Penpie $27M Hack event
Overview
On 3 September 2024, Penpie, a yield-boosting protocol built on Pendle, was exploited for approximately $27 million. The attacker leveraged an unprotected pool-registration function to create a fraudulent Pendle market, then exploited a reentrancy vulnerability in the batch reward-harvesting mechanism to manipulate reward accounting and drain assets. Pendle's contracts were not responsible for the flaw, but Pendle temporarily suspended affected functionality as a precaution during the investigation.
Within The Counterparty graph, Penpie $27M Hack connects to 1 tracked entity, most strongly to Ethereum.
Relations
Top connections in The Counterparty knowledge graph (confidence-weighted, 1 of 1 total).
| Relation | Connected entity | Confidence |
|---|---|---|
deployed_on | Ethereum | 85% |
Sources
Facts in this record were checked against the following. Where a claim is not covered here, the record states only what the graph holds.
Questions on the record
When did the Penpie hack occur?
3 September 2024.
How much was lost?
Around $27 million in crypto assets.