Perpy Hack
What happened
On May 6, 2024, an attacker exploited Perpy Finance's staking contract. The team noticed a heavy PRY sell-off and user reports that the staking module had stopped working. The attacker took control of the liquid staking module and withdrew 58,489,594 PRY, which was then swapped for about 41.895 ETH (roughly $132K at the time, per Quadriga Initiative).
The liquid staking module had been added after Perpy's audit. It was a fork of a vested staking design previously audited and used by Camelot, and the team decided not to audit the fork because it considered the change low risk. The flaw was an error in how the module's proxy contract was initialized.
Perpy paused the staking contract, bought back the dumped PRY on the market and redistributed it to affected stakers so their staked balances were restored, at a treasury cost of about 170K USDC. It also commissioned a PeckShield audit before reopening liquid staking.
How it happened
- Perpy deployed a liquid staking module behind a proxy. The module was unaudited code added after the protocol's audit.
- The proxy was not initialized correctly, which let the attacker update the contract, according to Perpy's own post-incident update.
- With control of the module, the attacker withdrew 58,489,594 PRY belonging to stakers.
- The attacker sold the PRY for about 41.895 ETH, crashing the token price.
- Perpy paused staking and used about 170K USDC from its treasury to buy back PRY and restore stakers' balances.
Protocol details
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.