{"investigation":{"slug":"peapods-finance","entity_name":"Peapods Finance","trust_score":42,"severity_base":null,"score_modifier":0,"confidence":0.78,"status":"published","content_type":"investigation","summary":"Peapods Finance is a permissionless DeFi protocol on Ethereum and multiple EVM chains that pioneered a 'Volatility Farming' yield mechanism using asset-backed Pods and Leveraged Volatility Farming (LVF). The protocol has suffered three distinct security incidents since its December 2023 launch, including a $231K reentrancy exploit, a slippage manipulation attack, and a $200K oracle price manipulation attack in July 2025. On-chain investigator ZachXBT identified that the individual behind the initial 2023 'white hat' exploit had dumped a portion of stolen funds before returning the remainder, raising questions about the altruistic framing of that recovery.","sections":[{"content":"Peapods Finance is a permissionless, modular DeFi protocol that allows any ERC-20 asset to form the foundation of a self-sustaining financial system. The protocol was launched in December 2023 on Ethereum and has since expanded to Arbitrum, Base, Sonic, Berachain, and Mode networks. Its core product, 'Pods,' are vaults that issue synthetic ERC-20 wrapped tokens (pTKN) representing deposited assets. Pods generate yield through a mechanism Peapods calls Volatility Farming, which captures fees from wrapping, unwrapping, trading, and borrowing activity and redistributes them as protocol revenue — rather than relying on inflationary token emissions. The protocol's native token, PEAS, has a fixed total supply of 10 million. It was distributed at launch via a fair-launch model: 44% to a concentrated Uniswap V3 PEAS/DAI liquidity position, 44% to a full-range Uniswap V3 PEAS/DAI position, and 12% to the team across six recipients, fully vested at TGE. Leveraged Volatility Farming (LVF), a later product upgrade, allows users to amplify their Pod yield exposure using soft leverage with self-collateralizing positions, subject to liquidation at LTV ratios exceeding 83.33%. TVL peaked in early 2024 and had declined to approximately $1.9 million by mid-2025.","heading":"Protocol Overview","sources":[{"url":"https://docs.peapods.finance/","name":"docs.peapods.finance","type":"other","credibility":3},{"url":"https://docs.peapods.finance/peas-tokenomics","name":"docs.peapods.finance","type":"other","credibility":3},{"url":"https://defillama.com/protocol/peapods-finance","name":"defillama.com","type":"other","credibility":3},{"url":"https://docs.peapods.finance/leveraged-volatility-farming-lvf","name":"docs.peapods.finance","type":"other","credibility":3}],"severity":"medium"},{"content":"On December 13, 2023, Peapods Finance was exploited via a reentrancy attack targeting the WeightedIndex contract. The attacker, later identified by on-chain investigator ZachXBT as likely axxe.eth (Twitter: @0xaxxe), used flashloan functionality to drain the contract's liquidity. The attack resulted in the theft of PEAS tokens valued at approximately $231,192 (104.47 ETH) at the time. Key attacker addresses include 0x2BA9dE5eBca7db023DD1f9Abce9100E7590D0000 and 0x838D23a8A17adaa6866969b86D35Ac0941C67510, with the malicious contract deployed at 0x928B2DAe97FC5d40Cb0552815fb5ab071103e20a. The primary exploit transaction was 0x98d8237027797a51b1251aa239d1a85b7a209d15c9f7895b44b4ee7ee0c754fb. The Peapods Finance team announced on December 14, 2023 that approximately 90% of stolen funds had been returned, characterizing the incident as a 'white hat hack.' The attacker subsequently tweeted on December 15 that the white hat fee had been returned to the team. However, ZachXBT identified through timing analysis that the exploiter had routed funds through FixedFloat — sending 1,000 USDC to FixedFloat at 2:55 PM UTC before the exploit occurred at 3:12 PM UTC — indicating the individual may have dumped a portion of the stolen assets before returning the remainder. The team addressed the vulnerability by implementing a locking mechanism on all affected contract