Penpie Exploit (2024) event
Overview
On 3 September 2024, Penpie, a yield-enhancement layer built atop Pendle, suffered an exploit resulting in losses of approximately $27 million. The attacker exploited an unprotected registerPenpiePool function to register a counterfeit Pendle market, then used reentrancy within batchHarvestMarketRewards to artificially inflate reward balances across genuine pools and withdraw significantly more than entitled. The vulnerability existed in Penpie's own smart contracts; Pendle's core protocol remained uncompromised, although Pendle temporarily paused its contracts as a precautionary measure.
Within The Counterparty graph, Penpie Exploit (2024) connects to 2 tracked entities, most strongly to Penpie, Penpie.
Relations
Top connections in The Counterparty knowledge graph (confidence-weighted, 2 of 2 total).
| Relation | Connected entity | Confidence |
|---|---|---|
affected | Penpie | 95% |
suffered_exploit | Penpie | 95% |
Sources
Facts in this record were checked against the following. Where a claim is not covered here, the record states only what the graph holds.
Questions on the record
How much was stolen from Penpie?
Approximately $27 million on 3 September 2024.