"According to Pike Finance, the initial exploit on April 26 was caused by weak security measures in Pike's contract functions when handling CCTP transfers."


"During protocol pausing attempts, an added dependency in the code altered storage layout and moved the initialized variable, causing contract misbehavior.


Seizing this opportunity, attackers upgraded spoke contracts without admin access, successfully siphoning off funds."


Pike Finance is a loan protocol which allows loans to be taken out using collateral on other chains. After users of Pike Finance had assets locked up due to a USDC withdrawal vulnerability, and then saw the entire smart contract drained due to a botched upgrade, an advanced phishing attack was started on the Twitter account PikeFinanc and domain pikefinance.net. After registering the fake domain and pumping the Twitter account with fake followers, the phishers responded to official updates from the Pike Finance team, claiming to be offering refunds, and pumping their posts with dozens of fake comments claiming to have received said refunds. The attack is ongoing and amount of damage is still unknown.

