{"investigation":{"slug":"pickle","entity_name":"Pickle Finance","trust_score":10,"severity_base":null,"score_modifier":-8,"confidence":0.85,"status":"published","content_type":"investigation","summary":"Pickle Finance was an Ethereum-based DeFi yield aggregator launched in September 2020 that suffered a critical smart contract exploit on November 21, 2020, resulting in the theft of approximately 19.76 million DAI (roughly $19.7 million) from its pDAI PickleJar. The exploit, known as the 'Evil Jar Attack,' combined three design flaws in unaudited contract code and led to a 50% collapse in the PICKLE token price, with hack proceeds later laundered through Tornado Cash. The protocol subsequently merged with Yearn Finance but never meaningfully recovered; it officially announced its shutdown in 2025 with the UI disabled on October 1, 2025.","sections":[{"content":"Pickle Finance launched in September 2020 during the height of the DeFi yield farming boom on Ethereum. The protocol offered two primary products: Pickle Jars (pJars), which are yield-optimizing vaults that auto-compound users' liquidity provider positions across platforms such as Curve, Sushi, and Uniswap; and Pickle Farms, liquidity mining pools where users could earn the native PICKLE governance token. The PICKLE token could be staked as DILL to earn a share of protocol revenues and boost farm APY. The project was founded by four pseudonymous developers primarily represented by an individual using the alias 'Larry the Cucumber,' a reference to a VeggieTales character. Two other developers, '0xPenguin' and 'BigBrainBriner,' departed in December 2020. A fourth developer known as 'Rick' left the project in its early stages. The fully pseudonymous team structure meant no developer accountability could be established in the event of a security failure. At its peak in late 2020, the protocol accumulated a total value locked (TVL) of approximately $140 million.","heading":"Background and Launch","sources":[{"url":"https://cryptotesters.com/review/what-is-pickle-finance","name":"cryptotesters.com","type":"other","credibility":3},{"url":"https://chainstack.com/pickle-finance-on-chainstack-accelerating-growth-into-new-networks/","name":"chainstack.com","type":"other","credibility":3},{"url":"https://docs.pickle.finance","name":"docs.pickle.finance","type":"other","credibility":3}],"severity":"medium"},{"content":"On November 21, 2020, at approximately 18:37 UTC, a sophisticated attacker exploited multiple design flaws in Pickle Finance's ControllerV4 smart contract and drained 19,759,355 DAI from the pDAI PickleJar — approximately $19.7 million at the time of the attack. Security researchers characterized this as one of the most technically complex DeFi exploits to that point, combining three distinct vulnerabilities in a chained attack sequence. The first vulnerability was an unvalidated jar check in the swapExactJarForJar function, which failed to verify whether jars passed as arguments were legitimate whitelisted Pickle contracts. The second was a call injection flaw in the CurveProxyLogic contract's add_liquidity function, which was constructed from user-controlled values and permitted arbitrary function execution. The third was a logic flaw in the pDAI Jar's strategy that classified cDAI — the protocol's primary deposit asset — as extractable 'dust,' allowing the attacker to withdraw approximately 19 million cDAI. The attacker executed the exploit in four stages: first transferring value from StrategyCmpDAIV2 to the pDAI Jar using the unvalidated swap function; second calling pDAI.earn three times to deposit 19 million cDAI; third injecting CurveProxyLogic as a target through a fake 'EvilJar' contract; and fourth using the call injection to execute a withdrawal function that extracted the cDAI classified as dust. Critically, the exploited ControllerV4 contract was added to the protocol on October 23, 2020 — three days after the most recent security audit by Haechi concluded on October 20, 2020 — meaning the vulnerable code was never reviewed by any auditor. The multisig governance timelock required a 12-hour delay to act, and the only keyholder who could bypass this was unavailable at the time of the attack, delaying the emergency response. A white-hat team drawn from Stake Capital, Yearn Finance, and other developers coordinated to patch the vulnerability and secure approximately $50 million in remaining assets still at risk.","heading":"November 2020 Exploit: The Evil Jar Attack (Critical)","sources":[{"url":"https://rekt.news/pickle-finance-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-defi-protocol-pickle-finance-hack-nov-2020","name":"halborn.com","type":"other","credibility":3},{"url":"https://picklefinance.medium.com/pickle-was-hacked-and-there-has-been-a-loss-of-funds-414b99969c29","name":"picklefinance.medium.com","type":"other","credibility":3},{"url":"https://decrypt.co/49149/pickle-finance-hack","name":"decrypt.co","type":"other","credibility":3},{"url":"https://www.nasdaq.com/articles/defi-protocol-pickle-finance-token-loses-almost-half-its-value-after-$19.7m-hack-2020-11","name":"nasdaq.com","type":"other","credibility":3},{"url":"https://github.com/banteg/evil-jar","name":"github.