{"investigation":{"slug":"pike-v1","entity_name":"Pike V1","trust_score":22,"severity_base":null,"score_modifier":0,"confidence":0.85,"status":"published","content_type":"investigation","summary":"Pike V1 (also known as Pike Beta) was a cross-chain DeFi lending protocol built by Nuts Finance that suffered two smart contract exploits within four days in April 2024, resulting in approximately $1.98 million in user losses. A vulnerability identified by auditing partner OtterSec prior to launch was never remediated, and a subsequent botched patch introduced even more severe vulnerabilities. The project's October 2024 token generation event further damaged investor trust after the team launched the $P token with only $10,000 in initial liquidity despite having raised $6.45 million in a presale.","sections":[{"content":"Pike V1 (branded as Pike Beta at launch) was a cross-chain lending and borrowing protocol developed by Nuts Finance, a Hong Kong-based DeFi development team led by co-founder Terry Lam. The protocol integrated Wormhole's cross-chain messaging, Circle's Cross-Chain Transfer Protocol (CCTP), and Pyth data feeds to enable lending and borrowing of native digital assets across multiple blockchains. Pike Beta launched on mainnet in February 2024 after receiving co-grants from Wormhole Foundation and Circle. The protocol was built on top of infrastructure that Nuts Finance had been developing since approximately 2019, with previous projects including ACoconut (acBTC aggregator), Tapio Finance, and Taiga Protocol. ACoconut reached a peak TVL of $70 million in April 2021 before collapsing during the 2021-2022 crypto winter, with its token price never recovering.","heading":"Protocol Overview","sources":[{"url":"https://protos.com/defi-lender-pike-finance-loses-1-9m-to-two-hacks-in-less-than-a-week/","name":"protos.com","type":"other","credibility":3},{"url":"https://medium.com/nuts-foundation/nuts-finance-journey-recollection-e6b62cd53911","name":"medium.com","type":"other","credibility":3},{"url":"https://cryptonews.net/news/blockchain/28112716/","name":"cryptonews.net","type":"other","credibility":3}],"severity":"medium"},{"content":"On April 26, 2024, Pike Beta suffered its first exploit when an attacker exploited a flaw in the protocol's integration with Circle's Cross-Chain Transfer Protocol (CCTP). The vulnerability allowed the attacker to manipulate the recipient address and transaction amounts during USDC transfer processing. Because Pike Finance did not properly validate external CCTP messages, the attacker was able to forge messages and drain 299,127 USDC (approximately $299,279) from the protocol. Pike's auditing partner OtterSec had identified this vulnerability prior to the attack but the development team had been unable to address it in a timely manner. Pike Finance later acknowledged that the exploit resulted from their team's 'improper integration' of third-party technologies, specifically CCTP and Gelato Network's automation services. Following the incident, the protocol was paused and the team began working on a patch. The stolen USDC was reportedly converted to ETH and sent to Tornado Cash.","heading":"First Exploit: CCTP Vulnerability (April 26, 2024)","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-pike-finance-hack-april-2024","name":"halborn.com","type":"other","credibility":3},{"url":"https://protos.com/defi-lender-pike-finance-loses-1-9m-to-two-hacks-in-less-than-a-week/","name":"protos.com","type":"other","credibility":3},{"url":"https://quadrigainitiative.com/casestudy/pikefinanceusdcwithdrawalvulnerability.php","name":"quadrigainitiative.com","type":"other","credibility":3},{"url":"https://cryptoslate.com/pike-finance-admits-to-error-following-1-7-million-exploit-denies-fault-of-usdc/","name":"cryptoslate.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On April 30, 2024, just four days after the first attack, Pike Beta was exploited again in a more severe incident. When the Pike team deployed an update to patch the original CCTP vulnerability, they introduced a critical flaw in the smart contract's storage layout. Adding a new pause() and unpause() function dependency shifted the storage slot of the 'initialized' variable, causing the contract to behave as if it had never been initialized. This allowed an attacker at address 0x19066f7431df29a0910d287c8822936bb7d89e23 to upgrade the spoke contracts to malicious versions, bypassing admin access controls entirely. The attacker drained 99,970.48 ARB, 64,126 OP, and 479.39 ETH across Optimism, Arbitrum, and Ethereum, totalling approximately $1.68 million. The total losses across both incidents reached approximately $1.98 million. Security firm Ancilia independently identified that the attacker had upgraded and taken control of the Pike contracts. The attacker then converted all stolen assets to approximately 562 ETH, moved funds through the Li.Fi bridge, and deposited them into the RAILGUN privacy protocol, which uses zero-knowledge proofs to obscure transaction trails. Pike explicitly stated that Circle's USDC infrastructure and Gelato were