media="print" onload="this.media='all'" />
The Counterparty

Penpie Exploit (2024) event

Event · PageRank 0.0015

Overview

On 3 September 2024, Penpie, a yield-enhancement layer built atop Pendle, suffered an exploit resulting in losses of approximately $27 million. The attacker exploited an unprotected registerPenpiePool function to register a counterfeit Pendle market, then used reentrancy within batchHarvestMarketRewards to artificially inflate reward balances across genuine pools and withdraw significantly more than entitled. The vulnerability existed in Penpie's own smart contracts; Pendle's core protocol remained uncompromised, although Pendle temporarily paused its contracts as a precautionary measure.

Within The Counterparty graph, Penpie Exploit (2024) connects to 2 tracked entities, most strongly to Penpie, Penpie.

Relations

Top connections in The Counterparty knowledge graph (confidence-weighted, 2 of 2 total).

RelationConnected entityConfidence
affectedPenpie95%
suffered_exploitPenpie95%

Sources

Facts in this record were checked against the following. Where a claim is not covered here, the record states only what the graph holds.

Questions on the record

How much was stolen from Penpie?

Approximately $27 million on 3 September 2024.