Penpie Exploit (2024) event
Overview
Penpie, a yield-boosting protocol built on top of Pendle, was exploited on 3 September 2024 for roughly $27 million. The attacker used an unguarded registerPenpiePool function to register a fake Pendle market, then triggered reentrancy inside batchHarvestMarketRewards to inflate reward accounting across legitimate pools and withdraw far more than was owed. It was a vulnerability in Penpie's own contracts; Pendle's core protocol was not itself compromised, though Pendle paused contracts as a precaution.
Within the DeFi Intel graph, Penpie Exploit (2024) connects to 2 tracked entities, most strongly to Penpie, Penpie.
Relations
Top connections in the DeFi Intel knowledge graph (confidence-weighted, 2 of 2 total).
| Relation | Connected entity | Confidence |
|---|---|---|
affected | Penpie | 95% |
suffered_exploit | Penpie | 95% |
Frequently asked questions
How much was stolen from Penpie?
Approximately $27 million on 3 September 2024.
What was the vulnerability?
A reentrancy flaw: the attacker registered a fake market via an unprotected registerPenpiePool function and then re-entered batchHarvestMarketRewards to manipulate reward accounting.
Was Pendle itself hacked?
No. The flaw was in Penpie's contracts, which are built on top of Pendle; Pendle's core protocol was not the source of the bug.
Sources
Facts on this page were verified against the following sources.