$105M Saved After DeFi Protocol Hacked For $27M
On Tuesday, September 3, 2024, an independent yield optimizer operating within the decentralized finance sector was subjected to an exploit that drained $27 million in digital assets. Following the incident, the underlying protocol developer claimed that its rapid intervention successfully safeguarded approximately $105 million in user funds from being compromised.
The attack targeted Penpie, a platform that functions as an independent yield optimizer on top of the decentralized finance protocol Pendle. The malicious activity occurred in a narrow timeframe, taking place across three distinct transactions executed between 6:25 P.M. and 6:42 P.M. UTC. The initial transaction resulted in the heaviest financial damage, draining $15.7 million from the protocol. This was immediately followed by two subsequent transactions that extracted $5.6 million each.
Blockchain security firm PeckShield conducted an analysis of the event and reported that the root cause was a smart contract vulnerability. This flaw permitted the permissionless listing of an "evil market", a malicious contract specifically designed to artificially inflate the attacker's staking balances. To achieve this, the exploiter generated valueless versions of Pendle's Standardized Yield (SY) tokens, utilizing them to trick the rewards system of the protocol into releasing funds.
Tracking the Missing Assets
During the preparation phase of the attack, the exploiter deployed five separate malicious contracts designed to act as legitimate liquidity pools. However, the attacker ultimately required only three of those contracts to successfully execute the exploit.

Following the theft, the drained tokens were converted into roughly 10,113 ETH. On-chain data indicates that the attacker then transferred 3,000 ETH to Tornado Cash, a cryptocurrency mixer frequently used to obscure transaction trails. The exploiter currently holds a remaining balance of 7,113.27 ETH.
Early on Wednesday morning, Pendle published a detailed post-mortem regarding the event. The developer noted that its in-house monitoring system actually detected the suspicious contract prior to the exploit, flagging that it had been funded via Tornado Cash. Despite this early detection, the system could not prevent the initial attack from being carried out.
Contract Pauses and Negotiations
In response to the active threat, Pendle confirmed it had promptly paused its contracts to mitigate any further damage. Blockchain security firm Hacken emphasized the timing of this action. "This was crucial, as the attacker deployed a fourth malicious contract only a minute later. Pausing Pendle's contracts effectively halted the exploit, preventing further loss," the firm stated.
With the threat contained, the protocol developer brought its systems back online. "Thanks to coordinated efforts from multiple parties, further breaches were mitigated, and Pendle contracts have now been unpaused. Normal operations have resumed," Pendle shared via its project team account on X.
In the aftermath of the $27 million loss, the Penpie team reached out directly to the exploiter. By sending both an on-chain message and an X post, Penpie acknowledged the hack and offered to negotiate a security bounty in exchange for the safe return of the stolen funds.


