{"id":47203,"date":"2021-08-04T15:17:08","date_gmt":"2021-08-04T12:17:08","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=47203"},"modified":"2025-09-01T20:09:10","modified_gmt":"2025-09-01T17:09:10","slug":"hacker-drains-more-than-20-million-from-the-popsicle-finance-defi-protocol","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/hacker-drains-more-than-20-million-from-the-popsicle-finance-defi-protocol\/","title":{"rendered":"Hacker drains more than $20 million from the Popsicle Finance DeFi protocol"},"content":{"rendered":"<p>The DeFi project Popsicle Finance was hacked, losing $20.7 million.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Popsicle Sorbetto Fragola, our Uniswap V3 optimizer last night was hacked.<\/p>\n<p>Thanks to all that supported us in the last hours, and in general to our unbelievable community that continuously makes us want to deliver!<\/p>\n<p>Here is our Post Mortem: <a href=\"https:\/\/t.co\/DuXMNos9td\">https:\/\/t.co\/DuXMNos9td<\/a><\/p>\n<p>\u2014 Popsicle Finance (@PopsicleFinance) <a href=\"https:\/\/twitter.com\/PopsicleFinance\/status\/1422882890724093953?ref_src=twsrc%5Etfw\">August 4, 2021<\/a><\/p><\/blockquote>\n<p> <script async=\"\" src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>A bug was found in the Sorbetto Fragola product of the project. It allows users to place assets in the most lucrative liquidity pools. According to the Popsicle Finance site, the solution was designed specifically for Uniswap v3, which introduced <a href=\"https:\/\/u1f987.com\/en\/news\/concentrated-liquidity-and-optimism-can-uniswap-sustain-leadership-among-dexs\">concentrated liquidity<\/a>.<\/p>\n<p>According to the DeFi protocol, the attacker drained 85% of the Sorbetto Fragola pools.<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u00abThe hacker forced the contract to believe that he earned as much in fees as the total amount of funds locked in the pool, and, on that basis, is entitled to $20.7 million held in the pool\u00bb, the project said.<\/p>\n<\/blockquote>\n<p>Subsequently, he swapped the proceeds for ETH on Uniswap, and then sent them to the Tornado.Cash mixing service to launder the funds, according to Popsicle Finance.<\/p>\n<p>SushiSwap developer Mudit Gupta said that \u00abthe hack was complex, but the bug was simple\u00bb. According to him, the attacker drained $25 million as a result of the attack.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Popsicle Finance exploited, hacker drained ~$25m. The hack was complex but the bug was simple. TX Hash: <a href=\"https:\/\/t.co\/CqyVvCq5I7\">https:\/\/t.co\/CqyVvCq5I7<\/a><\/p>\n<p>Basically, Popsicle doesn\u2019t transfer the reward debt when users transfer their shares. This exposes multiple exploits, one of which was used here \ud83e\uddf5\ud83d\udc47 <a href=\"https:\/\/t.co\/shdYdyemD9\">pic.twitter.com\/shdYdyemD9<\/a><\/p>\n<p>\u2014 Mudit Gupta (@Mudit__Gupta) <a href=\"https:\/\/twitter.com\/Mudit__Gupta\/status\/1422797923037814786?ref_src=twsrc%5Etfw\">August 4, 2021<\/a><\/p><\/blockquote>\n<p> <script async=\"\" src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>In return for the funds, Popsicle Finance offered the attacker $1 million \u00abin any currency\u00bb.<\/p>\n<p>Deposits for all pools are blocked; the only pools eligible for withdrawal are AXS\/ETH, YGG\/USDC, LINK\/ETH and all EURt pools. Users were urged to withdraw their funds from them.<\/p>\n<p>The team pledged to outline a plan to compensate users for the losses later.<\/p>\n<p>Earlier in July, the THORChain DeFi protocol team <a href=\"https:\/\/u1f987.com\/en\/news\/thorchain-halts-operations-after-a-string-of-hacker-attacks\">announced a suspension of operations<\/a> after several hacking attacks.<\/p>\n<p>Follow ForkLog&#8217;s Bitcoin news on our <a href=\"\/\/telegram.me\/forklog\" target=\"\u201c_blank\u201d\" rel=\"\u201cnofollow\u201d noopener\">Telegram<\/a> \u2014 cryptocurrency news, prices and analysis.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The DeFi project Popsicle Finance was hacked, losing $20.7 million.<\/p>\n","protected":false},"author":1,"featured_media":47204,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1154,1093],"class_list":["post-47203","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-crimes","tag-defi"],"aioseo_notices":[],"amp_enabled":true,"views":"25","promo_type":"1","layout_type":"1","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/47203","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=47203"}],"version-history":[{"count":1,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/47203\/revisions"}],"predecessor-version":[{"id":47205,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/47203\/revisions\/47205"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/47204"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=47203"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=47203"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=47203"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}