Penpie Hack
What happened
On September 3, 2024, Penpie, a yield-boosting protocol integrated with Pendle, was exploited across Ethereum and Arbitrum for approximately $27 million. The attacker introduced a malicious Pendle market backed by a counterfeit Standardized Yield contract, then used its reward callback to corrupt Penpie's reward accounting. The incident affected Penpie's staking and reward-distribution system, not Pendle's core protocol.
Security analyses identify a missing reentrancy guard in Penpie's batch reward-harvesting path and insufficient validation of markets accepted by that path as the combined cause.
Penpie's batchHarvestMarketRewards path made an external reward-redemption call after recording balances but before finalizing reward accounting, without reentrancy protection. A malicious market could therefore re-enter during that callback and make deposits that appeared to the outer call as newly harvested rewards. The attack also depended on Penpie treating permissionlessly created Pendle markets as trusted reward sources.
Case & protocol details
Attack Timeline
Audit assessment
Review priorities based on the documented failure pattern in Penpie (September 2024).
Critical checks
- Verify every sensitive logic path is guarded by appropriate access controls and input validation - see the Reentrancy attack class for patterns
- Check that all state-changing functions follow the Checks-Effects-Interactions (CEI) pattern to prevent reentrancy and logic ordering bugs
Evidence & learning
Attack pattern
Compare incidents →Proof of concept
1 availableSources and on-chain records
- report Report x.com
- report Penpie Post-Mortem zokyo.io
- analysis Twitter/X Alert x.com
- analysis Twitter/X Alert x.com
- analysis Twitter/X Alert x.com
- analysis Twitter/X Alert x.com
- analysis Website reference x.com
- analysis Website reference x.com
- analysis Penpie Hack Analysis blog.solidityscan.com
- analysis Penpie Protocol Exploit quillaudits.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.