functions. The incident occurred just days after the protocol's public launch.","heading":"Security Incident 1 — Reentrancy Exploit (December 2023)","sources":[{"url":"https://github.com/liqtags/crypto-rekts/blob/main/rekts/Peapods-Finance-Exploit.md","name":"github.com","type":"other","credibility":3},{"url":"https://x.com/zachxbt/status/1735025990819049968","name":"x.com","type":"other","credibility":3},{"url":"https://coinpaper.com/2875/over-8-4-million-stolen-in-crypto-exploits-within-a-single-week","name":"coinpaper.com","type":"other","credibility":3},{"url":"https://hacked.slowmist.io/?c=ETH&page=6","name":"hacked.slowmist.io","type":"other","credibility":3}],"severity":"medium"},{"content":"On February 8, 2025, Peapods Finance experienced a second security incident: a slippage frontrun attack targeting the reward contract's depositFromPairedLpToken function. The root cause was that the function allowed callers to set an unconstrained _slippageOverride parameter, which directly influenced the amountOutMinimum value passed to Uniswap's exactInputSingle function. The attacker first executed a large trade to manipulate the market price, then called depositFromPairedLpToken with _slippageOverride set to 999, forcing the contract to accept severely unfavorable trade conditions. The attacker then back-ran the transaction to capture the price difference. Financial impact was limited to approximately $3,500. The Peapods team stated the affected Pod would be reimbursed and noted the vulnerability existed only in an older version of the Pod code that was no longer in active deployment at the time. The attacker address associated with this incident was 0xeDee6379fe90bd9b85d8d0b767d4a6deb0dc9dcf, with the primary attack transaction 0x2c1a19982aa88bee8a5d9a5dfeb406f2bfe1cfc1213f20e91d91ce3b55c86cc5.","heading":"Security Incident 2 — Slippage Manipulation Attack (February 2025)","sources":[{"url":"https://blog.solidityscan.com/peapods-finance-hack-analysis-bdc5432107a5","name":"blog.solidityscan.com","type":"other","credibility":3},{"url":"https://getfailsafe.com/peapods-finance-hack-200k-exploit-what-happened-and-and-how-to-stay-safe/","name":"getfailsafe.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On July 8, 2025, Peapods Finance suffered its most publicly prominent exploit: an oracle price manipulation attack targeting the WETH/aspLONGsUSDe oracle pair on Ethereum mainnet. Blockchain analysts at TenArmorAlert identified that the oracle price was pushed to an artificially inflated level, enabling the attacker to drain approximately 78 ETH (valued at roughly $207,000 at the time) from the affected Pod. The attacker address was 0x277da2d1ce5601c0f0133515c19da314fc52a846, targeting the victim contract at 0xd1538a9d69801e57c937f3c64d8c4f57d2967257, via an exploit contract deployed at 0x7212de58f97ad6c28623752479acaeb6b15ad006. The primary exploit transaction hash was 0xeff836fa1ce60f04b94544fa424764101323f1f7c8ab8265b4bd34e9fa84f8db. BlockSec Phalcon noted in a public post that the attacker attempted a second exploit but was front-run by Yoink, a known MEV actor, preventing that second drain. Stolen funds were routed through ChangeNow and FixedFloat mixers. Multiple security firms including SlowMist, CertiK, PeckShield, and TenArmor independently flagged the incident. The Peapods team attributed the breach to a 'bad oracle configuration' in one specific user-created Pod rather than a systemic flaw in core contracts, and stated other vaults remained secure. As of the time of reporting, Peapods Finance had not issued a formal public statement or post-mortem. PEAS token price declined approximately 5% in the immediate aftermath. The incident resulted in a reported 70% decline in TVL from the protocol's March 2024 peak.","heading":"Security Incident 3 — Oracle Price Manipulation Attack (July 2025)","sources":[{"url":"https://quadrigainitiative.com/casestudy/peapodsfinanceasplongsusdepricemanipulationattack.php","name":"quadrigainitiative.com","type":"other","credibility":3},{"url":"https://thedefiant.io/news/defi/peapods-finance-token-slips-5-percent-on-reported-oracle-issue","name":"thedefiant.io","type":"other","credibility":3},{"url":"https://getfailsafe.com/peapods-finance-hack-200k-exploit-what-happened-and-and-how-to-stay-safe/","name":"getfailsafe.com","type":"other","credibility":3},{"url":"https://www.ccn.com/news/technology/this-week-crypto-hacks-gmx-peapods-finance-exploited/","name":"ccn.