Popsicle Finance Hack

TOTAL LOST $20.7M
High Flash Loan Attacks Ethereum

What happened

On August 3, 2021, an attacker drained about $20.7 million from Popsicle Finance's Sorbetto Fragola Uniswap V3 optimizer pools on Ethereum. The incident affected the Fragola contracts rather than Popsicle's other products. The exploit abused the vault's fee-accounting state so that the attacker was treated as entitled to fees equal to the pool's value.

Popsicle paused affected activity and later published a recovery plan for users.

Technical Root Cause

The fee ledger separated a user's stored token rewards from the LP shares that made those rewards valid. collectFees could withdraw the stored reward amounts even after the user no longer held PLP, enabling repeated claims when the accounting state was manipulated.

Case & protocol details

Classification Token Accounting / Reward Double Claim
Protocol Type Liquidity manager
Affected asset / contract ICE
Smart Contract Language Solidity
Official Website popsicle.finance/
Protocol Twitter/X @popsiclefinance

Attack Timeline

Sorbetto Fragola issued Popsicle LP shares for deposited liquidity and accrued each account's Uniswap fees through per-share accounting. The attacker used temporary liquidity and a sequence of deposit, withdrawal, and fee-collection operations to make the vault credit them with fees far beyond their legitimate position. The accounting retained accrued reward balances after the LP position changed, and the collection path paid those balances without requiring the account to still hold the corresponding LP shares.

The attacker repeatedly collected the inflated balances, swapped the withdrawn assets for ETH, and repaid the temporary liquidity within the same transaction.

Security review history

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.