not at fault, and accepted sole responsibility as the integrator.","heading":"Second Exploit: Storage Mapping Vulnerability (April 30, 2024)","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-pike-finance-hack-april-2024","name":"halborn.com","type":"other","credibility":3},{"url":"https://www.merklescience.com/blog/hack-track-pike-finance-flow-of-funds-analysis","name":"merklescience.com","type":"other","credibility":3},{"url":"https://quadrigainitiative.com/casestudy/pikefinancevariablestoragevulnerability.php","name":"quadrigainitiative.com","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/single/pike-finance-hacks","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://cryptoslate.com/pike-finance-admits-to-error-following-1-7-million-exploit-denies-fault-of-usdc/","name":"cryptoslate.com","type":"other","credibility":3}],"severity":"medium"},{"content":"A significant aggravating factor in the Pike V1 exploits was the team's failure to remediate a vulnerability that had already been identified before the attack. Auditing partner OtterSec had discovered the CCTP integration flaw prior to the April 26 exploit, yet the Pike development team did not address it in a timely manner. This is a critical failure of operational security: a known vulnerability was left open in a live protocol handling user funds. The subsequent attempt to patch this flaw then introduced the even more severe storage mapping vulnerability exploited on April 30. The combination of a known-unfixed bug leading to a second, larger hack resulting from a botched patch represents a compounded operational failure.","heading":"Known Vulnerability Left Unpatched","sources":[{"url":"https://protos.com/defi-lender-pike-finance-loses-1-9m-to-two-hacks-in-less-than-a-week/","name":"protos.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-pike-finance-hack-april-2024","name":"halborn.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/pike-defi-usdc-exploit-clarity","name":"cointelegraph.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploits, Pike Finance offered a 20% bounty for the return of stolen funds or information leading to the attacker's identification. The team committed to making affected users whole, releasing a full list of impacted wallet addresses and calculating net balances at asset prices from April 26, 2024. The team pledged to use 4% of community treasury $P tokens as collateral to borrow approximately $2 million for repurchasing assets and reimbursing users. According to one source, users were reportedly fully repaid in May 2024, though independent confirmation of complete repayment is limited. The chaotic situation also attracted secondary fraud: phishing attackers hijacked the Twitter handle PikeFinanc and registered the domain pikefinance.net to target users expecting refund communications.","heading":"User Compensation and Phishing Attacks","sources":[{"url":"https://quadrigainitiative.com/casestudy/pikefinancevariablestoragevulnerability.php","name":"quadrigainitiative.com","type":"other","credibility":3},{"url":"https://www.quadrigainitiative.com/hackfraudscam/pikefinancerefundphishingattack.php","name":"quadrigainitiative.com","type":"other","credibility":3},{"url":"https://protos.com/defi-lender-pike-finance-loses-1-9m-to-two-hacks-in-less-than-a-week/","name":"protos.com","type":"other","credibility":3},{"url":"https://medium.com/nuts-foundation/nuts-finance-journey-recollection-e6b62cd53911","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Despite having raised approximately $6.45 million in a March 2024 token presale at prices ranging from $0.0280 to $0.0374 per token, Pike Finance launched its $P token generation event (TGE) in October 2024 with only $10,000 in initial liquidity on the Aerodrome decentralized exchange on Base. The token price dropped approximately 90% shortly after launch, with DEXScreener data showing the price falling to around $0.0035. One presale investor publicly reported that their $1,500 investment was worth only $61 after launch. Multiple investors called for blockchain investigator ZachXBT to look into the situation. Pike co-founder Terry Lam blamed the minimal liquidity on tokenomics design constraints, stating the core team did not have access to sufficient Pike tokens to pair with a sizable stablecoin pool, and pledged to purchase $P tokens from the open market to progressively build liquidity. This explanation was met with significant skepticism from the investor community given the scale of the presale raise.","heading":"Token Launch Controversy (October 2024)","sources":[{"url":"https://www.theblock.co/post/318913/investors-upset-at-pike-finances-token-launch-over-liquidity-shortfall","name":"theblock.co","type":"other","credibility":3},{"url":"https://thedefiant.io/news/defi/pike-finance-blames-botched-launch-on-tokenomics","name":"thedefiant.io","type":"other","credibility":3},{"url":"https://web3.bitget.com/en/dapp/pikefinance-25839","name":"web3.bitget.