As a result of two attacks, Pike Finance lost almost $2 million

Father

Professional
Messages
2,394
Reputation
4
Reaction score
544
Points
113
On April 30, the attackers attacked the DeFi protocol of Pike Finance and withdrew 99,970 ARB, 64,126 OP and 479 ETH for a total amount of about $1.68 million.

Attention Users:

On the 30th of April 2024, the Pike Beta protocol was exploited for 99,970.48 ARB, 64,126 OP and 479.39 ETH.

This exploit is related to the initial USDC vulnerability that was reported last week on the 26th of April.

In order to pause the protocol, the spoke…
— Pike (@PikeFinance) May 1, 2024

A few days before the incident, on April 26, hackers took advantage of another exploit, stealing approximately $300,000 in USDC.

According to the Pike developers, due to an error in the initializing smart contract, criminals managed to bypass the peripheral security system without administrator access and as a result withdraw funds.

The protocol team offered a reward of 20% of the stolen assets for their return or information about the criminal.

Commenting on the first incident, the company noted that the vulnerability is related to weak security measures in the USDC transfer management system using the CCTP protocol.

"Insufficient security allowed attackers to manipulate the recipient's address and amounts that were treated as valid by the Pike protocol," the report says.

The protocol has been temporarily suspended at the smart contract level. The project team has launched an investigation in collaboration with several cross-chain protocols and Binance.
 
Top