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On-chain investigator ZachXBT conducted an independent investigation of the December 2023 reentrancy exploit and published findings on X (formerly Twitter). Using timing analysis of on-chain transactions, ZachXBT identified that the alleged white hat exploiter was likely axxe.eth or @0xaxxe. Specifically, the analysis showed that at 2:55 PM UTC, axxe sent 1,000 USDC to FixedFloat (transaction 0x7a49f6dc4084a6088406e56e27a2c85e7fd05f5b3adb3a58b5065704bbf2796e), followed at 3:12 PM UTC by the exploiter receiving 0.44 ETH — a timing pattern consistent with routing funds through a non-KYC exchange prior to executing the exploit. ZachXBT's analysis indicated the actor had dumped a portion of the stolen tokens before returning the majority of funds, contradicting the purely altruistic characterization offered by the Peapods team. This is the primary connection between ZachXBT and Peapods Finance documented in public sources. ZachXBT has not published a separate standalone investigation thread specifically dedicated to Peapods Finance beyond the December 2023 tweet.","heading":"ZachXBT Investigation and Findings","sources":[{"url":"https://x.com/zachxbt/status/1735025990819049968","name":"x.com","type":"other","credibility":3},{"url":"https://coinpaper.com/2875/over-8-4-million-stolen-in-crypto-exploits-within-a-single-week","name":"coinpaper.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Peapods Finance has undergone multiple security audits. SourceHat conducted an audit published on December 5, 2023, which identified two high-severity findings and five low-severity findings, all of which were reported as resolved by January 11, 2024. The high-severity findings related to share calculation disadvantaging early depositors in multi-asset indexes, and a vulnerability allowing a malicious user to manipulate the initial bond call to cause subsequent minting to return zero tokens. A low-severity TWAP oracle window of 5 minutes was upgraded to 10 minutes as part of remediation. The overall SourceHat assessment was a 'PASS' rating, noting some centralized aspects remain. Additional audits were reportedly conducted by yAudit, Guardian, and Pashov, though detailed reports for those engagements were not verified in publicly accessible sources at the time of this investigation. A Sherlock audit contest for the Leveraged Volatility Farming upgrade was conducted in early 2025 with 84 independent auditors participating. One medium-severity finding from the Sherlock contest involved addInterest not updating interest accurately, potentially enabling users to claim rewards for periods during which they were not staked in LendingAssetVault. Notably, the July 2025 oracle manipulation exploit occurred after these audits were completed, suggesting that oracle configuration risk in permissionlessly created Pods was not fully mitigated by the audit process. The Peapods team attributed that incident to a user configuration issue rather than a core contract vulnerability, a claim that was not independently verified by a published post-mortem at the time of this investigation.","heading":"Audit History and Security Posture","sources":[{"url":"https://sourcehat.com/audits/PeapodsFinance/","name":"sourcehat.com","type":"other","credibility":3},{"url":"https://github.com/sherlock-audit/2025-01-peapods-finance","name":"github.com","type":"other","credibility":3},{"url":"https://audits.sherlock.xyz/contests/749","name":"audits.sherlock.xyz","type":"other","credibility":3},{"url":"https://x.com/PeapodsFinance/status/1891971076936347935","name":"x.