OAK — OnChain Attack Knowledge

Worked example · 2024-05

Cypher Protocol Hoak insider theft from redemption fund — Solana — 2024-05

Loss
approximately $317K (~7,118 SOL at the prevailing price) extracted from the Cypher Protocol post-incident redemption fund by a pseudonymous developer operating under the handle "Hoak". The redemption fund had been established to compensate users affected by the August 2023 Cypher sub-account isolation exploit (~$1M loss; see examples/2023-08-cypher.md), and the insider extraction therefore occurred against the recovery surface of a prior incident.
Recovery
none publicly confirmed at v0.1 cutoff; Hoak publicly admitted the theft on Twitter / X on May 14, 2024, stating "I took the funds and gambled them away" — the proceeds had been gambled away on a Solana-native gambling platform before any recovery action was feasible. There is no public criminal proceeding at v0.1 cutoff; civil-recovery / restitution surface is structurally narrow because the proceeds were dissipated.
Attribution
confirmed. Hoak (pseudonymous) publicly admitted the theft on Twitter / X on May 14, 2024, stating "I took the funds and gambled them away" and apologising to affected users. Decrypt, CoinDesk, and other secondary sources documented the admission. No real-name operator identification has been publicly confirmed at v0.1 cutoff; the admission established the operator-action attribution but not the off-chain identity. Cypher Protocol's own response acknowledged the insider role and the loss but did not pursue public criminal-prosecution proceedings. The structural case is a named-pseudonymous-operator-with-self-confession attribution shape, structurally distinct from the broader pseudonymous DeFi-exploit attribution shape because the operator-action is publicly admitted by the operator.
Key teaching point
Post-incident redemption / restitution funds are themselves a custody surface that requires the same operational-governance discipline as the pre-incident protocol treasury. The Cypher case is the canonical 2024 worked example of insider abuse against the recovery surface of a prior incident. Affected users had a structural expectation that the redemption fund's governance would be at least as disciplined as the original protocol's governance; in practice, the fund's signing authority was concentrated enough that a single contributor with custodial-signing access could dissipate it. Defenders running incident-recovery operations should treat the redemption-fund custody surface as a new threat-model surface, not as a continuation of the original protocol's threat-model. Multi-sig with external-trustee participation, time-locked withdrawals, public per-disbursement transparency, and external-audit of fund-flow are the canonical defender-tooling controls; the Cypher case demonstrates that absence of these controls produces a structurally exploitable second-order incident.

OAK Techniques observed:

  • OAK-T11 (Custody and Signing Infrastructure — broad construction) — at the operator-side custodial-key abuse sub-surface. Hoak was a Cypher Protocol team member with legitimate signing authority over the redemption fund's custody surface; the theft was executed through legitimate signing under attacker intent rather than through external compromise of the keys. The structural shape is closest to OAK-T5.005 (Treasury-Management Exit) — operator-side abuse of legitimate signing authority over protocol funds — but with the structurally distinguishing feature that the funds were already-recovered restitution proceeds for a prior incident, not protocol treasury or LP funds.
  • OAK-T8.001 (Cluster Reuse) at a degenerate scale — Hoak operated under a single pseudonymous identity across the Cypher contributor surface, the on-chain signing surface, and the post-theft confessional surface (the Twitter / X admission). The cluster fingerprint is unitary; no operator-cohort attribution applies.
  • No T9 / T1 chain. The case is a custody / operational-control failure, not a smart-contract exploit or token-genesis failure. Cypher's contracts continued to operate correctly; the failure was in the operational governance of the redemption fund.

Summary

Cypher Protocol is a Solana-native decentralised futures and lending exchange that suffered a smart-contract exploit in August 2023, losing approximately $1M to a sub-account isolation flaw (see examples/2023-08-cypher.md). Following the original incident, Cypher established a post-incident redemption fund to compensate affected users from operator-side reserves and recovered assets.

In May 2024, the Cypher team disclosed that funds had been removed from the redemption fund without authorisation. On May 14, 2024, a pseudonymous developer operating under the handle "Hoak" — a Cypher Protocol contributor with legitimate signing authority over portions of the redemption fund's custody surface — publicly admitted on Twitter / X to having taken approximately $317K (~7,118 SOL at prevailing prices) from the fund and gambled the proceeds away on a Solana-native gambling platform.

Hoak's admission stated, in substance: "I took the funds and gambled them away. I have no money to return. I am sorry to the affected users." The admission was widely covered by Decrypt, CoinDesk, and other crypto-press secondary sources. Cypher Protocol acknowledged the insider role and the loss but did not pursue public criminal-prosecution proceedings; the structural recovery surface was effectively zero because the proceeds had been dissipated to a gambling platform before the disclosure.

The case is the canonical 2024 worked example of insider abuse against the recovery surface of a prior incident. Cypher's affected users — already once-victimised by the August 2023 sub-account isolation exploit — were re-victimised through the operational governance of the redemption fund itself. The structural lesson is that post-incident redemption funds are a custody surface that requires the same operational-governance discipline as the pre-incident protocol treasury, and absence of that discipline produces a structurally exploitable second-order incident.

