{"investigation":{"slug":"purrlend","entity_name":"Purrlend","trust_score":22,"severity_base":null,"score_modifier":0,"confidence":0.72,"status":"published","content_type":"investigation","summary":"Purrlend is a non-custodial DeFi lending and borrowing protocol deployed on HyperEVM and MegaETH, operating as an Aave-style fork designed for leveraged yield farming. On April 25, 2026, the protocol suffered a multisig permission exploit that drained approximately $1.52 million across both networks, collapsing its TVL by roughly 70%. As of late May 2026, the protocol remains paused with no published post-mortem, recovery plan, or user compensation details.","sections":[{"content":"On April 25, 2026, Purrlend lost approximately $1,522,038 across its HyperEVM and MegaETH deployments in what on-chain observers described as a coordinated dual-network exploit. The attack originated from a suspicious admin multisig transaction executed at approximately 1:20 a.m. UTC, which updated borrowing caps and assigned elevated permissions to an unknown external address. That address was subsequently granted 'bridge' role privileges within the protocol — a role that inherited elevated permissions from Purrlend's underlying Aave-style contract implementation. Using those permissions, the attacker minted unbacked tokens and withdrew liquidity-pool assets across both chains. On HyperEVM, losses totaled approximately $1.197 million, comprising 449,683 USDC, 214,125 USDT0, 194,745 USDH, 2.05 UBTC, 19.6 UETH, 1,581 wstHYPE, 868 kHYPE, and 757 WHYPE. On MegaETH, approximately $324,549 was drained in USDT0, WETH, and USDm. The protocol's total value locked collapsed from roughly $1.5 million to approximately $444,000 following depositor flight. At approximately 9:10 a.m. UTC on April 25, Purrlend paused all protocol operations and issued a brief statement: 'We have detected irregular activity on the protocol and are actively investigating.' The exploit was first publicly flagged by on-chain investigator Kirby Ong, founder of HypurrCollective.","heading":"April 2026 Exploit: Multisig Permission Breach","sources":[{"url":"https://ourcryptotalk.com/news/purrlend-defi-protocol-loses-1-5m-multisig-exploit","name":"ourcryptotalk.com","type":"other","credibility":3},{"url":"https://www.mexc.com/news/1053473","name":"mexc.com","type":"other","credibility":3},{"url":"https://www.livebitcoinnews.com/purrlend-exploit-steals-1-5m-on-hyperevm-and-megaeth/","name":"livebitcoinnews.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/defi-attack-impact-purrlend-drained/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://www.mexc.com/news/1053509","name":"mexc.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The core vulnerability enabling the exploit was architectural rather than a smart-contract code flaw. Purrlend operated a 2-of-3 admin multisig without any timelock mechanism. This design meant that any two of three multisig signers could immediately execute privileged transactions, including role assignments, without a community review window. Security analysts noted that a timelock would have given users and the community the opportunity to observe and respond to the suspicious role assignment executed approximately eight hours before the drain. The 'bridge' role that the attacker's address received inherited elevated permissions from legacy Aave V2/V3 contract implementations underpinning the protocol, enabling unbacked token minting — a permission class not typically expected to be assignable via governance multisig in a properly scoped access-control model. Purrlend's documentation emphasized that 'security is treated as a core requirement' with 'rigorous auditing,' but no publicly available audit reports from named third-party auditors were found in relation to this deployment. The absence of timelock protections on privileged multisig operations represents a significant governance failure that the community has highlighted as the primary enabling condition for the exploit.","heading":"Governance and Security Design Failures","sources":[{"url":"https://ourcryptotalk.com/news/purrlend-defi-protocol-loses-1-5m-multisig-exploit","name":"ourcryptotalk.com","type":"other","credibility":3},{"url":"https://www.ainvest.com/news/purrlend-exploit-1-5m-drain-l2s-part-800m-april-defi-bloodbath-2604/","name":"ainvest.com","type":"other","credibility":3},{"url":"https://purrlends.gitbook.io/purrlend","name":"purrlends.gitbook.