Penpie $27M Hack event
Overview
The Penpie hack refers to the 3 September 2024 exploit of Penpie, a Pendle-based yield-boosting protocol, which lost roughly $27 million. The attacker exploited an unprotected pool-registration function to create a fake Pendle market and then used reentrancy in the batch reward-harvesting routine to manipulate reward accounting and drain funds. Pendle's own contracts were not the source of the bug, but Pendle paused affected functionality as a precaution while the incident was investigated.
Within the DeFi Intel graph, Penpie $27M Hack connects to 1 tracked entity, most strongly to Ethereum.
Relations
Top connections in the DeFi Intel knowledge graph (confidence-weighted, 1 of 1 total).
| Relation | Connected entity | Confidence |
|---|---|---|
deployed_on | Ethereum | 85% |
Frequently asked questions
When did the Penpie hack occur?
3 September 2024.
How much was lost?
Around $27 million in crypto assets.
How did the attacker do it?
By registering a fake market through an unguarded registerPenpiePool function and then re-entering batchHarvestMarketRewards to inflate reward accounting across legitimate pools.
Sources
Facts on this page were verified against the following sources.