DeFi Intel

Penpie Exploit (2024) event

Event · PageRank 0.0015

Overview

Penpie, a yield-boosting protocol built on top of Pendle, was exploited on 3 September 2024 for roughly $27 million. The attacker used an unguarded registerPenpiePool function to register a fake Pendle market, then triggered reentrancy inside batchHarvestMarketRewards to inflate reward accounting across legitimate pools and withdraw far more than was owed. It was a vulnerability in Penpie's own contracts; Pendle's core protocol was not itself compromised, though Pendle paused contracts as a precaution.

Within the DeFi Intel graph, Penpie Exploit (2024) connects to 2 tracked entities, most strongly to Penpie, Penpie.

Relations

Top connections in the DeFi Intel knowledge graph (confidence-weighted, 2 of 2 total).

RelationConnected entityConfidence
affectedPenpie95%
suffered_exploitPenpie95%

Frequently asked questions

How much was stolen from Penpie?

Approximately $27 million on 3 September 2024.

What was the vulnerability?

A reentrancy flaw: the attacker registered a fake market via an unprotected registerPenpiePool function and then re-entered batchHarvestMarketRewards to manipulate reward accounting.

Was Pendle itself hacked?

No. The flaw was in Penpie's contracts, which are built on top of Pendle; Pendle's core protocol was not the source of the bug.

Sources

Facts on this page were verified against the following sources.