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Two audits were completed prior to the exploit: one by MixBytes on October 3, 2020, and one by Haechi on October 20, 2020. However, both audits covered ControllerV3 and did not include ControllerV4 or the swapExactJarForJar function, which was deployed on October 23, 2020 — after both audits were completed. Haechi subsequently clarified that the attack was carried out against a newly created smart contract outside the scope of their review. The practice of deploying new, unaudited contract logic to a protocol holding tens of millions of dollars in user funds represents a significant security governance failure. The incident became a frequently cited case study in the necessity of continuous, rolling security audits for DeFi protocols that ship code rapidly. Pickle Finance's own documentation states that timelocks and multisig governance were in place, but the governance structure was insufficient to respond to an emergency in real time, as the critical keyholder was unreachable when the attack occurred.","heading":"Audit Failures and Security Governance","sources":[{"url":"https://github.com/pickle-finance/protocol/blob/master/audits/Haechi_Audit.pdf","name":"github.com","type":"other","credibility":3},{"url":"https://docs.pickle.finance/security/audits-and-timelock/smart-contract-audits","name":"docs.pickle.finance","type":"other","credibility":3},{"url":"https://rekt.news/pickle-finance-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://beincrypto.com/pickle-finance-postmortem-details-how-19-million-dai-was-pilfered/","name":"beincrypto.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, Pickle Finance issued the CORNICHON token to track losses stemming from the attack, with tokens minted against a snapshot of balances at the time of the exploit and distributed proportionally to affected depositors. However, how and whether CORNICHON would accrue real economic value was not specified by the team at launch, leaving the token's role in actual compensation unclear. A claim was filed with Cover Protocol, a decentralized insurance platform, which ultimately approved a 100% payout ratio on covered policies. However, the total Cover Protocol payout was approximately 282,035 DAI — covering only a small fraction of the $19.7 million loss. The vast majority of affected depositors received no meaningful restitution. The Yearn Finance merger announced days after the hack was partly framed as a path to eventual compensation, but no formal restitution mechanism covering the full loss was established.","heading":"Victim Compensation and Insurance","sources":[{"url":"https://coverprotocol.medium.com/11-21-20-claim-outcome-for-pickle-finance-aa2fcc56cb7c","name":"coverprotocol.medium.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/decentralized-insurance-protocol-cover-holds-vote-to-cover-pickle-hack","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://beincrypto.com/pickle-finance-loses-20-million-in-latest-defi-exploit/","name":"beincrypto.com","type":"other","credibility":3}],"severity":"medium"},{"content":"According to on-chain analytics reported by PeckShieldAlert, the proceeds from the November 2020 Pickle Finance exploit were subsequently laundered through Tornado Cash, an Ethereum-based coin mixer. Specifically, 1,800 ETH — representing a portion of the converted stolen funds — was moved through Tornado Cash in batches of 100 ETH. Tornado Cash was later sanctioned by the U.S. Treasury's Office of Foreign Assets Control (OFAC) in August 2022 for its role in laundering funds on behalf of the North Korea-linked Lazarus Group and other illicit actors. The use of Tornado Cash to launder the Pickle Finance proceeds substantially reduced the likelihood of fund recovery or attacker identification. No arrests or identifications of the attacker have been publicly reported.","heading":"Stolen Funds Laundering via Tornado Cash","sources":[{"url":"https://cryptonews.net/news/security/6222707/","name":"cryptonews.net","type":"other","credibility":3},{"url":"https://en.ethereumworldnews.com/2020s-pickle-finance-hackers-launder-1800-ethereum-through-tornado-cash/","name":"en.ethereumworldnews.