Popsicle Finance Hack
Incident Overview
Popsicle Finance suffered an exploit due to a bug in the collectFees() function, allowing the attacker to withdraw rewards without holding PLP tokens. The attacker stole a total of 2.56K WETH, 96.2 WBTC, 160K DAI, 5.39M USDC, 4.98M USDT, and 10.5K UNI.
The attacker created three contracts, one of which was used to launch the attack, while the other two were used to invoke the collectFees() function to fetch the rewards. The attacker utilized a Flash Loan from AAVE and launched the Deposit-Withdraw-CollectFees cycle to perform the attack. There were 8 cycles in total, and a significant amount of liquidity was withdrawn from multiple vaults of Popsicle Finance. After the attack, the stolen funds were deposited into the Tornado Cash mixer.
Stolen funds:
- 2.56K WETH
- 96.2 WBTC
- 160K DAI
- 5.39M USDC
- 4.98M USDT
- 10.5K UNI
The attacker's address:
https://etherscan.io/address/0xf9e3d081…4bea52
The transaction behind the attack:
https://etherscan.io/tx/0xcd7dae14…ab70fc
The transaction list of the stolen funds:
https://bloxy.info/txs/transfers_from/0xf9e3d081…4bea52?currency_id=1
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Popsicle Finance, these are the critical security checks that could have prevented this incident (August 2021).
- Verify all logic paths related to Flashloan Incentive Rewards Exploit / Other are guarded by proper access controls and input validation - see the Flash Loans Attacks attack class for patterns
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSecurity Audit History
- Certik Report
Related Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Proof-of-Concept Exploits
On-Chain Evidence & References
Sources & References
Learn to Prevent the Next Popsicle Finance
The Popsicle Finance hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.