CryptoReal
CASE FILE — Sep 4, 2024

Fake Pendle Market Lets Attacker Siphon $27M From Penpie's Reward Contracts

On September 3, 2024, Penpie, a yield-farming protocol built on top of the Pendle Finance ecosystem, lost approximately $27 million to an exploit. The fallout hit token prices almost immediately: PNP dropped roughly 40%, while PENDLE fell about 9% as the market reacted to the news.

The first public warning came from researcher Chaofan Shou, who posted that Penpie appeared to have been hacked for an estimated $17 million. Within twenty minutes, security firm Cyvers reported that the real figure was closer to $27 million.

Pendle Finance, whose infrastructure underpins Penpie, stated that its own funds were not at risk, but paused all of its contracts as a precaution regardless. Penpie followed with its own acknowledgment of a "security compromise" and froze deposits and withdrawals platform-wide.

According to PeckShield's analysis, the exploit hinged on "the introduction of an evil market that was used to inflate the staking balance to claim unwarranted rewards" — in other words, the attacker set up a counterfeit Pendle market and used it to convince Penpie's contracts they were interacting with a genuine one. Ancilia's writeup pinned the underlying flaw to Penpie's batchHarvestMarketRewards() function.

Mechanically, the attack was a reentrancy exploit. The attacker registered the fake Pendle market, then triggered the harvest function; when that function's call to redeemRewards() executed, the attacker's contract intervened mid-call to claim rewards a second time before the original balance update completed — effectively double-dipping to inflate their staking position and extract rewards they had no legitimate claim to.

Sums referenced in this case file

Exploit transaction: 0x56e09abb35ff12271fdb38ff8a23e4d4a7396844426a94c4d3af2e8b7a0a2813

Exploiter addresses: 0x7a2f4d625fb21f5e51562ce8dc2e722e12a61d1b, 0xc0Eb7e6E2b94aA43BDD0c60E645fe915d5c6eb84

Fake Pendle market: 0x0ab305033592E16dB7D8e77d613F8d172a76ddc9

Attack contracts: Arbitrum — 0x4BC9815b859c8172CEe1ab2CD372fD0Eb00eb487; Ethereum — 0x4aF4C234B8CB6e060797e87AFB724cfb1d320Bb7

Notably, Penpie had previously gone through audits from both WatchPug and Zokyo, yet neither review caught the vulnerability that was ultimately exploited.

Following the incident, Penpie addressed the attacker directly on X in what appeared to be an attempt to negotiate a return of funds. Pendle also published a post-mortem on Penpie's behalf, noting that $105 million in assets had remained safe, though it did not specify what exactly had been stolen or lay out the technical details of the exploit.

The incident adds to a recurring pattern in DeFi: protocols integrating deeply with external contracts remain exposed to attack surfaces that audits do not always catch, particularly around reward-claiming logic and reentrancy in cross-protocol calls.

Penpie
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.