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On November 24, 2020 — three days after the exploit — Yearn Finance announced what was characterized as DeFi's first merger, absorbing Pickle Finance. The arrangement involved Pickle developers joining Yearn as strategists, with PICKLE token used as a reward for staking Yearn vault tokens in Pickle gauges. Two new tokens, DILL and CORNICHON, were introduced as part of the post-merger structure. The merger drew governance criticism from both communities: neither the Pickle DAO nor the Yearn community held a formal governance vote prior to the announcement. A Yearn team member defended the arrangement by arguing that creating new vaults is permissionless and therefore does not require a vote, but critics argued this reasoning did not apply to the full scope of the merger. A retroactive governance vote was subsequently posted on the Yearn governance forum. The merger ultimately did not result in a sustained recovery in TVL or user activity for Pickle Finance.","heading":"Yearn Finance Merger and Governance Controversy","sources":[{"url":"https://beincrypto.com/yearn-finance-consumes-pickle-without-governance-vote/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2020/11/24/yearning-for-pickle-two-defi-protocols-merge","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/yearn-finance-absorbs-pickle-to-boost-defi-rewards","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://gov.yearn.finance/t/retroactive-vote-on-pickle-yearn-ferments/8306","name":"gov.yearn.finance","type":"other","credibility":3}],"severity":"medium"},{"content":"The PICKLE token fell approximately 50% on the day of the exploit, declining from roughly $23 to $10.17. The token reached an all-time high of approximately $34.35 on February 9, 2021 — a brief speculative recovery likely tied to post-merger sentiment — before entering a prolonged decline. As of 2025, PICKLE traded more than 99.68% below its all-time high, at fractions of a cent. TVL, which peaked at approximately $140 million in late 2020, declined to approximately $6 million by the time of the protocol's sunset announcement. The bear market of 2022 and an increasingly competitive yield aggregator landscape were cited by the team as contributing factors to the protocol's failure to attract meaningful deposits after the hack.","heading":"Token Price Collapse and Protocol Decline","sources":[{"url":"https://coinmarketcap.com/currencies/pickle-finance/","name":"coinmarketcap.com","type":"other","credibility":3},{"url":"https://www.coingecko.com/en/coins/pickle-finance","name":"coingecko.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/pickle","name":"defillama.com","type":"other","credibility":3},{"url":"https://picklefinance.medium.com/pickle-finance-closing-the-jar-7996fe4ecd94","name":"picklefinance.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"In 2025, Pickle Finance announced it was sunsetting after nearly five years of operation. The protocol's UI was disabled on October 1, 2025, though the underlying smart contracts remain functional indefinitely for direct interaction. The remaining treasury of 170,280 USDC was distributed proportionally to eligible PICKLE and DILL token holders across multiple blockchains, with eligibility requiring an aggregate balance exceeding 300 PICKLE tokens as of a June 10, 2025 snapshot. Users who had not withdrawn funds from Pickle Jars before the UI shutdown were required to interact directly with the smart contracts to retrieve their assets.","heading":"Protocol Shutdown (2025)","sources":[{"url":"https://picklefinance.medium.com/pickle-finance-closing-the-jar-7996fe4ecd94","name":"picklefinance.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Pickle Finance was built and operated entirely by pseudonymous developers. The primary public representative of the protocol, 'Larry the Cucumber,' remained anonymous throughout the project's life. Two of the four founding developers, '0xPenguin' and 'BigBrainBriner,' stepped away from the project in December 2020, shortly after the exploit. A third developer, 'Rick,' had left earlier. The fully anonymous team structure means that no formal legal accountability for the $19.7 million loss was possible. This structure is common in DeFi but represents an elevated risk factor for depositors, particularly when combined with unaudited code deployments and inadequate emergency response mechanisms.","heading":"Pseudonymous Team and Accountability Risk","sources":[{"url":"https://cryptotesters.com/review/what-is-pickle-finance","name":"cryptotesters.com","type":"other","credibility":3},{"url":"https://www.publish0x.com/arkemmus-blog/pickle-finance-defi-with-a-cucumber-flavour-xgpnznp","name":"publish0x.