{"investigation":{"slug":"penpie","entity_name":"Penpie","trust_score":10,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"Penpie is a yield-boosting DeFi protocol built on Pendle Finance by the Magpie DAO ecosystem, allowing users to earn boosted yields on Pendle liquidity pools without directly locking PENDLE tokens. On September 3, 2024, an attacker exploited a reentrancy vulnerability in Penpie's staking contract to drain approximately $27.3 million across Ethereum and Arbitrum, subsequently laundering all stolen funds through Tornado Cash and ignoring recovery appeals. The protocol filed reports with the FBI and Singapore Police but recovered no funds; a partial community compensation plan was proposed but not fully executed.","sections":[{"content":"Penpie is a sub-DAO within the Magpie ecosystem, first introduced in May 2023. It was designed to provide Pendle Finance users with yield-boosting and veTokenomics optimization without requiring them to lock PENDLE tokens directly. Penpie achieves this by accumulating and perpetually locking PENDLE tokens for two years on behalf of users, accruing vePENDLE voting power and distributing boosted yields via its mPENDLE liquid wrapper mechanism. Prior to the September 2024 exploit, Penpie represented approximately 35-36% of Pendle Finance's total value locked (TVL), making it one of the most significant third-party integrations in the Pendle ecosystem. The protocol had undergone prior security audits by Zokyo and WatchPug; however, a critical code path introduced via permissionless pool registration in May 2024 was not re-audited.","heading":"Background","sources":[{"url":"https://docs.magpiexyz.io/the-magpie-ecosystem/penpie-pendle-finance","name":"","type":"other","credibility":3},{"url":"https://docs.penpiexyz.io/penpie-ecosystem/introduction","name":"","type":"other","credibility":3},{"url":"https://www.auditone.io/blog-posts/the-penpie-hack-understanding-the-september-2024-reentrancy-exploit-and-the-role-of-auditing-in-defi-security","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On September 3, 2024, at approximately 6:23 PM UTC, an attacker exploited a reentrancy vulnerability in Penpie's PendleStakingBaseUpg::batchHarvestMarketRewards() function across both the Arbitrum and Ethereum networks. The attack was executed in three transactions between 6:25 PM and 6:42 PM UTC, with the first transaction alone siphoning approximately $15.7 million and the remaining two extracting approximately $5.6 million combined. The root cause was a combination of three security failures: (1) absence of reentrancy guards on the reward harvesting function; (2) lack of access controls on Pendle market registration, which had been made permissionless in a May 2024 update without re-evaluation of the security implications; and (3) insufficient input validation on pool contracts. The attacker created a malicious Pendle market containing counterfeit Standardized Yield (SY) tokens. By depositing flash-loaned assets — including wstETH, sUSDe, agETH, and rswETH borrowed from Balancer — into the malicious SY contract, the attacker minted fake Pendle Market LP tokens. These were deposited into Penpie's staking contract, and the attacker then repeatedly re-entered the batchHarvestMarketRewards() function before any state updates occurred, inflating reward balances and claiming them multiple times. The total amount stolen was approximately $27.348 million, subsequently converted into approximately 11,109.62 ETH. The Euler Finance exploiter sent an on-chain congratulatory message to the Penpie attacker. Moments after Penpie's contracts were frozen by the team, the attacker deployed a second malicious contract apparently targeting the remaining approximately $105 million still at risk, though this second attack was not executed.","heading":"The Reentrancy