📈 Get daily crypto insights that make you smarter about your money

Penpie Protocol Drained of $27 Million in Sophisticated Reentrancy Attack

On September 3, 2024, the decentralized finance ecosystem suffered one of its most significant security breaches of the year when Penpie, a yield-enhancement protocol built on the Pendle platform, was exploited for approximately $27 million. The attack exposed critical vulnerabilities in reward distribution mechanisms and served as yet another stark reminder of the risks inherent in DeFi smart contract deployment.

The Exploit Mechanics

The attacker exploited a reentrancy vulnerability in Penpie’s _harvestBatchMarketRewards function, a core component of the protocol’s staking reward system. Reentrancy attacks occur when an external contract is able to call back into the vulnerable function before the initial execution completes, allowing the attacker to manipulate state variables that have not yet been updated.

In this specific case, the attacker deployed a malicious smart contract classified as an “evil market” on the platform. This contract was designed to artificially inflate the attacker’s staking balance on Penpie. By repeatedly calling the vulnerable reward harvesting function before the protocol could update the underlying stake records, the attacker amplified their apparent holdings to claim a significantly larger share of rewards than legitimately entitled to.

The exploited function lacked adequate reentrancy guards — a well-known class of protections that prevent recursive calls during critical state changes. Without these safeguards, the attacker could execute multiple withdrawal cycles within a single transaction, draining millions in crypto assets including ETH and various ERC-20 tokens from the protocol’s liquidity pools.

Affected Systems

Penpie operates as a decentralized application on Ethereum and Arbitrum, built on top of the Pendle Finance platform. The breach impacted users who had staked assets in Penpie’s yield-enhancement vaults. Following the discovery of the exploit, the Penpie team immediately suspended all deposits and withdrawals across the platform, halting operations to prevent further losses.

With Bitcoin trading at approximately $57,431 and Ethereum at $2,420 at the time of the attack, the broader market was already experiencing significant downward pressure. The Penpie exploit added to the negative sentiment, contributing to concerns about DeFi protocol safety during a period of heightened market volatility.

The stolen funds — totaling roughly $27 million — were quickly moved through Tornado Cash, a sanctioned cryptocurrency mixer that obscures transaction origins. Approximately $7 million was laundered through the mixer within hours of the attack, according to blockchain analytics reports.

The Mitigation Strategy

In the immediate aftermath, Penpie’s response team took several steps to contain the damage. The protocol filed official complaints with both the Singapore Police Force and the United States Federal Bureau of Investigation, seeking law enforcement assistance in tracing and recovering the stolen assets.

The team also sent an on-chain message to the attacker, offering a negotiated bounty payment in exchange for the safe return of funds. “We acknowledge your exploit of our protocol,” the message read. “Please contact us to discuss terms confidentially. No legal action will be pursued if the funds are returned.” This approach mirrors strategies employed by other DeFi protocols that have successfully negotiated with hackers in the past.

However, the Penpie hacker showed no intention of returning the stolen assets. In a bizarre twist, the infamous Euler Finance hacker — responsible for a $195 million DeFi heist in 2023 — left an on-chain message praising the Penpie attacker for keeping the funds.

Lessons Learned

The Penpie exploit underscores several critical lessons for the DeFi ecosystem. First, reentrancy vulnerabilities remain one of the most common and devastating attack vectors in smart contract security. Despite being a well-understood class of bugs since the infamous DAO hack of 2016, protocols continue to fall victim to insufficient reentrancy protections.

Second, the speed at which stolen funds were laundered through Tornado Cash highlights the challenges of fund recovery in DeFi. Even with law enforcement involvement, the use of mixing services makes tracing and recovering stolen assets extremely difficult.

Third, the total value lost to crypto hacks in 2024 surpassed $1.2 billion by September, representing a 15.5% increase over the previous year. This upward trend in losses demands a fundamental rethinking of how DeFi protocols approach security auditing and deployment.

User Action Required

If you were a user of Penpie protocol, you should immediately revoke any token approvals granted to Penpie smart contracts. Monitor the official Penpie communication channels for updates on fund recovery efforts and potential reimbursement plans. All DeFi users should regularly review their active token allowances using tools like Revoke.cash or similar platforms, and never grant unlimited approvals unless absolutely necessary.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before engaging with any DeFi protocol.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

25 thoughts on “Penpie Protocol Drained of $27 Million in Sophisticated Reentrancy Attack”

  1. evil market contract is a nasty trick. you trust the protocol to handle market registration and the attacker weaponizes that trust

    1. the evil market trick is clever from the attacker side. register a legitimate-looking market, inflate balance, drain rewards. trust was the vulnerability

  2. Another reentrancy bug in 2024. This was literally the DAO hack vector from 2016. How are teams still shipping code without checks-effects-interactions?