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2020-09","event":"Pickle Finance launches on Ethereum as a yield aggregator offering Pickle Jars and Pickle Farms.","source":"","date_original":"2020-09-01"},{"date":"2020-10-03","event":"MixBytes completes a security audit of Pickle Finance smart contracts (ControllerV3 scope).","source":""},{"date":"2020-10-20","event":"Haechi completes a security audit of Pickle Finance smart contracts (ControllerV3 scope).","source":""},{"date":"2020-10-23","event":"ControllerV4 and the swapExactJarForJar function are deployed to production without undergoing a security audit.","source":""},{"date":"2020-11-21","event":"Attacker exploits three chained vulnerabilities in ControllerV4 and drains 19,759,355 DAI from the pDAI PickleJar in the Evil Jar Attack. PICKLE token falls approximately 50%.","source":""},{"date":"2020-11-22","event":"Pickle Finance executes an emergency timelock transaction at 15:15 UTC to revoke the exploited proxy logic from the Controller. White-hat team secures remaining $50 million in assets. Official postmortem published.","source":""},{"date":"2020-11-24","event":"Yearn Finance announces merger with Pickle Finance, characterized as DeFi's first M&A deal, without a prior community governance vote from either protocol.","source":""},{"date":"2020-11-25","event":"PICKLE token surges to approximately $27 on merger announcement.","source":""},{"date":"2020-12","event":"Cover Protocol approves Pickle Finance insurance claim; 282,035 DAI paid out, covering less than 2% of total losses.","source":"","date_original":"2020-12-01"},{"date":"2020-12","event":"Developers 0xPenguin and BigBrainBriner depart Pickle Finance.","source":"","date_original":"2020-12-01"},{"date":"2021-02-09","event":"PICKLE token reaches all-time high of approximately $34.35 before entering a sustained decline.","source":""},{"date":"2021","event":"Stolen funds from the November 2020 exploit are laundered through Tornado Cash in batches of 100 ETH; total of 1,800 ETH moved through the mixer according to PeckShieldAlert.","source":"","date_original":"2021-01-01"},{"date":"2022","event":"Bear market conditions sharply reduce Pickle Finance TVL and user activity; the protocol struggles to compete in the saturated yield aggregator market.","source":"","date_original":"2022-01-01"},{"date":"2025-06-10","event":"Pickle Finance takes a snapshot of PICKLE and DILL holders for treasury distribution eligibility (minimum 300 PICKLE required).","source":""},{"date":"2025-10","event":"Pickle Finance UI is disabled. Protocol officially sunsets after approximately five years. Remaining 170,280 USDC treasury distributed to eligible token holders.","source":"","date_original":"2025-10-01"}],"sources_used":[{"url":"https://cryptotesters.com/review/what-is-pickle-finance","name":"cryptotesters.com","type":"other","archive_url":"http://web.archive.org/web/20251209204539/https://cryptotesters.com/review/what-is-pickle-finance","credibility":3,"archive_timestamp":"2025-12-09T20:45:39+00:00"},{"url":"https://chainstack.com/pickle-finance-on-chainstack-accelerating-growth-into-new-networks/","name":"chainstack.com","type":"other","archive_url":"https://web.archive.org/web/20260830203124/https://chainstack.com/pickle-finance-on-chainstack-accelerating-growth-into-new-networks/","credibility":3,"archive_timestamp":"2026-08-30T20:31:24+00:00"},{"url":"https://docs.pickle.finance","name":"docs.pickle.finance","type":"other","archive_url":"http://web.archive.org/web/20260421081036/https://docs.pickle.finance/","credibility":3,"archive_timestamp":"2026-04-21T08:10:36+00:00"},{"url":"https://rekt.news/pickle-finance-rekt","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260313112213/https://rekt.news/pickle-finance-rekt","credibility":3,"archive_timestamp":"2026-03-13T11:22:13+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-defi-protocol-pickle-finance-hack-nov-2020","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260609210504/https://www.halborn.com/blog/post/explained-the-defi-protocol-pickle-finance-hack-nov-2020","credibility":3,"archive_timestamp":"2026-06-09T21:05:04+00:00"},{"url":"https://picklefinance.medium.com/pickle-was-hacked-and-there-has-been-a-loss-of-funds-414b99969c29","name":"picklefinance.medium.com","type":"other","archive_url":"http://web.archive.org/web/20251007150621/https://picklefinance.medium.com/pickle-was-hacked-and-there-has-been-a-loss-of-funds-414b99969c29","credibility":3,"archive_timestamp":"2025-10-07T15:06:21+00:00"},{"url":"https://decrypt.co/49149/pickle-finance-hack","name":"decrypt.co","type":"other","archive_url":"http://web.archive.org/web/20260612011620/https://