Pike V1 Hack
What happened
On April 30, 2024, Pike Beta protocol suffered an exploit resulting in the loss of 99,970.48 ARB, 64,126 OP, and 479.39 ETH, totaling over $1.6 million. The attack was related to a vulnerability initially reported on April 26 concerning USDC, prompting protocol upgrades that inadvertently introduced new variables and storage misalignment, allowing attackers to withdraw funds.
Pike is a liquidity market facilitating lending and borrowing using native assets directly on their respective blockchains, without wrapping or cross-chain transfers. The exploit exploited a vulnerability introduced during protocol upgrades aimed at addressing an earlier USDC vulnerability. The attacker leveraged an upgrade function to insert their address into the protocol's active variable, allowing them to bypass admin access and withdraw funds.
Attacker Address: 0x19066f74…D89E23
Attacker Contract: 0x1da4Bc59…C47fbD
Victim Contract: 0xFC7599cf…d2F063
Optimism Transaction: https://optimistic.etherscan.io/address/0x19066f74…d89e23
Arbitrum Transaction: https://arbiscan.io/address/0x19066f74…D89E23
Ethereum Transaction: https://etherscan.io/tx/0xe2912b8b…e66431
Case & protocol details
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report twitter.com
- analysis Website reference quillaudits.medium.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.