Purrlend Hack
What happened
On April 25, 2026, Purrlend was affected across its HyperEVM and MegaETH deployments. Recoveris reported an estimated $1.52 million in real assets taken after a compromise of the protocol’s 2-of-3 administrator multisignature wallet.
Reporting attributes the incident to the compromised 2-of-3 administrator multisignature wallet, which had no timelock and was used to grant a malicious address BRIDGE_ROLE access.
How it happened
Recoveris reported that the malicious role holder used mintUnbacked to create unbacked pUSDm and pUSDC, then supplied those tokens as collateral to borrow real assets from the HyperEVM and MegaETH deployments.
Protocol details
Evidence
- report @purrlend incident report x.com
- report Purrlend incident report recoveris.io
- analysis DeFiLlama defillama.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.