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Multiple independent security firms published post-incident analyses of the Pike V1 exploits. CertiK, Halborn, and QuillAudits each published technical breakdowns of the attack vectors. The consensus across these analyses identified the root cause as: (1) insufficient validation of external CCTP messages allowing address and amount manipulation, and (2) a storage layout collision introduced during the smart contract upgrade where the delegatecall mechanism shifted the position of the 'initialized' storage slot, effectively resetting administrator access controls. Merkle Science conducted an on-chain flow-of-funds analysis, tracing the stolen 562 ETH to RAILGUN. The attacker pre-funded their Arbitrum wallet via RAILGUN before the second attack, and moved exploited proceeds from Optimism and Arbitrum to Ethereum via Li.Fi bridge before final deposit into RAILGUN for obfuscation.","heading":"Technical Analysis and Security Assessments","sources":[{"url":"https://www.certik.com/resources/blog/pike-finance-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-pike-finance-hack-april-2024","name":"halborn.com","type":"other","credibility":3},{"url":"https://quillaudits.medium.com/decoding-pike-finance-exploit-quillaudits-40a1662d3f8a","name":"quillaudits.medium.com","type":"other","credibility":3},{"url":"https://www.merklescience.com/blog/hack-track-pike-finance-flow-of-funds-analysis","name":"merklescience.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the Pike V1 (Beta) exploits, the team continued development under the Pike Finance brand. The protocol relaunched with a V2 architecture incorporating Local Markets (LMs), Universal Vault (UV), and Protocol-Oriented Chain Abstraction (POCA) modules. Developer changelogs indicate active maintenance through at least late 2025, with version 0.20.1 documented as of December 2025. The native $P token trades at a fraction of its presale price. The protocol self-describes as being in an early and experimental stage and notes it has not been thoroughly reviewed for all security vulnerabilities. No regulatory actions by the SEC, CFTC, or other government bodies have been identified in connection with Pike Finance or Nuts Finance.","heading":"Current Protocol Status","sources":[{"url":"https://docs.pike.finance/developer-docs/resources/developer-changelog","name":"docs.pike.finance","type":"other","credibility":3},{"url":"https://github.com/nutsfinance/pike-protocol","name":"github.com","type":"other","credibility":3},{"url":"https://messari.io/project/pike-finance","name":"messari.io","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2024-02","event":"Pike Beta launches on mainnet, integrated with Wormhole cross-chain messaging and Circle's CCTP.","source":"","date_original":"2024-02-01"},{"date":"2024-03","event":"Pike Finance raises approximately $6.45 million in a token presale at $0.0280-$0.0374 per $P token.","source":"","date_original":"2024-03-01"},{"date":"2024-04-26","event":"First exploit: attacker drains 299,127 USDC (~$299,279) via a CCTP message forgery vulnerability that auditor OtterSec had previously identified but the team had not patched.","source":""},{"date":"2024-04-30","event":"Second exploit: attacker at 0x19066f7431df29a0910d287c8822936bb7d89e23 exploits a storage mapping flaw introduced by the team's patch, draining 99,970.48 ARB, 64,126 OP, and 479.39 ETH (~$1.68 million) across Arbitrum, Optimism, and Ethereum.","source":""},{"date":"2024-04-30","event":"Stolen proceeds (~562 ETH total across both exploits) laundered through RAILGUN privacy protocol via Li.Fi bridge.","source":""},{"date":"2024-05","event":"Pike Finance offers 20% bounty for return of funds or attacker information; commits to making users whole using community treasury $P tokens as collateral.","source":"","date_original":"2024-05-01"},{"date":"2024-05","event":"Phishing attackers register PikeFinanc Twitter handle and pikefinance.net domain to exploit users awaiting refund communications.","source":"","date_original":"2024-05-01"},{"date":"2024-05","event":"Pike Finance accepts sole responsibility as integrator; clarifies that Circle (USDC) and Gelato were not at fault for the exploits.","source":"","date_original":"2024-05-01"},{"date":"2024-05-31","event":"Team reportedly repays affected users in full using community treasury allocation, though independent verification is limited.","source":""},{"date":"2024-10","event":"Pike Finance conducts token generation event (TGE) for $P token on Aerodrome (Base) with only $10,000 in initial liquidity; token price drops approximately 90% within hours.","source":"","date_original":"2024-10-01"},{"date":"2024-10","event":"Investor backlash intensifies; community members call for ZachXBT to investigate the token launch given the $6.45M presale raise versus the minimal liquidity deployment.","source":"","date_original":"2024-10-01"},{"date":"2024-10-21","event":"Pike Finance publishes community update focused on Local Markets development and front-end improvements; does not directly address token price or liquidity