Exploit","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-penpie-hack-september-2024","name":"","type":"other","credibility":3},{"url":"https://threesigma.xyz/blog/exploit/penpie-reentrancy-exploit-analysis","name":"","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/penpie-protocol-exploited-suffers-27-million-loss","name":"","type":"other","credibility":3},{"url":"https://zokyo.io/blog/penpie-postmortem-analysis-of-the-27m-reentrancy-exploit/","name":"","type":"other","credibility":3},{"url":"https://invezz.com/news/2024/09/06/hacker-behind-27m-penpie-heist-applauded-by-euler-exploiter/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Blockchain analysis firms identified multiple attacker-controlled wallet addresses involved in the exploit and subsequent laundering. The primary attacker addresses identified by Three Sigma and other analysts include: 0x28e3fd9edca8fccb912fe3ab36c78f96cfc74769, 0x69751b7e52dbbd64281ec9049dfa623c7ecdeb52, 0x2f2dde668e5426463e05d795f5297db334f61c39, 0xd440d2c13e9c0b86f54da4f515f68c56f0c36cc3, 0x2dc15e0ff02f39d4d23a96d6ef2595df3d1e18a0, 0x10f8c81386a2563f687011f4ebc8f2091cb501e8, 0x8c37ad70ce51e54d2d75da40668e9530d337f26b, and 0x688413d6cae1c0e0882e274a98e0b901fdf7233c. The three primary exploit transactions on Arbitrum carry hashes: 0x56e09abb35ff12271fdb38ff8a23e4d4a7396844426a94c4d3af2e8b7a0a2813, 0x42b2ec27c732100dd9037c76da415e10329ea41598de453bb0c0c9ea7ce0d8e5, and 0x663b55a1ee992603f7636ef23ff5cf19d3b261ab81494d06e218c86482df5342. The attacker aggregated approximately 11,109.62 ETH into a consolidation wallet before beginning the laundering phase. On September 6, 2024, the attacker transferred 7,262 ETH ($17.4 million) to an intermediary address, which then routed 5,600 ETH ($13.4 million) through Tornado Cash. PeckShield confirmed that by September 8, 2024, the attacker had successfully laundered the full 11,261 ETH balance through Tornado Cash in batches of 100 ETH. No funds were recovered.","heading":"On-Chain Evidence","sources":[{"url":"https://threesigma.xyz/blog/exploit/penpie-reentrancy-exploit-analysis","name":"","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/penpie-protocol-hacker-launders-7m-tornado-cash","name":"","type":"other","credibility":3},{"url":"https://dailycoin.com/penpie-hacker-launders-last-batch-of-the-stolen-27m-ether","name":"","type":"other","credibility":3},{"url":"https://defi-planet.com/2024/09/penpie-protocol-hacker-reportedly-laundered-7m-through-tornado-cash-within-12-hours-of-27m-theft/","name":"","type":"other","credibility":3},{"url":"https://arbiscan.io/tx/0xe44a4e2c1812ff00db4902d61d1bc2815854b38d63e8fe605707614cb1675e79","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Within 20 minutes of the exploit being detected, the Pendle Finance team paused all Pendle contracts, which prevented the attacker from executing a second alleged attack on the remaining approximately $105 million in the protocol. Penpie also froze its own contracts in response. On September 4, 2024, Penpie sent an on-chain message to the attacker offering to drop legal action and protect the attacker's identity in exchange for return of the funds. The attacker did not respond and continued laundering. The Penpie team filed a police report with the Kampong Java Neighbourhood Police Centre in Singapore on September 3, 2024, and filed a complaint with the FBI's Internet Crime Complaint Center (IC3) on September 4, 2024. Penpie provided Singapore law enforcement with a VPN IP address used during the attack for investigation. No arrests have been publicly reported. On September 6, 2024, Penpie offered a 10% bounty to any party providing information leading to identification of the attacker. On October 7, 2024, Magpie published a compensation plan proposing distribution of approximately 27 million Safu Recovery Tokens (SRT) to affected users, backed by an allocation of 4% of MGP token supply (1% from team allocation and 3% from treasury). The plan also proposed directing 20% of Penpie's vePENDLE