Friday, November 21, 2025
DIGESTWIRE
Contribute
CONTACT US
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
DIGESTWIRE
No Result
View All Result
Home Blockchain

Penpie exploited for $27 million in reentrancy attack

by DigestWire member
September 4, 2024
in Blockchain, Crypto Market, Cryptocurrency
0
Penpie exploited for $27 million in reentrancy attack
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Yield protocol Penpie got exploited for $27 million on Sept. 3 after a malicious agent explored a vulnerability in the protocol’s smart contracts.

Penpie is a yield protocol on Pendle that aims to boost rewards for users on the network.

Reentrancy exploited

In a Sept. 4 breakdown, blockchain security firm Hacken explained that the attacker used a pool with fake tokens to perform the heist. The exploiter created valueless versions of Pendle’s yield-bearing tokens, Standardized Yield (SY), and tied them to valuable assets.

The attacker deployed five malicious contracts to act as legitimate liquidity pools and trick Penpie’s rewards system, but only three of them were used. He then leveraged the fake SY tokens as tickets to claim real yield.

Three attack transactions were executed between 6:25 P.M. and 6:42 P.M. UTC. The first transaction extracted the highest amount, siphoning $15.7 million, followed by two other transactions that took $5.6 million each out of Penpie’s contract.

The exploiter got away with 695 Restaked Swell ETH (rswETH), 4,101 Kelp Gain (agETH), 2,723 Wrapped Staked ETH (wstETH), and 2.52 million Staked Ethena USD (sUSDe).

The remaining two malicious contracts deployed by the exploiter were not used in the attack, which was made possible due to a reentrancy vulnerability in Penpie’s contract.

A reentrancy vulnerability occurs when a contract needs to make an external call to another smart contract before updating its own state. Thus, malicious contracts can fool the protocol by changing information and inputting actions.

Notably, the losses could have been larger. Pendle identified the malicious transactions and paused its contracts at 6:45 P.M. UTC, three minutes after the third attack. Hacken highlighted:

“This was crucial, as the attacker deployed a fourth malicious contract only a minute later. Pausing Pendle’s contracts effectively halted the exploit, preventing further loss.”

The whole batch of tokens was converted to Ethereum (ETH), amounting to roughly 10,113 ETH. The exploiter transferred 3,000 ETH to the mixer service Tornado Cash and currently holds 7,113.27 ETH, according to on-chain data.

The Penpie team reached out to the exploited via an on-chain message and an X post acknowledging the hack and claiming to be open to negotiating a bounty in exchange for the funds stolen. Furthermore, they promised that no legal action would be pursued.

The post Penpie exploited for $27 million in reentrancy attack appeared first on CryptoSlate.

Read Entire Article
Tags: BlockchainCoin SurgesCryptoslate
Share30Tweet19
Next Post
25 Disney Facts That Are Truly Fascinating, And That You Might Not Know

25 Disney Facts That Are Truly Fascinating, And That You Might Not Know

Thailand’s Mahidol University Partners With Tether to Integrate Blockchain and Stablecoin Education

Thailand’s Mahidol University Partners With Tether to Integrate Blockchain and Stablecoin Education

Kamala Harris turns to Coinbase for crypto campaign donations, CFO reveals

Kamala Harris turns to Coinbase for crypto campaign donations, CFO reveals

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

No Result
View All Result
Coins MarketCap Live Updates Coins MarketCap Live Updates Coins MarketCap Live Updates
ADVERTISEMENT

Highlights

South Africa’s first G20 faces challenges over exclusion of its oldest communities

Bitcoin Core Gets First-Ever Third-Party Security Audit: These Are The Results

Dogecoin Price Prediction: Will DOGE Recover in December or Fall Further First?

Ripple News: XRP Price Breaks Below $2 Amid ETF Race, Bitwise Trails Canary

Bitcoin won’t hit $200K until Q3 2029: Veteran trader Peter Brandt

Billionaire Ray Dalio Issues Dire Bubble Warning as Wealth Gaps and Fiscal Strain Deepen

Trending

‘Next Year’ Trailer: ‘Fellow Travelers’ Star Jaleni Alladin Tries to Survive a Near-Future U.S. Where Homosexuality Is Outlawed (EXCLUSIVE)
Entertainment

‘Next Year’ Trailer: ‘Fellow Travelers’ Star Jaleni Alladin Tries to Survive a Near-Future U.S. Where Homosexuality Is Outlawed (EXCLUSIVE)

by DigestWire member
November 21, 2025
0

“Next Year” may be resonating in more ways than the filmmakers originally imagined. A trailer for the...

Inside the Variety CMA Awards Lounge: Conversations With Shaboozey, the Red Clay Strays, Tucker Wetmore, the War & Treaty, Megan Moroney and More Stars

Inside the Variety CMA Awards Lounge: Conversations With Shaboozey, the Red Clay Strays, Tucker Wetmore, the War & Treaty, Megan Moroney and More Stars

November 21, 2025
Eros Innovation Secures $150 Million, Expands AI-Media Platform (EXCLUSIVE)

Eros Innovation Secures $150 Million, Expands AI-Media Platform (EXCLUSIVE)

November 21, 2025
South Africa’s first G20 faces challenges over exclusion of its oldest communities

South Africa’s first G20 faces challenges over exclusion of its oldest communities

November 21, 2025
Bitcoin Core Gets First-Ever Third-Party Security Audit: These Are The Results

Bitcoin Core Gets First-Ever Third-Party Security Audit: These Are The Results

November 21, 2025
DIGEST WIRE

DigestWire is an automated news feed that utilizes AI technology to gather information from sources with varying perspectives. This allows users to gain a comprehensive understanding of different arguments and make informed decisions. DigestWire is dedicated to serving the public interest and upholding democratic values.

Privacy Policy     Terms and Conditions

Recent News

  • ‘Next Year’ Trailer: ‘Fellow Travelers’ Star Jaleni Alladin Tries to Survive a Near-Future U.S. Where Homosexuality Is Outlawed (EXCLUSIVE) November 21, 2025
  • Inside the Variety CMA Awards Lounge: Conversations With Shaboozey, the Red Clay Strays, Tucker Wetmore, the War & Treaty, Megan Moroney and More Stars November 21, 2025
  • Eros Innovation Secures $150 Million, Expands AI-Media Platform (EXCLUSIVE) November 21, 2025

Categories

  • Blockchain
  • Blog
  • Breaking News
  • Business
  • Cricket
  • Crypto Market
  • Cryptocurrency
  • Defense
  • Entertainment
  • Football
  • Founders
  • Health Care
  • Opinion
  • Politics
  • Sports
  • Strange
  • Technology
  • UK News
  • Uncategorized
  • US News
  • World

© 2020-23 Digest Wire. All rights belong to their respective owners.

No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Blockchain
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Strange
  • Blog
  • Founders
  • Contribute!

© 2024 Digest Wire - All right reserved.

Privacy Policy   Terms and Conditions

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.