Why this is structurally significant

The Hoak case is structurally distinct from the broader DeFi-incident corpus in three ways:

  1. The custody surface is the recovery surface of a prior incident, not the original protocol treasury. Most operator-side custody-abuse cases (T5.005-class) target protocol treasuries, LP funds, or governance-held tokens — assets that retail users may have implicit exposure to via token holdings but not explicit expectations of as restitution. The Cypher redemption fund had explicit restitution semantics: affected users had been promised compensation from this specific custody surface for harms from the August 2023 incident. Insider abuse against the redemption fund therefore produced a second-order victimisation with a structurally different harm profile from a generic treasury-exit case.

  2. The attribution shape is named-pseudonymous-self-confession. Most pseudonymous-operator cases require external forensic work to attribute on-chain actions to off-chain identities (or remain unattributed). Hoak's public Twitter / X admission collapses the attribution gap at the operator-action layer (the operator has publicly confirmed the action) without resolving the off-chain identity. This is structurally distinct from the broader OAK pseudonymous-attribution corpus and warrants a discrete attribution-strength label: confirmed at operator-action layer, pseudonymous at off-chain identity layer.

  3. The recovery surface is structurally null because of the dissipation pathway. Unlike DeFi exploits where the proceeds are routed through bridges and mixers (and may be partially recoverable via cross-chain freezing or operator-side intervention), the Hoak proceeds were dissipated to a Solana-native gambling platform — a structurally one-way value-destruction surface that produces no on-chain forensic recovery handle. Defender-side incident-response playbooks for insider-theft-with-gambling-dissipation produce structurally null recovery outcomes; the case is the canonical 2024 worked example for this dissipation pathway.

The case generalises beyond Cypher: any post-incident redemption-fund custody surface with concentrated insider signing-authority is exposed to the same threat-model. The 2024-2025 corpus has a small but growing cluster of post-incident-recovery-surface failures (Cypher 2024 Hoak, smaller cases in lending-protocol post-incident recovery) that warrant cohort-level documentation as the corpus matures.

Timeline (UTC)

When Event OAK ref
2023-08-07 Cypher Protocol smart-contract exploit drains ~$1M via sub-account isolation flaw on Solana; original incident documented at examples/2023-08-cypher.md (prior incident — T9.004 broadly construed)
2023-08 → 2024-05 Cypher establishes post-incident redemption fund from operator-side reserves and recovered assets; Hoak (pseudonymous developer / Cypher contributor) holds custodial signing authority over portions of the fund (recovery surface — latent custody concentration)
2024-05 (early) Hoak signs withdrawal transactions against the redemption fund; ~$317K (~7,118 SOL) extracted to Hoak-controlled wallets T5.005-class extraction (insider abuse of recovery custody)
2024-05 (early to mid) Extracted SOL routed to Solana-native gambling platform; proceeds dissipated through gambling activity Dissipation pathway — structurally one-way
2024-05-14 Hoak publicly admits on Twitter / X: "I took the funds and gambled them away"; Decrypt, CoinDesk publish coverage of the admission Self-confession — confirmed at operator-action layer
2024-05 onward Cypher Protocol acknowledges the insider role and the loss; affected users notified; no public criminal-prosecution proceedings (defender response — limited)
2024-05 → 2026 Hoak's off-chain identity remains undisclosed publicly; recovery surface effectively zero due to dissipation pathway (continuing forensic surface — null recovery)

What defenders observed

  • Pre-event (custody-concentration layer): the redemption-fund signing authority was concentrated enough that a single contributor with custodial-signing access could withdraw $317K in one operation. The structural pre-condition was the absence of multi-sig with external-trustee participation, time-locked withdrawals, and public per-disbursement transparency. Defender lesson: post-incident redemption-fund custody architecture should default to stronger governance than the pre-incident protocol treasury, not equal-or-weaker. Affected users have explicit expectations of redemption-fund integrity that exceed their implicit expectations of protocol-treasury integrity.
  • At-event (extraction-signal layer): the extraction was on-chain observable in real time — withdrawals from the redemption fund's custody addresses to Hoak-controlled wallets, then onward routing to the gambling platform. Cypher's monitoring stack did not (per public record) generate a real-time alert distinguishing legitimate redemption-disbursement from insider-theft. Defender lesson: redemption-fund custody monitoring should include per-disbursement-purpose categorisation; a withdrawal whose destination is not on a published list of approved recipient addresses should produce a discrete alert at signing-time.
  • At-event (dissipation-pathway layer): the Hoak proceeds were routed to a Solana-native gambling platform within hours / days of extraction. Gambling-platform routing is a structurally one-way value-destruction surface — the platform's own custody surface absorbs the value and emits residual house-edge-bounded payouts back to the operator. Defender lesson: insider-theft cases involving gambling-platform dissipation produce structurally null recovery surfaces; the recovery-window-closure dynamic for these cases is zero-recovery-from-the-extraction-event, not a function of cross-chain laundering speed.
  • Post-event (self-confession layer): Hoak's Twitter / X admission collapsed the attribution gap at the operator-action layer. The admission is structurally similar to the Mango Markets Eisenberg "profitable trading strategy" admission (October 2022, see examples/2022-10-mango-markets.md) but operates in a different attribution-shape: Eisenberg's admission preceded his real-name identification; Hoak's admission is paired with continued pseudonymity. Defender lesson: self-confession is a discrete attribution-strength signal that warrants its own label; the operator-action layer can be confirmed while the off-chain identity layer remains pseudonymous.
  • Post-event (recovery-action-surface layer): Cypher Protocol did not pursue public criminal-prosecution proceedings against Hoak; the structural reason is the combination of pseudonymous off-chain identity + dissipation-pathway null recovery + operator-self-confession (which closes the attribution gap but does not produce recoverable assets). Defender lesson: when the dissipation pathway is structurally one-way, criminal-prosecution is a public-deterrence surface rather than a recovery surface; the operator-side decision whether to pursue prosecution is a separate calculation from the recovery-action calculation.