revenue and 20% of Magpie's overall monthly revenue toward buying back SRT tokens from the open market. The protocol resumed operations in October 2024. TVL fell approximately 65% in the five weeks following the exploit, from approximately $127.3 million to $44.9 million.","heading":"Recovery Efforts","sources":[{"url":"https://therecord.media/penpie-defi-protocol-ethereum-stolen","name":"","type":"other","credibility":3},{"url":"https://thedefiant.io/news/defi/penpie-proposes-compensation-plan-and-insurance-protocol-after-usd27m-exploit","name":"","type":"other","credibility":3},{"url":"https://finance.yahoo.com/news/defi-platform-pendle-claims-saved-134115901.html","name":"","type":"other","credibility":3},{"url":"https://www.theblock.co/post/314616/pendle-says-it-saved-105-million-that-could-have-been-further-drained-amid-penpie-hack","name":"","type":"other","credibility":3},{"url":"https://blog.penpiexyz.io/penpie-post-mortem-report-1ac9863b663a","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Penpie presents a high residual risk profile for several compounding reasons. First, the protocol suffered a total loss of approximately $27.3 million with zero fund recovery — all stolen assets were fully laundered through Tornado Cash within five days. Second, the exploit arose from a known class of vulnerability (reentrancy) that had been insufficiently addressed despite two prior security audits by Zokyo and WatchPug; the vulnerable code path was introduced through a May 2024 permissionless pool update that was not subjected to re-audit. Third, the proposed community compensation plan allocates MGP governance tokens and a portion of protocol revenue as recovery instruments — mechanisms that are contingent on the protocol's future revenue and token value, and do not represent direct dollar-for-dollar restitution. Fourth, no known law enforcement actions have resulted from the FBI or Singapore police filings, and no attacker has been publicly identified or charged. Fifth, the protocol's TVL fell approximately 65% post-exploit, indicating significant loss of user confidence. Sixth, Penpie's architecture remains dependent on Pendle Finance's smart contract integrity and market registration logic, meaning vulnerability surface extends beyond its own codebase. Users considering this protocol should treat the 2024 exploit as indicative of a systemic oversight in the security review process during protocol upgrades. The complete absence of fund recovery and the attacker's use of a privacy mixer to obfuscate the full trail elevate overall risk.","heading":"Risk Assessment","sources":[{"url":"https://www.auditone.io/blog-posts/the-penpie-hack-understanding-the-september-2024-reentrancy-exploit-and-the-role-of-auditing-in-defi-security","name":"","type":"other","credibility":3},{"url":"https://www.quillaudits.com/blog/hack-analysis/penpie-protocol-exploit","name":"","type":"other","credibility":3},{"url":"https://medium.com/@Magpieprotocol/magpie-protocol-charting-a-secure-path-following-exploit-c7046d9fc3ca","name":"","type":"other","credibility":3},{"url":"https://gov.magpiexyz.io/t/penpie-compensation-plan-draft-02/412","name":"","type":"other","credibility":3},{"url":"https://defillama.com/protocol/penpie","name":"","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2023-05","event":"Penpie launches as the first sub-DAO under the Magpie ecosystem, built on Pendle Finance.","source":"","date_original":"2023-05-01"},{"date":"2024-05","event":"Penpie introduces permissionless pool registration, allowing anyone to create Pendle markets — removing an access control that had previously mitigated reentrancy risk in the batchHarvestMarketRewards() function.","source":"","date_original":"2024-05-01"},{"date":"2024-09-03","event":"At 6:23 PM UTC, the reentrancy exploit begins. Three attack transactions drain approximately $27.348 million in wstETH, sUSDe, agETH, and rswETH across Arbitrum