    1. checks-effects-interactions doesnt save you when the contract architecture itself lets external contracts register as markets. the bug was deeper than a missing guard

    2. the DAO hack was 2016 and penpie was 2024. 8 years and devs still ship the same vulnerability. unreal

      1. 8 years and reentrancy is still the #1 exploit vector. at some point you have to blame the hiring pipeline not the language

        1. 8 years and reentrancy is still the #1 exploit vector. at some point you have to blame the hiring pipeline not the language

      2. bugreport_ the DAO hack was 2016 and we are still seeing the same bug in 2024. the issue isnt hiring, its that teams copy paste yield logic without understanding the state machine they are building on

        1. reentrancy_kep_

          rekt_codex_ exactly. same bug class since DAO 2016. the tooling exists, slither and mythril catch these. teams just do not run them on integration contracts before going live

  3. the evil market exploit on _harvestBatchMarketRewards is classic reentrancy. checks-effects-interactions exists for exactly this reason

  4. 27M gone because reward harvesting had no reentrancy guard. this was a known pattern since the DAO hack in 2016. inexcusable

    1. reentrancy_void_

      Petros L. no reentrancy guard on a reward harvesting function in 2024. the DAO hack was 8 years earlier. there is no excuse

    2. stake_cap_ghost_

      Petros L. the malicious contract inflating staking balance before the protocol updated state is the same trick used on Cream last year. nothing new

  5. I had a small position in Pendle that I pulled out when Penpie launched. Something about restaking on top of yield trading felt like stacking risk unnecessarily.

  6. the evil market registration is the part that gets me. no whitelist, no vetting. anyone could deploy arbitrary contracts that interact with the harvest function

    1. Ravi S. no whitelist for market registration on a 27M protocol is insane. letting anyone deploy arbitrary contracts that touch reward functions is asking for this exact attack

  7. The _harvestBatchMarketRewards function was clearly missing proper state updates before external calls. Attacker registers evil market, inflates balance, then drains $27M before records catch up. Classic reentrancy but executed on market registration trust.

  8. Penpie lost $27 million on Sept 3 because anyone could deploy a malicious smart contract as a market. Inflating staking balance and hammering the harvest function before updates is exactly why market registration needs strict controls.

  9. Penpie built on top of Pendle which is already complex yield trading. adding a restaking layer on that is just stacking assumption on top of assumption. one breaks and the whole thing collapses

    1. yield_stack_skeptic_

      Marina C. stacking yield protocols is literally multiplying attack surfaces. penpie on pendle was always a ticking bomb

    2. Marina C. this is exactly why I pulled out of Pendle ecosystem stuff entirely. stacking yield protocols is just multiplying your attack surface for marginal extra gains

      1. static_analysis_fan_

        0xhalvening stacking yield protocols is the issue. each layer adds a new attack surface. penpie on pendle was always going to be a target

        1. static_analysis_fan_ stacking yield protocols multiplies attack surface exponentially. penpie on pendle was always one bug away from disaster

          1. Sofie K. stacking yield is the DeFi equivalent of collateralized debt obligations. each layer assumes the one below is safe. one breaks and the cascade takes everything

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$77,339.00+0.0%ETH$2,508.42-0.8%SOL$101.08-1.0%BNB$721.05-1.4%XRP$1.36-1.0%ADA$0.20840.0%DOGE$0.0845-0.6%DOT$1.03-1.1%AVAX$7.43+0.2%LINK$11.41-1.0%UNI$6.36+0.3%ATOM$1.61-1.4%LTC$54.76+1.5%ARB$0.1404-0.7%NEAR$2.35-1.8%FIL$1.02+26.1%SUI$0.7201-0.9%BTC$77,339.00+0.0%ETH$2,508.42-0.8%SOL$101.08-1.0%BNB$721.05-1.4%XRP$1.36-1.0%ADA$0.20840.0%DOGE$0.0845-0.6%DOT$1.03-1.1%AVAX$7.43+0.2%LINK$11.41-1.0%UNI$6.36+0.3%ATOM$1.61-1.4%LTC$54.76+1.5%ARB$0.1404-0.7%NEAR$2.35-1.8%FIL$1.02+26.1%SUI$0.7201-0.9%
Scroll to Top