We collect cookies to analyze our website traffic and performance; we never collect any personal data.Cookies Policy
Accept
Michigan Post
Search
  • Home
  • Trending
  • Michigan
  • World
  • Politics
  • Top Story
  • Business
    • Business
    • Economics
    • Real Estate
    • Startups
    • Autos
    • Crypto & Web 3
  • Tech
  • Lifestyle
    • Lifestyle
    • Food
    • Beauty
    • Art & Books
  • Health
  • Sports
  • Entertainment
  • Education
Reading: ‘Sherlock missed it’: Cork hacker slams audit corporations in on-chain messages
Share
Font ResizerAa
Michigan PostMichigan Post
Search
  • Home
  • Trending
  • Michigan
  • World
  • Politics
  • Top Story
  • Business
    • Business
    • Economics
    • Real Estate
    • Startups
    • Autos
    • Crypto & Web 3
  • Tech
  • Lifestyle
    • Lifestyle
    • Food
    • Beauty
    • Art & Books
  • Health
  • Sports
  • Entertainment
  • Education
© 2024 | The Michigan Post | All Rights Reserved.
Michigan Post > Blog > Crypto & Web 3 > ‘Sherlock missed it’: Cork hacker slams audit corporations in on-chain messages
Crypto & Web 3

‘Sherlock missed it’: Cork hacker slams audit corporations in on-chain messages

By Editorial Board Published June 20, 2025 4 Min Read
Share
‘Sherlock missed it’: Cork hacker slams audit corporations in on-chain messages

The hacker behind final month’s $12 million exploit of Cork Protocol has weighed in on a debate between squabbling crypto safety audit corporations.

Messages left on-chain from the hacker’s deal with seem to set the document straight concerning the root causes of the incident and lament the clout-chasing of some auditors within the wake of such assaults.

The feedback got here in response to a put up made on Wednesday by Jack Sanford, CEO of safety audit agency Sherlock. Sandford accuses rivals Spearbit and Cantina of lacking the vulnerability and masking up their failures.

Within the first message, the hacker states “sherlock missed it.” Minutes later, they moved 4,530 ether — at present valued at $11.6 million — to a brand new deal with.

The talk

On Might 28, a16z-backed Cork Protocol introduced a “security incident affecting the wstETH:weETH market” and a short lived pause of all markets. The autopsy report that adopted said that “the attacker exploited an access control vulnerability in the Cork Hook, which none of our audits flagged.”

Nevertheless, Sanford’s put up factors to the commit hashes submitted in varied auditors’ stories, as proof that the supposed vulnerability didn’t fall inside their scope.

He then highlights Cantina’s failure to offer such hashes and the way Spearbit is but to launch their report publicly, regardless of it being overdue.

Within the preliminary message left by the hacker, they seemingly appropriate the assumed root reason for the exploit, stating “uniswap hook is not problem,” pouring chilly water on the concept the bug was solely current in later variations of the code.

The dressing-down

The attacker then adopted up with “a really big bombshell,” written in Estonian, wherein they seem to contradict themselves by stating that “Sherlock didn’t miss it,” and that “there are many ways to take DS, not just the Uniswap hook.”

He warns that every one corporations that missed the preliminary bug “should not be trusted.”

Considerably satirically, the hacker’s predominant beef seems to be with blockchain safety corporations that capitalize on the eye introduced by hacks.

Companies that “failed to detect the real problem” of their assessments allegedly embody Dedaub, Three Sigma, Halborn, Blocksec, and plenty of others.

The hacker says corporations that search for promotion by releasing evaluation earlier than the official autopsy “are not recommended.”

In a closing message, despatched hours later, the hacker doubles down on its assault on audit corporations that “write nonsense about bugs to promote their brands and profit from the efforts of others.”

They name out Dedaub’s Neville Grech specifically, accusing him of “promoting your brands by analyzing bugs that you can’t detect yourself.”

The Cork Protocol perpetrator?

The content material of those later messages suggests the hacker could be a member of the safety researcher neighborhood with an axe to grind. Others actually appear to suppose so.

So he steals 12M, observes the entire drama AND then feedback on it 😅

I’m questioning who that’s now .. the possibility could be very excessive everyone knows him https://t.co/spm4NNTTvd

— CharlesWang (@0xCharlesWang) June 19, 2025

In that case, it wouldn’t be the primary time suspicions had been raised about a longtime determine within the scene being a blackhat. Earlier this 12 months, Nick L. Franklin, a prolific researcher who claimed to have “analyzed every major blockchain hack,” was linked to the $50 million Radiant Capital hack.

TAGGED:auditCorkfirmshackermessagesmissedonchainSherlockslams
Share This Article
Facebook Twitter Email Copy Link Print

HOT NEWS

How did your MP vote on the assisted dying invoice?

How did your MP vote on the assisted dying invoice?

Politics
June 20, 2025
East Lansing providing cooling facilities for warmth aid

East Lansing providing cooling facilities for warmth aid

LANSING, Mich. (WLNS) -- The town of East Lansing shall be opening cooling facilities for…

June 20, 2025
Manny Pacquiao faces welterweight champ Mario Barrios, however his actual problem can be time

Manny Pacquiao faces welterweight champ Mario Barrios, however his actual problem can be time

Mauricio Sulaiman smiled as he recalled the decision throughout which a boxing legend requested him…

June 20, 2025
Bayesian: Sunken British superyacht emerges from seabed

Bayesian: Sunken British superyacht emerges from seabed

Salvage groups have managed to lift a British superyacht which capsized and sank 10 months…

June 20, 2025
Palestine Motion to be banned after break in at RAF base, Sky Information understands

Palestine Motion to be banned after break in at RAF base, Sky Information understands

Yvette Cooper is making ready a written ministerial assertion which might make turning into a…

June 20, 2025

YOU MAY ALSO LIKE

From memes to biometrics: Reddit may quickly require eye scans

World, the Sam Altman-owned iris scanning agency, is reportedly in talks with Reddit about introducing the eyeball-based World ID system…

Crypto & Web 3
June 20, 2025

5 methods to utilizing investor funds to purchase bitcoin

Michael Saylor has made no secret of his bitcoin (BTC)-accumulating technique. By issuing bonds and securities like ATMs, Strike, Strife,…

Crypto & Web 3
June 20, 2025

Crypto on line casino Luckio beneath fireplace for shady code, $500K influencer offers

A crypto on line casino that has been branded “a terrible idea for several reasons” is reportedly paying crypto influencers…

Crypto & Web 3
June 20, 2025

What occurred to WBTC on TRON?

On August 9 final 12 months, a press launch introduced that Justin Solar and BiT International had been getting concerned…

Crypto & Web 3
June 19, 2025

Welcome to Michigan Post, an esteemed publication of the Enspirers News Group. As a beacon of excellence in journalism, Michigan Post is committed to delivering unfiltered and comprehensive news coverage on World News, Politics, Business, Tech, and beyond.

Company

  • About Us
  • Newsroom Policies & Standards
  • Diversity & Inclusion
  • Careers
  • Media & Community Relations
  • Accessibility Statement

Contact Us

  • Contact Us
  • Contact Customer Care
  • Advertise
  • Licensing & Syndication
  • Request a Correction
  • Contact the Newsroom
  • Send a News Tip
  • Report a Vulnerability

Term of Use

  • Digital Products Terms of Sale
  • Terms of Service
  • Privacy Policy
  • Cookie Settings
  • Submissions & Discussion Policy
  • RSS Terms of Service
  • Ad Choices

© 2024 | The Michigan Post | All Rights Reserved

Welcome Back!

Sign in to your account

Lost your password?