Pike Finance Hack

REPORTED LOSS $300K
Low Other

What happened

Pike Finance's first April 2024 exploit drained approximately $300,000 from its USDC pool on Arbitrum. The project attributed the incident to a forged message in its CCTP integration. An emergency upgrade added pausing functionality, but introduced the storage-layout issue exploited in a separate incident later that month.

Technical Root Cause

Pike's message-handling integration accepted a forged cross-chain message. The reported failure was in Pike's integration; the incident does not establish a vulnerability in Circle's CCTP protocol.

Case & protocol details

Classification Bridge
Protocol Type Exploit/Other
Official Website www.pike.finance/
Protocol Twitter/X @PikeFinance

How it happened

  1. The attacker targeted Pike's cross-chain USDC handling with a forged message, according to the project account reported by CertiK.
  2. The accepted message enabled withdrawals from the Arbitrum pool.
  3. Pike upgraded its contracts to add a pause capability and halted operations.
  4. That upgrade introduced a separate storage-layout vulnerability, which was exploited on April 30.

Evidence & learning

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.