concerns.","source":""}],"sources_used":[{"url":"https://protos.com/defi-lender-pike-finance-loses-1-9m-to-two-hacks-in-less-than-a-week/","name":"protos.com","type":"other","archive_url":"http://web.archive.org/web/20260217174412/https://protos.com/defi-lender-pike-finance-loses-1-9m-to-two-hacks-in-less-than-a-week/","credibility":3,"archive_timestamp":"2026-02-17T17:44:12+00:00"},{"url":"https://medium.com/nuts-foundation/nuts-finance-journey-recollection-e6b62cd53911","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://cryptonews.net/news/blockchain/28112716/","name":"cryptonews.net","type":"other","archive_url":"https://web.archive.org/web/20260829234951/https://cryptonews.net/news/blockchain/28112716/","credibility":3,"archive_timestamp":"2026-08-29T23:49:51+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-pike-finance-hack-april-2024","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260605231538/https://www.halborn.com/blog/post/explained-the-pike-finance-hack-april-2024","credibility":3,"archive_timestamp":"2026-06-05T23:15:38+00:00"},{"url":"https://quadrigainitiative.com/casestudy/pikefinanceusdcwithdrawalvulnerability.php","name":"quadrigainitiative.com","type":"other","archive_url":"http://web.archive.org/web/20260519152845/https://quadrigainitiative.com/casestudy/pikefinanceusdcwithdrawalvulnerability.php","credibility":3,"archive_timestamp":"2026-05-19T15:28:45+00:00"},{"url":"https://cryptoslate.com/pike-finance-admits-to-error-following-1-7-million-exploit-denies-fault-of-usdc/","name":"cryptoslate.com","type":"other","archive_url":"http://web.archive.org/web/20260725202542/https://cryptoslate.com/pike-finance-admits-to-error-following-1-7-million-exploit-denies-fault-of-usdc/","credibility":3,"archive_timestamp":"2026-07-25T20:25:42+00:00"},{"url":"https://www.merklescience.com/blog/hack-track-pike-finance-flow-of-funds-analysis","name":"merklescience.com","type":"other","archive_url":"http://web.archive.org/web/20260423030642/https://www.merklescience.com/blog/hack-track-pike-finance-flow-of-funds-analysis","credibility":3,"archive_timestamp":"2026-04-23T03:06:42+00:00"},{"url":"https://quadrigainitiative.com/casestudy/pikefinancevariablestoragevulnerability.php","name":"quadrigainitiative.com","type":"other","archive_url":"http://web.archive.org/web/20260422115815/https://quadrigainitiative.com/casestudy/pikefinancevariablestoragevulnerability.php","credibility":3,"archive_timestamp":"2026-04-22T11:58:15+00:00"},{"url":"https://www.web3isgoinggreat.com/single/pike-finance-hacks","name":"web3isgoinggreat.com","type":"other","archive_url":"https://web.archive.org/web/20260830011407/https://www.web3isgoinggreat.com/single/pike-finance-hacks","credibility":3,"archive_timestamp":"2026-08-30T01:14:07+00:00"},{"url":"https://cointelegraph.com/news/pike-defi-usdc-exploit-clarity","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260720142256/https://cointelegraph.com/news/pike-defi-usdc-exploit-clarity","credibility":3,"archive_timestamp":"2026-07-20T14:22:56+00:00"},{"url":"https://www.quadrigainitiative.com/hackfraudscam/pikefinancerefundphishingattack.php","name":"quadrigainitiative.com","type":"other","archive_url":"https://web.archive.org/web/20260829153018/https://www.quadrigainitiative.com/hackfraudscam/pikefinancerefundphishingattack.php","credibility":3,"archive_timestamp":"2026-08-29T15:30:18+00:00"},{"url":"https://www.theblock.co/post/318913/investors-upset-at-pike-finances-token-launch-over-liquidity-shortfall","name":"theblock.co","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://thedefiant.io/news/defi/pike-finance-blames-botched-launch-on-tokenomics","name":"thedefiant.io","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://web3.bitget.com/en/dapp/pikefinance-25839","name":"web3.bitget.com","type":"other","archive_url":"https://web.archive.org/web/20260829143235/https://web3.bitget.com/dapp/pike-finance-25839","credibility":3,"archive_timestamp":"2026-08-29T14:32:35+00:00"},{"url":"https://www.certik.com/resources/blog/pike-finance-incident-analysis","name":"certik.com","type":"other","archive_url":"http://web.archive.org/web/20251012105453/https://www.certik.com/resources/blog/pike-finance-incident-analysis","credibility":3,"archive_timestamp":"2025-10-12T10:54:53+00:00"},{"url":"https://quillaudits.medium.com/decoding-pike-finance-exploit-quillaudits-40a1662d3f8a","name":"quillaudits.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://docs.pike.finance/developer-docs/resources/developer-changelog","name":"docs.pike.finance","type":"other","archive_url":"http://web.archive.org/web/20260210031843/https://docs.pike.finance/developer-docs/resources/developer-changelog","credibility":3,"archive_timestamp":"2026-02-10T03:18:43+00:00"},{"url":"https://github.com/nutsfinance/pike-protocol","name":"github.com","type":"other","archive_url":"http://web.archive.org/web/20260725204039/https://github.com/nutsfinance/pike-protocol","credibility":3,"archive_timestamp":"2026-07-25T20:40:39+00:00"},{"url":"https://messari.io/project/pike-finance","name":"messari.io","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:32.88063+00:00","updated_at":"2026-08-30T05:14:07.979366+00:00"}}