Beosin: Analysis of the Attack on the DeFi Protocol Penpie Resulting in Approximately $27 Million in Asset Losses

Sep 11, 2024 15:38:01

Share to

ChainCatcher news, according to Beosin Alert monitoring, the DeFi protocol Penpie built on Pendle has been hacked, resulting in the theft of approximately $27 million in crypto assets. Beosin provides the following brief analysis of the incident:

The attacker exploited the claimRewards function in the market contract to re-enter the staking contract, increasing the staking contract balance, and then withdrew excess tokens and staked assets from the taking contract for profit.

  1. The attacker first created an attack contract and constructed the corresponding market contract through the official factory.
  2. Called the batchHarvestMarketRewards function of the staking contract to update rewards for the market.
  3. During the reward update, the attack contract's claimRewards function is called back, allowing for re-entry to stake the assets obtained from the flash loan, creating a discrepancy in the asset quantity of the staking contract, and withdrawing the excess.
  4. The attacker withdrew the staked assets and repaid the flash loan for profit.
Beosin: Analysis of the Attack on the DeFi Protocol Penpie Resulting in Approximately $27 Million in Asset Losses

Related Projects

Latest News

Data: BTC breaks through 92,000 USD

ChainCatcher

Jan 12, 2026 10:46:01

Data: BTC falls below 91,000 USD

ChainCatcher

Jan 12, 2026 08:34:41

Data: ETH breaks through 3100 USD

ChainCatcher

Jan 12, 2026 08:04:03

Data: ETH falls below 3100 USD

ChainCatcher

Jan 12, 2026 07:04:02

Data: SOL breaks through 140 USD

ChainCatcher

Jan 12, 2026 02:54:25

Recent Fundraising

More
$50M Dec 30, 2025
-- Dec 26, 2025

New Tokens

More
Dec 24, 2025
Dec 23, 2025
Dec 20, 2025

Latest Updates on 𝕏

More