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The PEAS token launched in December 2023 via a fair-launch model with a fixed total supply of 10 million tokens, all minted and distributed at TGE. The distribution allocated 88% to Uniswap V3 PEAS/DAI liquidity positions (split between a concentrated range and a full-range position) and 12% to the team across six recipients, fully vested at launch. The token reached an all-time high of approximately $11.21–$11.74 (sources vary slightly) around late January 2024, just weeks after launch, implying a peak market capitalization in the range of $110–$117 million. As of mid-2025, PEAS trades at approximately $0.56–$0.60, representing a decline of approximately 95% from its all-time high. Current market capitalization is approximately $5.5–$6 million against a circulating supply of approximately 9.93 million PEAS. The protocol's TVL similarly declined from a peak in early 2024 to approximately $1.9 million across six chains by mid-2025, with Ethereum representing the largest single-chain concentration. The token incorporates a deflationary burn mechanism: protocol fees are used to buy PEAS from the open market, a portion of which is distributed to liquidity providers and the remainder burned. The team's 12% allocation was fully vested at TGE, which in principle eliminates future team unlock selling pressure but also means there are no vesting constraints on team-held tokens.","heading":"Token Economics and Market Performance","sources":[{"url":"https://docs.peapods.finance/peas-tokenomics","name":"docs.peapods.finance","type":"other","credibility":3},{"url":"https://defillama.com/protocol/peapods-finance","name":"defillama.com","type":"other","credibility":3},{"url":"https://www.coingecko.com/en/coins/peapods-finance","name":"coingecko.com","type":"other","credibility":3},{"url":"https://coinmarketcap.com/currencies/peapods-finance/","name":"coinmarketcap.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Peapods Finance carries several categories of risk that prospective users should evaluate. First, the protocol has experienced three distinct security incidents in under two years of operation — a pattern that raises questions about the robustness of its security practices despite multiple third-party audits. Second, the permissionless Pod creation model means that any user can deploy a Pod with custom oracle configurations; the July 2025 exploit exploited a misconfigured oracle in one such Pod, illustrating systemic risk from user-deployed infrastructure that core contract audits may not fully cover. Third, the Leveraged Volatility Farming (LVF) product introduces liquidation risk: positions are liquidated when LTV exceeds 83.33%, and liquidation prices are dynamic — if the paired asset strengthens against pTKN, the liquidation threshold rises. High borrowing utilization periods can also cause interest rates to spike sharply. Fourth, the protocol's TVL of approximately $1.9 million as of mid-2025 represents thin liquidity that could amplify price impact during stress events. Fifth, the use of 100% slippage tolerance in certain DEX swap pathways — acknowledged in the Sherlock audit scope — represents a design choice that relies on low transaction values to deter sandwich attacks, which may not hold in all market conditions. Finally, the PEAS token's 95% decline from ATH limits the effectiveness of fee-buyback-and-burn mechanics as a value accrual mechanism in the current market environment.","heading":"Protocol Risk Factors","sources":[{"url":"https://docs.peapods.finance/leveraged-volatility-farming-lvf","name":"docs.peapods.finance","type":"other","credibility":3},{"url":"https://docs.peapods.finance/liquidations-lvf","name":"docs.peapods.finance","type":"other","credibility":3},{"url":"https://docs.peapods.finance/risk-ownership-borrowers","name":"docs.peapods.finance","type":"other","credibility":3},{"url":"https://github.com/sherlock-audit/2025-01-peapods-finance","name":"github.com","type":"other","credibility":3},{"url":"https://quadrigainitiative.com/casestudy/peapodsfinanceasplongsusdepricemanipulationattack.php","name":"quadrigainitiative.