tracked. Mallory keeps watching after this page renders.
phemex.com
Open sourceblock-chain24.com
Open sourcephemex.com
Open sourcebits.media
Open sourceforklog.com
Open sourceincrypted.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.