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, community members alleged the incident may have been an inside job, given that the attacker's address was added as a trusted 'bridge' role through the 2-of-3 admin multisig — meaning two of the protocol's own admin keyholders signed the transaction granting the attacker elevated privileges. No definitive evidence of insider involvement has been publicly confirmed. The attacker's on-chain wallet addresses were documented by Kirby Ong on block explorers for both HyperEVM and MegaETH, though those addresses have not been publicly attributed to any known individual. No law enforcement referral or on-chain asset freeze has been reported. As of the investigation date, neither Purrlend's team nor any security researcher has published findings confirming whether the exploit was the result of compromised admin keys held by a third party or deliberate action by a protocol insider. The protocol's founding team operates without publicly disclosed identities, consistent with its stated cypherpunk philosophy.","heading":"Insider Allegations and Unknown Attacker Identity","sources":[{"url":"https://ourcryptotalk.com/news/purrlend-defi-protocol-loses-1-5m-multisig-exploit","name":"ourcryptotalk.com","type":"other","credibility":3},{"url":"https://www.mexc.com/news/1053473","name":"mexc.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/defi-attack-impact-purrlend-drained/","name":"cryptobriefing.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Purrlend's founding team has not publicly disclosed individual identities. The protocol's GitBook documentation describes a 'cypherpunk philosophy' centered on privacy and autonomy, consistent with the project operating under pseudonymous or anonymous leadership. No named founders, developers, or executives associated with Purrlend have been identified in public reporting. Following the April 2026 exploit, the team issued only a brief statement confirming the protocol pause and investigation. As of late May 2026, no post-mortem has been published, no recovery or compensation plan has been announced, and user funds in open positions on HyperEVM and MegaETH reportedly remain inaccessible. The combination of anonymous leadership, no published audit reports, no post-exploit transparency, and the use of a no-timelock admin multisig are compounding risk factors that security researchers and community observers have flagged.","heading":"Team Anonymity and Lack of Transparency","sources":[{"url":"https://purrlends.gitbook.io/purrlend","name":"purrlends.gitbook.io","type":"other","credibility":3},{"url":"https://intellectia.ai/news/crypto/purrlend-pauses-protocol-amid-152m-hack-investigation","name":"intellectia.ai","type":"other","credibility":3},{"url":"https://finance.yahoo.com/markets/crypto/articles/another-defi-platform-just-got-122925586.html","name":"finance.yahoo.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The Purrlend exploit occurred during what analysts have characterized as the worst month for DeFi security in the industry's history. April 2026 recorded total losses exceeding $800 million across more than a dozen separate incidents, with Purrlend's $1.52 million loss representing a relatively small portion of the broader damage. Major incidents in the same period included exploits affecting other protocols in the hundreds of millions of dollars range. The concentration of attacks in April 2026 reflected attacker focus on newer Layer 2 ecosystems, including HyperEVM and MegaETH, where protocols were newly deployed, auditing practices were inconsistent, and governance structures were immature. The Purrlend exploit is cited by security researchers as illustrative of the risks posed by deploying Aave-style fork contracts with access-control configurations inherited from the base implementation without proper scoping or timelocked governance.","heading":"Broader Context: April 2026 DeFi Security Crisis","sources":[{"url":"https://startupfortune.com/purrlends-15-million-exploit-is-a-small-number-in-april-2026s-catastrophic-defi-security-ledger/","name":"startupfortune.com","type":"other","credibility":3},{"url":"https://www.ainvest.com/news/purrlend-exploit-1-5m-drain-l2s-part-800m-april-defi-bloodbath-2604/","name":"ainvest.com","type":"other","credibility":3},{"url":"https://www.bitget.com/news/detail/12560605385020","name":"bitget.