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2023-12-11","event":"PEAS token launches on Ethereum via fair-launch model; 88% of supply deployed to Uniswap V3 PEAS/DAI liquidity pools, 12% distributed to team fully vested at TGE.","source":""},{"date":"2023-12-13","event":"Reentrancy exploit on WeightedIndex contract drains $231,192 (104.47 ETH) in PEAS tokens. Exploiter later identified by ZachXBT as likely axxe.eth via timing analysis linking the address to FixedFloat transactions.","source":""},{"date":"2023-12-14","event":"Peapods Finance announces ~90% of stolen funds returned; characterizes incident as 'white hat hack.' ZachXBT publishes on-chain evidence that the exploiter had dumped a portion of stolen funds through FixedFloat before returning the majority.","source":""},{"date":"2023-12-15","event":"Alleged exploiter @0xaxxe tweets that white hat fee was returned to the Peapods team.","source":""},{"date":"2024-01-11","event":"SourceHat audit of Peapods Finance finalizes. All identified high- and low-severity findings reported as resolved. Protocol receives overall 'PASS' rating.","source":""},{"date":"2024-01-26","event":"PEAS token reaches all-time high of approximately $11.21–$11.74, implying a peak market capitalization of approximately $110–$117 million.","source":""},{"date":"2025-02-08","event":"Second exploit: slippage manipulation attack on depositFromPairedLpToken function in legacy Pod code drains approximately $3,500. Peapods team states affected Pod will be reimbursed; notes the vulnerability was in a deprecated version.","source":""},{"date":"2025-02-15","event":"Peapods Finance announces conclusion of Sherlock audit contest for Leveraged Volatility Farming upgrade; 84 independent auditors participated. Contest prize pool was 120,000 USDC.","source":""},{"date":"2025-07-08","event":"Third exploit: oracle price manipulation attack on WETH/aspLONGsUSDe Pod drains approximately 78 ETH ($207,000). Attacker routes funds through ChangeNow and FixedFloat. Second attack attempt is front-run by MEV bot Yoink. Multiple security firms including SlowMist, CertiK, PeckShield, and TenArmor flag the incident. Peapods team attributes breach to 'bad oracle configuration' in a user-created Pod.","source":""}],"sources_used":[{"url":"https://docs.peapods.finance/","name":"docs.peapods.finance","type":"other","archive_url":"http://web.archive.org/web/20260707142932/https://docs.peapods.finance/","credibility":3,"archive_timestamp":"2026-07-07T14:29:32+00:00"},{"url":"https://docs.peapods.finance/peas-tokenomics","name":"docs.peapods.finance","type":"other","archive_url":"http://web.archive.org/web/20260718183733/https://docs.peapods.finance/peas-tokenomics","credibility":3,"archive_timestamp":"2026-07-18T18:37:33+00:00"},{"url":"https://defillama.com/protocol/peapods-finance","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20250917111812/https://defillama.com/protocol/peapods-finance","credibility":3,"archive_timestamp":"2025-09-17T11:18:12+00:00"},{"url":"https://docs.peapods.finance/leveraged-volatility-farming-lvf","name":"docs.peapods.finance","type":"other","archive_url":"http://web.archive.org/web/20260718183733/https://docs.peapods.finance/leveraged-volatility-farming-lvf","credibility":3,"archive_timestamp":"2026-07-18T18:37:33+00:00"},{"url":"https://github.com/liqtags/crypto-rekts/blob/main/rekts/Peapods-Finance-Exploit.md","name":"github.com","type":"other","archive_url":"https://web.archive.org/web/20260829080149/https://github.com/liqtags/crypto-rekts/blob/main/rekts/Peapods-Finance-Exploit.md","credibility":3,"archive_timestamp":"2026-08-29T08:01:49+00:00"},{"url":"https://x.com/zachxbt/status/1735025990819049968","name":"x.