Purrlend Hack

Reported loss $1.5M
Hyperliquid L1 Megaeth
Access Control

What happened

On April 25, 2026, Purrlend was affected across its HyperEVM and MegaETH deployments. Recoveris reported an estimated $1.52 million in real assets taken after a compromise of the protocol’s 2-of-3 administrator multisignature wallet.

Technical root cause

Reporting attributes the incident to the compromised 2-of-3 administrator multisignature wallet, which had no timelock and was used to grant a malicious address BRIDGE_ROLE access.

How it happened

Recoveris reported that the malicious role holder used mintUnbacked to create unbacked pUSDm and pUSDC, then supplied those tokens as collateral to borrow real assets from the HyperEVM and MegaETH deployments.

Protocol details

Classification Borrowing and Lending / Access Control
Protocol Type Lending
Implementation language Solidity
Protocol links Website @purrlend

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.