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2025-02","event":"HyperEVM mainnet launches, enabling new DeFi deployments on Hyperliquid's EVM layer.","source":"","date_original":"2025-02-01"},{"date":"2026-04-25","event":"At approximately 1:20 a.m. UTC, Purrlend's 2-of-3 admin multisig executes a suspicious transaction granting an unknown address the 'bridge' role with elevated permissions inherited from the underlying Aave-style implementation.","source":""},{"date":"2026-04-25","event":"Hours after the suspicious role assignment, the attacker uses the granted bridge privileges to mint unbacked tokens and drain liquidity pools across HyperEVM and MegaETH, stealing approximately $1.52 million.","source":""},{"date":"2026-04-25","event":"At approximately 9:10 a.m. UTC, Purrlend pauses all protocol operations and posts a brief statement on X: 'We have detected irregular activity on the protocol and are actively investigating.'","source":""},{"date":"2026-04-25","event":"Kirby Ong, founder of HypurrCollective, first publicly flags the exploit and documents attacker wallet addresses on both HyperEVM and MegaETH block explorers.","source":""},{"date":"2026-04-25","event":"Protocol TVL collapses from approximately $1.5 million to $444,000 as depositor flight follows news of the exploit.","source":""},{"date":"2026-05-26","event":"As of this investigation date, the Purrlend protocol remains paused. No post-mortem, user compensation plan, or recovery details have been published. The exploiting address has not been publicly attributed.","source":""}],"sources_used":[{"url":"https://ourcryptotalk.com/news/purrlend-defi-protocol-loses-1-5m-multisig-exploit","name":"ourcryptotalk.com","type":"other","archive_url":"https://web.archive.org/web/20260829081645/https://ourcryptotalk.com/news/purrlend-defi-protocol-loses-1-5m-multisig-exploit","credibility":3,"archive_timestamp":"2026-08-29T08:16:45+00:00"},{"url":"https://www.mexc.com/news/1053473","name":"mexc.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.livebitcoinnews.com/purrlend-exploit-steals-1-5m-on-hyperevm-and-megaeth/","name":"livebitcoinnews.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cryptobriefing.com/defi-attack-impact-purrlend-drained/","name":"cryptobriefing.com","type":"other","archive_url":"http://web.archive.org/web/20260510015117/https://cryptobriefing.com/defi-attack-impact-purrlend-drained/","credibility":3,"archive_timestamp":"2026-05-10T01:51:17+00:00"},{"url":"https://www.mexc.com/news/1053509","name":"mexc.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:gone","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.ainvest.com/news/purrlend-exploit-1-5m-drain-l2s-part-800m-april-defi-bloodbath-2604/","name":"ainvest.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://purrlends.gitbook.io/purrlend","name":"purrlends.gitbook.io","type":"other","archive_url":"http://web.archive.org/web/20260120014628/https://purrlends.gitbook.io/purrlend/","credibility":3,"archive_timestamp":"2026-01-20T01:46:28+00:00"},{"url":"https://intellectia.ai/news/crypto/purrlend-pauses-protocol-amid-152m-hack-investigation","name":"intellectia.ai","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://finance.yahoo.com/markets/crypto/articles/another-defi-platform-just-got-122925586.html","name":"finance.yahoo.com","type":"other","archive_url":"http://web.archive.org/web/20260724181329/https://finance.yahoo.com/markets/crypto/articles/another-defi-platform-just-got-122925586.html","credibility":3,"archive_timestamp":"2026-07-24T18:13:29+00:00"},{"url":"https://startupfortune.com/purrlends-15-million-exploit-is-a-small-number-in-april-2026s-catastrophic-defi-security-ledger/","name":"startupfortune.com","type":"other","archive_url":"https://web.archive.org/web/20260829081820/https://startupfortune.com/purrlends-15-million-exploit-is-a-small-number-in-april-2026s-catastrophic-defi-security-ledger/","credibility":3,"archive_timestamp":"2026-08-29T08:18:20+00:00"},{"url":"https://www.bitget.com/news/detail/12560605385020","name":"bitget.com","type":"other","archive_url":"https://web.archive.org/web/20260829083730/https://www.bitget.com/news/detail/12560605385020","credibility":3,"archive_timestamp":"2026-08-29T08:37:30+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:16.788494+00:00","updated_at":"2026-08-29T23:26:11.225122+00:00"}}