T
iTokenly

Pike Finance V1 hack — April 2024

Verified — 6 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedApril 30, 2024
Target typeLending protocol
Loss$1,684,506Price at time of incident
MethodAccess control flawStorage-layout collision introduced by an emergency upgrade. New pause-related state variables shifted the spoke contracts' storage, overwriting the slot holding the `initialized` flag, so the contracts reported themselves uninitialised. The attacker called initialize() again, took the privileged role, then used upgradeToAndCall() to install a malicious implementation and withdraw user deposits.
ChainsEthereum, Arbitrum, Optimism
Audited beforehandOtterSec
OutcomeUnresolved

What happened

Pike Finance ran a cross-chain lending protocol on Ethereum, Arbitrum and Optimism. On 26 April 2024 an attacker forged a Circle CCTP message and took about $299,000 in USDC, a flaw Pike later said its auditing partner OtterSec had already identified and that the team had not fixed in time. That earlier incident is not counted in the figure recorded here.

The larger loss came four days later and was caused by the fix. To pause the protocol Pike upgraded its spoke contracts and pulled in an additional dependency. The new pause-related state variables shifted the contracts' storage layout and the slot holding the initialized flag was overwritten, so the contracts behaved as though they had never been initialised. On 30 April 2024 an attacker called initialize() again, granted itself the privileged role, then used upgradeToAndCall() to install its own implementation and withdraw deposits.

Pike stated the protocol was drained of 99,970.48 ARB, 64,126 OP and 479.39 ETH, figures Merkle Science independently confirmed. CertiK itemised the 30 April losses as $1,433,977.23 on Ethereum, $150,458.95 on Optimism and $100,070 on Arbitrum, a total of $1,684,506. Reporting rounded this variously to $1.6 million and $1.7 million; the itemised CertiK sum is used here. Merkle Science traced the proceeds being consolidated on Ethereum, with 562 ETH sent into the privacy protocol RAILGUN.

Pike initially described the incident as related to a USDC vulnerability, then retracted that, saying the fault lay in its own integration of third-party services rather than in Circle's product. It offered a 20 percent bounty for the return of the funds, which was not taken up, and began refunding some pre-sale deposits. No completed reimbursement of affected lenders could be verified from published sources.

Sources

  1. Pike FinancePrimary · retrieved 2026-08-01
  2. CertiKSecondary · retrieved 2026-08-01
  3. Merkle ScienceSecondary · retrieved 2026-08-01
  4. CointelegraphSecondary · retrieved 2026-08-01
  5. HalbornSecondary · retrieved 2026-08-01
  6. CryptopolitanSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Pike Finance V1 hack — April 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/pike-finance-v1
https://itokenly.com/hacks/pike-finance-v1

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.