HomeAboutWhat is web3?FAQLicenseTwitterMastodonBlueskyInstagramThreadsRSSLeaderboardGlossaryContributeNewsletterStore

Archived tweet

Back

Tweet thread by Pike Finance:

Attention Users:

On the 30th of April 2024, the Pike Beta protocol was exploited for 99,970.48 ARB, 64,126 OP and 479.39 ETH.

This exploit is related to the initial USDC vulnerability that was reported last week on the 26th of April.

In order to pause the protocol, the spoke contracts were upgraded and there was the inclusion of an additional dependency within the smart contract code.

This dependency introduced new variables which altered the storage layout - in particular, the position of the *initialized* variable. 

As a result, the position occupied by the *initialized* variable was taken over by other variables, leading to a misalignment in storage mapping.

This misalignment caused the contract to behave as if it was uninitialized, since the *initialized* variable could no longer be accessed.

As a result, attackers were then able to upgrade the spoke contracts, bypassing admin access, and as a result, withdraw funds.

While we continue our investigation, we are offering a 20% reward for the return of the funds, or information leading to the recovery of funds.

In addition, a report and plan to make users whole will be provided at a later time.

Thank you. 
Tweeted at 3:32 AM · May 1, 2024

2/ There are no more tweets after this.

Be on the lookout for scammers, impersonators and phishers during this volatile time. 

If you see posts mentioning a refund or airdrop - be sure to report the accounts responsible. 
Tweeted at 5h

Text is licensed under a Creative Commons Attribution 3.0 Unported License. All attribution can be found on the attribution page.

Source code | Contribute