and Ethereum.","source":""},{"date":"2024-09-03","event":"Within 20 minutes of the exploit, Pendle Finance pauses all contracts, preventing the attacker from executing a second malicious contract targeting the remaining ~$105 million.","source":""},{"date":"2024-09-03","event":"Penpie team visits Kampong Java Neighbourhood Police Centre in Singapore and files a police report.","source":""},{"date":"2024-09-04","event":"Penpie files a complaint with the FBI's Internet Crime Complaint Center (IC3) and sends an on-chain message to the attacker offering amnesty in exchange for return of funds.","source":""},{"date":"2024-09-04","event":"Attacker begins laundering stolen funds through Tornado Cash; approximately $7 million (26% of total) is laundered within 12 hours of the exploit.","source":""},{"date":"2024-09-06","event":"Euler Finance exploiter sends an on-chain congratulatory message to the Penpie attacker. Penpie offers a 10% bounty for information leading to the attacker's identification.","source":""},{"date":"2024-09-06","event":"Attacker transfers 7,262 ETH ($17.4 million) to an intermediary address; 5,600 ETH is then laundered through Tornado Cash.","source":""},{"date":"2024-09-08","event":"Attacker completes laundering of all remaining stolen ETH through Tornado Cash; full 11,261 ETH balance is confirmed laundered by PeckShield.","source":""},{"date":"2024-10-07","event":"Magpie publishes Penpie compensation plan proposing 27 million Safu Recovery Tokens (SRT) backed by 4% of MGP token supply, and launches Safupie insurance mechanism proposal. Protocol operations resume.","source":""}],"sources_used":[{"url":"https://docs.magpiexyz.io/the-magpie-ecosystem/penpie-pendle-finance","name":"","type":"other","archive_url":"http://web.archive.org/web/20260623110845/https://docs.magpiexyz.io/the-magpie-ecosystem/penpie-pendle-finance","credibility":3,"archive_timestamp":"2026-06-23T11:08:45+00:00"},{"url":"https://docs.penpiexyz.io/penpie-ecosystem/introduction","name":"","type":"other","archive_url":"http://web.archive.org/web/20260521082222/https://docs.penpiexyz.io/penpie-ecosystem/introduction","credibility":3,"archive_timestamp":"2026-05-21T08:22:22+00:00"},{"url":"https://www.auditone.io/blog-posts/the-penpie-hack-understanding-the-september-2024-reentrancy-exploit-and-the-role-of-auditing-in-defi-security","name":"","type":"other","archive_url":"http://web.archive.org/web/20260414064141/https://www.auditone.io/blog-posts/the-penpie-hack-understanding-the-september-2024-reentrancy-exploit-and-the-role-of-auditing-in-defi-security","credibility":3,"archive_timestamp":"2026-04-14T06:41:41+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-penpie-hack-september-2024","name":"","type":"other","archive_url":"http://web.archive.org/web/20260609212953/https://www.halborn.com/blog/post/explained-the-penpie-hack-september-2024","credibility":3,"archive_timestamp":"2026-06-09T21:29:53+00:00"},{"url":"https://threesigma.xyz/blog/exploit/penpie-reentrancy-exploit-analysis","name":"","type":"other","archive_url":"http://web.archive.org/web/20260514075007/https://threesigma.xyz/blog/exploit/penpie-reentrancy-exploit-analysis","credibility":3,"archive_timestamp":"2026-05-14T07:50:07+00:00"},{"url":"https://cointelegraph.com/news/penpie-protocol-exploited-suffers-27-million-loss","name":"","type":"other","archive_url":"http://web.archive.org/web/20260720145524/https://cointelegraph.com/news/penpie-protocol-exploited-suffers-27-million-loss","credibility":3,"archive_timestamp":"2026-07-20T14:55:24+00:00"},{"url":"https://zokyo.io/blog/penpie-postmortem-analysis-of-the-27m-reentrancy-exploit/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260214014102/https://zokyo.io/blog/penpie-postmortem-analysis-of-the-27m-reentrancy-exploit/","credibility":3,"archive_timestamp":"2026-02-14T01:41:02+00:00"},{"url":"https://invezz.com/news/2024/09/06/hacker-behind-27m-penpie-heist-applauded-by-euler-exploiter/","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cointelegraph.com/news/penpie-protocol-hacker-launders-7m-tornado-cash","name":"","type":"other","archive_url":"http://web.archive.org/web/20250914003843/https://cointelegraph.com/news/penpie-protocol-hacker-launders-7m-tornado-cash","credibility":3,"archive_timestamp":"2025-09-14T00:38:43+00:00"},{"url":"https://dailycoin.com/penpie-hacker-launders-last-batch-of-the-stolen-27m-ether","name":"","type":"other","archive_url":"http://web.archive.org/web/20250913004508/https://dailycoin.com/penpie-hacker-launders-last-batch-of-the-stolen-27m-ether/","credibility":3,"archive_timestamp":"2025-09-13T00:45:08+00:00"},{"url":"https://defi-planet.com/2024/09/penpie-protocol-hacker-reportedly-laundered-7m-through-tornado-cash-within-12-hours-of-27m-theft/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260218220009/https://defi-planet.com/2024/09/penpie-protocol-hacker-reportedly-laundered-7m-through-tornado-cash-within-12-hours-of-27m-theft/","credibility":3,"archive_timestamp":"2026-02-18T22:00:09+00:00"},{"url":"https://arbiscan.io/tx/0xe44a4e2c1812ff00db4902d61d1bc2815854b38d63e8fe605707614cb1675e79","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829232625/https://arbiscan.io/tx/0xe44a4e2c1812ff00db4902d61d1bc2815854b38d63e8fe605707614cb1675e79","credibility":3,"archive_timestamp":"2026-08-29T23:26:25+00:00"},{"url":"https://therecord.media/penpie-defi-protocol-ethereum-stolen","name":"","type":"other","archive_url":"http://web.archive.org/web/20260215164557/https://therecord.media/penpie-defi-protocol-ethereum-stolen","credibility":3,"archive_timestamp":"2026-02-15T16:45:57+00:00"},{"url":"https://thedefiant.io/news/defi/penpie-proposes-compensation-plan-and-insurance-protocol-after-usd27m-exploit","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://finance.yahoo.com/news/defi-platform-pendle-claims-saved-134115901.html","name":"","type":"other","archive_url":"http://web.archive.org/web/20250930201621/https://finance.yahoo.com/news/defi-platform-pendle-claims-saved-134115901.html","credibility":3,"archive_timestamp":"2025-09-30T20:16:21+00:00"},{"url":"https://www.theblock.co/post/314616/pendle-says-it-saved-105-million-that-could-have-been-further-drained-amid-penpie-hack","name":"","type":"other","archive_url":"http://web.archive.org/web/20260726011702/https://www.theblock.co/post/314616/pendle-says-it-saved-105-million-that-could-have-been-further-drained-amid-penpie-hack","credibility":3,"archive_timestamp":"2026-07-26T01:17:02+00:00"},{"url":"https://blog.penpiexyz.io/penpie-post-mortem-report-1ac9863b663a","name":"","type":"other","archive_url":"http://web.archive.org/web/20240910025330/https://blog.penpiexyz.io/penpie-post-mortem-report-1ac9863b663a","credibility":3,"archive_timestamp":"2024-09-10T02:53:30+00:00"},{"url":"https://www.quillaudits.com/blog/hack-analysis/penpie-protocol-exploit","name":"","type":"other","archive_url":"http://web.archive.org/web/20260515100550/https://www.quillaudits.com/blog/hack-analysis/penpie-protocol-exploit","credibility":3,"archive_timestamp":"2026-05-15T10:05:50+00:00"},{"url":"https://medium.com/@Magpieprotocol/magpie-protocol-charting-a-secure-path-following-exploit-c7046d9fc3ca","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://gov.magpiexyz.io/t/penpie-compensation-plan-draft-02/412","name":"","type":"other","archive_url":"http://web.archive.org/web/20260726041422/https://gov.magpiexyz.io/t/penpie-compensation-plan-draft-02/412","credibility":3,"archive_timestamp":"2026-07-26T04:14:22+00:00"},{"url":"https://defillama.com/protocol/penpie","name":"","type":"other","archive_url":"http://web.archive.org/web/20260713034056/https://defillama.com/protocol/penpie","credibility":3,"archive_timestamp":"2026-07-13T03:40:56+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:29.638058+00:00","updated_at":"2026-08-30T05:14:06.877666+00:00"}}