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://coinpaper.com/2875/over-8-4-million-stolen-in-crypto-exploits-within-a-single-week","name":"coinpaper.com","type":"other","archive_url":"http://web.archive.org/web/20260217145210/https://coinpaper.com/2875/over-8-4-million-stolen-in-crypto-exploits-within-a-single-week","credibility":3,"archive_timestamp":"2026-02-17T14:52:10+00:00"},{"url":"https://hacked.slowmist.io/?c=ETH&page=6","name":"hacked.slowmist.io","type":"other","archive_url":"https://web.archive.org/web/20260829033648/https://hacked.slowmist.io/?c=ETH&page=6","credibility":3,"archive_timestamp":"2026-08-29T03:36:48+00:00"},{"url":"https://blog.solidityscan.com/peapods-finance-hack-analysis-bdc5432107a5","name":"blog.solidityscan.com","type":"other","archive_url":"http://web.archive.org/web/20260512191052/https://blog.solidityscan.com/peapods-finance-hack-analysis-bdc5432107a5/","credibility":3,"archive_timestamp":"2026-05-12T19:10:52+00:00"},{"url":"https://getfailsafe.com/peapods-finance-hack-200k-exploit-what-happened-and-and-how-to-stay-safe/","name":"getfailsafe.com","type":"other","archive_url":"http://web.archive.org/web/20260521170959/https://getfailsafe.com/peapods-finance-hack-200k-exploit-what-happened-and-and-how-to-stay-safe","credibility":3,"archive_timestamp":"2026-05-21T17:09:59+00:00"},{"url":"https://quadrigainitiative.com/casestudy/peapodsfinanceasplongsusdepricemanipulationattack.php","name":"quadrigainitiative.com","type":"other","archive_url":"http://web.archive.org/web/20260422112706/https://quadrigainitiative.com/casestudy/peapodsfinanceasplongsusdepricemanipulationattack.php","credibility":3,"archive_timestamp":"2026-04-22T11:27:06+00:00"},{"url":"https://thedefiant.io/news/defi/peapods-finance-token-slips-5-percent-on-reported-oracle-issue","name":"thedefiant.io","type":"other","archive_url":"http://web.archive.org/web/20251220031512/https://thedefiant.io/news/defi/peapods-finance-token-slips-5-percent-on-reported-oracle-issue","credibility":3,"archive_timestamp":"2025-12-20T03:15:12+00:00"},{"url":"https://www.ccn.com/news/technology/this-week-crypto-hacks-gmx-peapods-finance-exploited/","name":"ccn.com","type":"other","archive_url":"http://web.archive.org/web/20260322135010/https://www.ccn.com/news/technology/this-week-crypto-hacks-gmx-peapods-finance-exploited/","credibility":3,"archive_timestamp":"2026-03-22T13:50:10+00:00"},{"url":"https://sourcehat.com/audits/PeapodsFinance/","name":"sourcehat.com","type":"other","archive_url":"https://web.archive.org/web/20260829041626/https://sourcehat.com/audits/PeapodsFinance/","credibility":3,"archive_timestamp":"2026-08-29T04:16:26+00:00"},{"url":"https://github.com/sherlock-audit/2025-01-peapods-finance","name":"github.com","type":"other","archive_url":"https://web.archive.org/web/20260829080219/https://github.com/sherlock-audit/2025-01-peapods-finance","credibility":3,"archive_timestamp":"2026-08-29T08:02:19+00:00"},{"url":"https://audits.sherlock.xyz/contests/749","name":"audits.sherlock.xyz","type":"other","archive_url":"http://web.archive.org/web/20260123083855/https://audits.sherlock.xyz/contests/749","credibility":3,"archive_timestamp":"2026-01-23T08:38:55+00:00"},{"url":"https://x.com/PeapodsFinance/status/1891971076936347935","name":"x.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.coingecko.com/en/coins/peapods-finance","name":"coingecko.com","type":"other","archive_url":"http://web.archive.org/web/20260629120338/https://www.coingecko.com/en/coins/peapods-finance","credibility":3,"archive_timestamp":"2026-06-29T12:03:38+00:00"},{"url":"https://coinmarketcap.com/currencies/peapods-finance/","name":"coinmarketcap.com","type":"other","archive_url":"http://web.archive.org/web/20260215055908/https://coinmarketcap.com/currencies/peapods-finance/","credibility":3,"archive_timestamp":"2026-02-15T05:59:08+00:00"},{"url":"https://docs.peapods.finance/liquidations-lvf","name":"docs.peapods.finance","type":"other","archive_url":"http://web.archive.org/web/20260718183733/https://docs.peapods.finance/liquidations-lvf","credibility":3,"archive_timestamp":"2026-07-18T18:37:33+00:00"},{"url":"https://docs.peapods.finance/risk-ownership-borrowers","name":"docs.peapods.finance","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:22.521906+00:00","updated_at":"2026-08-29T09:21:03.826413+00:00"}}