Pike Finance Hack
What happened
Pike Finance's first April 2024 exploit drained approximately $300,000 from its USDC pool on Arbitrum. The project attributed the incident to a forged message in its CCTP integration. An emergency upgrade added pausing functionality, but introduced the storage-layout issue exploited in a separate incident later that month.
Pike's message-handling integration accepted a forged cross-chain message. The reported failure was in Pike's integration; the incident does not establish a vulnerability in Circle's CCTP protocol.
Case & protocol details
How it happened
- The attacker targeted Pike's cross-chain USDC handling with a forged message, according to the project account reported by CertiK.
- The accepted message enabled withdrawals from the Arbitrum pool.
- Pike upgraded its contracts to add a pause capability and halted operations.
- That upgrade introduced a separate storage-layout vulnerability, which was exploited on April 30.
Evidence & learning
Sources and on-chain records
- report Report twitter.com
- report Report twitter.com
- analysis Pike Finance Incident Analysis certik.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.