Peapods Finance Hack
What happened
Peapods Finance's February 2025 incident affected reward processing in an older Pod implementation. A caller could choose an extreme slippage override, forcing a swap after manipulating the pool price. The reported impact was approximately $3,500, and Peapods said the affected Pod would be reimbursed.
An unrestricted caller-supplied _slippageOverride controlled amountOutMinimum for a Uniswap V3 swap. An extreme value bypassed the intended price protection and exposed reward processing to price manipulation.
Case & protocol details
How it happened
- The attacker made a large trade to move the pool price.
- They called depositFromPairedLpToken with _slippageOverride set to 999, weakening the swap's minimum-output protection.
- The rewards contract traded at an unfavorable price, and the attacker traded back to extract the difference.
Security review history
- SourceHat Report
Evidence & learning
Sources and on-chain records
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.