Clipper DEX Says Withdrawal Vulnerability Led to $450K Hack, Denies Private Key Leak

DeFi Defi Hack Hack
The exploit targeted two liquidity pools on December 1, affecting around 6% of its total value locked.
Author
Author
Ruholamin HaqshanasVerified
Part of the Team Since
Oct 2021
About Author

Ruholamin Haqshanas is a contributing crypto writer for CryptoNews. He is a crypto and finance journalist with over four years of experience. Ruholamin has been featured in several high-profile crypto...

Last updated: 

Decentralized exchange Clipper has revealed that a vulnerability in its withdrawal function enabled a $450,000 hack on its platform, refuting claims of a private key leak as alleged by external parties.

The platform confirmed in a post on X that the exploit targeted two liquidity pools on December 1, affecting around 6% of its total value locked.

Other pools were not impacted, and the exploit has since been resolved.

“There have been third-party claims suggesting a private key leak,” Clipper stated. “We can confirm that this is not the case and is inconsistent with the design and security architecture of Clipper.”

Clipper Disables the Exploited Function

Clipper added that the ability to withdraw using a single token—a feature that combines swaps with deposit or withdrawal transactions—has been disabled, as it was identified as the exploited function.

Earlier, Chaofan Shou, co-founder of security firm Fuzzland, suggested on X that Clipper’s hack was due to an API vulnerability, potentially allowing attackers to sign unauthorized deposit and withdrawal requests.

“During the attack, the exploit involved a deposit request that acquired pool shares using a certain amount of tokens. In the same tx, those pool shares were withdrawn, but yielding a higher quantity of tokens than originally deposited,” Shou claimed.

However, Clipper’s statement challenges this narrative, emphasizing its robust security framework.

Following the incident, Clipper paused swaps and deposits while keeping withdrawals open under specific conditions: withdrawals must be executed as a mix of all assets in the pool.

The exchange is actively tracing the stolen funds and has invited the attacker to engage in communication if willing.

The hack contributes to the $1.48 billion in crypto stolen during 2024 up to November, representing a 15% year-over-year decline, according to a report by Immunefi.

Clipper is investigating the breach and promises to provide updates.

Attacks on Major Centralized Exchanges

The recent attack on Clipper comes amid a trend of increasing attacks on centralized exchanges in 2024.

Some major incidents this year include the $235 million breach of India’s WazirX exchange in July, a $52 million hack on Singapore’s BingX in September, and a $55 million exploit of Turkey’s BtcTurk in June.

More recently, XT.com, a Seychelles-based cryptocurrency exchange, paused withdrawals following reports of a suspected $1.7 million hack.

Last week, U.S. federal prosecutors charged five individuals in connection with a sophisticated hacking operation that allegedly stole $11 million in crypto and sensitive data from individuals and companies across multiple countries.

According to court filings, the alleged hackers targeted at least 29 individuals, with one victim losing over $6.3 million in cryptocurrency after their email and digital wallets were compromised.

Prosecutors claim the group also targeted 45 companies in the U.S., Canada, India, and the United Kingdom.

Among their targets was a U.S.-based cryptocurrency exchange whose employees were tricked by fake text messages into divulging sensitive credentials.

In the Article
Bitcoin
BTC
$88,579
0.67 %
Ethereum
ETH
$2,973
0.17 %

2M+

Active Monthly Users Around the World

250+

Guides and Reviews Articles

8

Years on the Market

70

International Team Authors
editors
+72 More
At Cryptonews, we aim to make cryptocurrency, blockchain, and Web3 understandable, and information available to everyone, no matter what level you are in your investment journey. Founded in 2017, Cryptonews has been dedicated to delivering reliable, multilingual coverage of the cryptocurrency industry.

Best Crypto ICOs

Discover trending tokens still in presale — early-stage picks with potential.

Explore Our Tools

Smart tools made for everyday crypto users

Market Overview

  • 7d
  • 1m
  • 1y
Market Cap
$3,122,836,387,303
0.99
Trending Crypto

More Articles

Altcoin News
Family Offices Expand Crypto Exposure, but Volatility Clouds 2026 Outlook
Amin Ayan
Amin Ayan
2025-12-31 07:37:13
Blockchain News
Uganda’s Opposition Leader Urges Use Of Decentralized Messaging Ahead Of Election
Amin Ayan
Amin Ayan
2025-12-31 06:37:18
Crypto News in numbers
editors
Authors List + 66 More
2M+
Active Monthly Users Around the World
250+
Guides and Reviews Articles
8
Years on the Market
70
International Team Authors