What this example tells contributors writing future Technique pages

  • Post-incident redemption / restitution funds are a discrete custody surface. Future T11 / T5.005-adjacent worked examples should preserve the substrate distinction: protocol treasury (most T5.005 cases), recovered-assets pre-distribution custody, and post-incident redemption funds are three structurally distinct sub-surfaces with structurally different harm profiles. Hoak / Cypher is the canonical 2024 worked example for the redemption-fund sub-surface.
  • Self-confession-with-pseudonymity is a discrete attribution-strength shape. Future contributors writing pseudonymous-operator cases with public self-confession should use the explicit framing "confirmed at operator-action layer, pseudonymous at off-chain identity layer" and resist collapsing the attribution into a generic pseudonymous or inferred-strong label.
  • Gambling-platform dissipation pathways produce structurally null recovery surfaces. Future incident worked-examples involving gambling-platform routing should record the dissipation pathway as a first-class observable and treat the recovery surface as structurally bounded at zero. The recovery-rate documentation (where OAK preserves bounty-mediated, regulator-mediated, vendor-mediated recovery as distinct outcome categories) should add a dissipation-pathway-bounded-zero-recovery outcome category.
  • The operator-side decision to publicly disclose insider-theft is a defender-tooling-positive signal. Cypher's acknowledgement of the insider role enables the broader defender-cohort to learn from the case. Future contributors writing operator-disclosure cases should preserve this transparency as a discrete observable distinct from the operator's recovery-action decision.
  • The relationship between original-incident scale and recovery-incident scale is structurally informative. Cypher's original incident was ~$1M; the recovery-incident was ~$317K, or roughly one-third of the original scale. Defenders should not assume that recovery-fund risk is bounded at "small fraction of original scale" — the redemption-fund custody surface is a discrete threat surface whose scale is bounded by the redemption fund's size, not by the original incident's scale.

Public references

Discussion

The Cypher Hoak case is OAK's canonical 2024 worked example for insider abuse of post-incident redemption-fund custody. The case sits at the intersection of T11 (custody and signing — broadly construed at the operational-governance layer), T5.005 (treasury-management exit — extended to redemption-fund-management exit), and a discrete attribution-shape (confirmed at operator-action layer, pseudonymous at off-chain identity layer).

The structural distinguishing feature of the case is the second-order victimisation pattern — affected users were already once-victimised by the August 2023 Cypher sub-account isolation exploit, and the redemption-fund insider-theft re-victimised them through the operational governance of the recovery surface itself. This is structurally distinct from the broader DeFi-exploit corpus where insider-theft is typically against the original protocol treasury, not against the redemption surface for a prior incident.

For OAK's broader cohort coverage, this case + the 2023-08 Cypher original incident (examples/2023-08-cypher.md) collectively establish that post-incident recovery surfaces are themselves threat-model surfaces that warrant distinct operational-governance discipline. Future post-incident-recovery surfaces — Loopscale's negotiated-recovery proceeds (examples/2025-04-loopscale.md), KiloEx's bounty-recovery proceeds (examples/2025-04-kiloex.md), the broader 2024-2025 cohort of bounty-mediated-recovery cases — should be analysed for their own custody / signing-governance discipline.

The case also generalises beyond Solana. Any chain's DeFi cohort that produces post-incident redemption funds is exposed to the same structural threat-model. The 2024-2025 corpus has not yet produced a comparably-publicised cross-chain case, but the structural shape is generic; defenders running incident-recovery operations on any chain should treat the redemption-fund custody surface as a first-class threat-modelling surface. The Hoak admission produces the public-record forensic anchor that lets OAK document the class; future contributors should preserve the framing for cross-chain analogues if and when they materialise.

The attribution-shape — confirmed-at-operator-action-layer + pseudonymous-at-off-chain-identity-layer — is potentially recurrent across the 2024-2025 corpus (smaller-scale insider-theft cases exist but are less publicised). OAK's attribution-strength taxonomy at v0.1 does not cleanly accommodate this shape; the v0.x development should add the discrete label and document the cohort's methodology for distinguishing self-confession-with-pseudonymity from generic-pseudonymity.

Techniques demonstrated (3)