decrypt.co/49149/pickle-finance-hack","credibility":3,"archive_timestamp":"2026-06-12T01:16:20+00:00"},{"url":"https://www.nasdaq.com/articles/defi-protocol-pickle-finance-token-loses-almost-half-its-value-after-$19.7m-hack-2020-11","name":"nasdaq.com","type":"other","archive_url":"https://web.archive.org/web/20260829203207/https://www.nasdaq.com/articles/defi-protocol-pickle-finance-token-loses-almost-half-its-value-after-$19.7m-hack-2020-11","credibility":3,"archive_timestamp":"2026-08-29T20:32:07+00:00"},{"url":"https://github.com/banteg/evil-jar","name":"github.com","type":"other","archive_url":"http://web.archive.org/web/20260901040011/https://github.com/banteg/evil-jar","credibility":3,"archive_timestamp":"2026-09-01T04:00:11+00:00"},{"url":"https://github.com/pickle-finance/protocol/blob/master/audits/Haechi_Audit.pdf","name":"github.com","type":"other","archive_url":"http://web.archive.org/web/20260119154053/https://github.com/pickle-finance/protocol/blob/master/audits/Haechi_Audit.pdf","credibility":3,"archive_timestamp":"2026-01-19T15:40:53+00:00"},{"url":"https://docs.pickle.finance/security/audits-and-timelock/smart-contract-audits","name":"docs.pickle.finance","type":"other","archive_url":"http://web.archive.org/web/20260421081033/https://docs.pickle.finance/security/audits-and-timelock/smart-contract-audits","credibility":3,"archive_timestamp":"2026-04-21T08:10:33+00:00"},{"url":"https://beincrypto.com/pickle-finance-postmortem-details-how-19-million-dai-was-pilfered/","name":"beincrypto.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://coverprotocol.medium.com/11-21-20-claim-outcome-for-pickle-finance-aa2fcc56cb7c","name":"coverprotocol.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cointelegraph.com/news/decentralized-insurance-protocol-cover-holds-vote-to-cover-pickle-hack","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260306122813/https://cointelegraph.com/news/decentralized-insurance-protocol-cover-holds-vote-to-cover-pickle-hack","credibility":3,"archive_timestamp":"2026-03-06T12:28:13+00:00"},{"url":"https://beincrypto.com/pickle-finance-loses-20-million-in-latest-defi-exploit/","name":"beincrypto.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cryptonews.net/news/security/6222707/","name":"cryptonews.net","type":"other","archive_url":"https://web.archive.org/web/20260830163222/https://cryptonews.net/news/security/6222707/","credibility":3,"archive_timestamp":"2026-08-30T16:32:22+00:00"},{"url":"https://en.ethereumworldnews.com/2020s-pickle-finance-hackers-launder-1800-ethereum-through-tornado-cash/","name":"en.ethereumworldnews.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://beincrypto.com/yearn-finance-consumes-pickle-without-governance-vote/","name":"beincrypto.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.coindesk.com/markets/2020/11/24/yearning-for-pickle-two-defi-protocols-merge","name":"coindesk.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://cointelegraph.com/news/yearn-finance-absorbs-pickle-to-boost-defi-rewards","name":"cointelegraph.com","type":"other","archive_url":"https://web.archive.org/web/20260830084515/https://cointelegraph.com/news/yearn-finance-absorbs-pickle-to-boost-defi-rewards","credibility":3,"archive_timestamp":"2026-08-30T08:45:15+00:00"},{"url":"https://gov.yearn.finance/t/retroactive-vote-on-pickle-yearn-ferments/8306","name":"gov.yearn.finance","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-job","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://coinmarketcap.com/currencies/pickle-finance/","name":"coinmarketcap.com","type":"other","archive_url":"http://web.archive.org/web/20260513094613/https://coinmarketcap.com/currencies/pickle-finance/","credibility":3,"archive_timestamp":"2026-05-13T09:46:13+00:00"},{"url":"https://www.coingecko.com/en/coins/pickle-finance","name":"coingecko.com","type":"other","archive_url":"http://web.archive.org/web/20251007211548/https://www.coingecko.com/en/coins/pickle-finance","credibility":3,"archive_timestamp":"2025-10-07T21:15:48+00:00"},{"url":"https://defillama.com/protocol/pickle","name":"defillama.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://picklefinance.medium.com/pickle-finance-closing-the-jar-7996fe4ecd94","name":"picklefinance.medium.com","type":"other","archive_url":"http://web.archive.org/web/20251007160921/https://picklefinance.medium.com/pickle-finance-closing-the-jar-7996fe4ecd94","credibility":3,"archive_timestamp":"2025-10-07T16:09:21+00:00"},{"url":"https://www.publish0x.com/arkemmus-blog/pickle-finance-defi-with-a-cucumber-flavour-xgpnznp","name":"publish0x.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:59.889366+00:00","updated_at":"2026-09-02T00:39:37.039+00:00"}}