Refreshed 2h ago· updates every 6h

Pickle Finance (2020) — Crypto Hack

Laundered
Nov 21, 2020·
Ethereum
Amount Stolen
$19.7M
~19.7M DAI
Recovered
$0

Pickle Finance's DAI jar (vault) was drained via a sophisticated exploit using counterfeit jars and swapping logic to extract DAI.

Summary

Pickle Finance's DAI jar (vault) was drained via a sophisticated exploit using counterfeit jars and swapping logic to extract DAI.

How It Was Compromised — DeFi via Smart Contract Exploit

DeFiSmart Contract Exploit

The attacker created a malicious 'evil jar' contract that mimicked Pickle Finance's official jar interface. By exploiting a flaw in the swap logic between jars, the attacker convinced the protocol to transfer 19.7M DAI from the cDAI jar to the evil jar. The exploit required deep understanding of Pickle's architecture and multiple Yearn-inherited components.

Fund Flow & Laundering Analysis

The 19.7M DAI was converted to ETH and routed through Tornado Cash in large batches. Pickle Finance and Yearn Finance collaborated on a post-mortem and compensation plan. Yearn's Andre Cronje helped identify the vulnerability. The attacker was never identified, and funds were not recovered.

Related Incidents

For educational and transparency purposes only. Not financial advice. Data compiled from public sources and may contain approximations.