Penpie Hack

TOTAL LOST $27.0M
High Cross-contract reentrancy Ethereum Arbitrum
Chain Ethereum 2 networks affected
Recovered - No recovery reported
Loss Rank #200 All-time
Protocol Type Yield Target category

What happened

On September 3, 2024, Penpie, a yield-boosting protocol integrated with Pendle, was exploited across Ethereum and Arbitrum for approximately $27 million. The attacker introduced a malicious Pendle market backed by a counterfeit Standardized Yield contract, then used its reward callback to corrupt Penpie's reward accounting. The incident affected Penpie's staking and reward-distribution system, not Pendle's core protocol.

Security analyses identify a missing reentrancy guard in Penpie's batch reward-harvesting path and insufficient validation of markets accepted by that path as the combined cause.

Technical Root Cause

Penpie's batchHarvestMarketRewards path made an external reward-redemption call after recording balances but before finalizing reward accounting, without reentrancy protection. A malicious market could therefore re-enter during that callback and make deposits that appeared to the outer call as newly harvested rewards. The attack also depended on Penpie treating permissionlessly created Pendle markets as trusted reward sources.

Case & protocol details

Classification Reentrancy / untrusted market validation
Protocol Type Yield
Smart Contract Language Solidity
Official Website www.magpiexyz.io/earn
Protocol Twitter/X @Penpiexyz_io
Team Anonymous
Source Code Unverified

Market Context at Time of Hack

Token Categories
Ethereum Ecosystem Arbitrum Ecosystem BNB Chain Ecosystem

Attack Timeline

The attacker created a counterfeit Standardized Yield contract and used Pendle's permissionless market infrastructure to create a market that Penpie accepted for reward processing. They then invoked Penpie's batch reward-harvesting flow with the malicious market. That flow captured reward-token balances before making an external call to the market's reward-redemption logic. The malicious market used the callback opportunity to re-enter Penpie and deposit flash-loaned liquidity into legitimate Pendle markets. When the original harvest resumed, Penpie treated the balance increase as harvested rewards rather than newly deposited liquidity. The attacker was credited with inflated rewards, withdrew the resulting Pendle LP positions, redeemed them for underlying assets, repaid the flash loans, and retained the difference.

Audit assessment

Review priorities based on the documented failure pattern in Penpie (September 2024).

Critical checks

  • Verify every sensitive logic path is guarded by appropriate access controls and input validation - see the Reentrancy attack class for patterns
  • Check that all state-changing functions follow the Checks-Effects-Interactions (CEI) pattern to prevent reentrancy and logic ordering bugs

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.