Peapods Finance Hack

REPORTED LOSS $4K
Low Other

What happened

Peapods Finance's February 2025 incident affected reward processing in an older Pod implementation. A caller could choose an extreme slippage override, forcing a swap after manipulating the pool price. The reported impact was approximately $3,500, and Peapods said the affected Pod would be reimbursed.

Technical Root Cause

An unrestricted caller-supplied _slippageOverride controlled amountOutMinimum for a Uniswap V3 swap. An extreme value bypassed the intended price protection and exposed reward processing to price manipulation.

Case & protocol details

Classification Yield Aggregator
Protocol Type Yield
Official Website peapods.finance/app
Protocol Twitter/X @PeapodsFinance

How it happened

  1. The attacker made a large trade to move the pool price.
  2. They called depositFromPairedLpToken with _slippageOverride set to 999, weakening the swap's minimum-output protection.
  3. The rewards contract traded at an unfavorable price, and the attacker traded back to extract the difference.

Security review history

Evidence & learning

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.