Skip to main content
AVOID.NET

Penpie

avoid.net/penpie→10/100·100% conf.
[AI-DRAFTED · AWAITING VERIFICATION][src:defillama]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·58cjNX…gdeT

Summary

Penpie is a yield-boosting DeFi protocol built on Pendle Finance by the Magpie DAO ecosystem, allowing users to earn boosted yields on Pendle liquidity pools without directly locking PENDLE tokens. On September 3, 2024, an attacker exploited a reentrancy vulnerability in Penpie's staking contract to drain approximately $27.3 million across Ethereum and Arbitrum, subsequently laundering all stolen funds through Tornado Cash and ignoring recovery appeals. The protocol filed reports with the FBI and Singapore Police but recovered no funds; a partial community compensation plan was proposed but not fully executed.

Connected Entities

6 entities · 60 linked investigations
Relationships
  • Balancer→mentioned with→Arbitrum(60%)
  • Balancer→mentioned with→Ethereum(70%)
  • Euler Finance→mentioned with→Ethereum(80%)
  • Penpie→mentioned with→Pendle(80%)
  • Pendle→mentioned with→Penpie(80%)
  • Pendle→mentioned with→Arbitrum(70%)
  • Pendle→mentioned with→Ethereum(80%)
  • Pendle→mentioned with→Balancer(60%)
  • Balancer→mentioned with→Euler Finance(80%)
  • Penpie→mentioned with→Euler Finance(80%)
  • + 5 more
Have evidence about Penpie?

Timeline(11 events)

May 2023

Penpie launches as the first sub-DAO under the Magpie ecosystem, built on Pendle Finance.

May 2024

Penpie introduces permissionless pool registration, allowing anyone to create Pendle markets — removing an access control that had previously mitigated reentrancy risk in the batchHarvestMarketRewards() function.

3 September 2024

At 6:23 PM UTC, the reentrancy exploit begins. Three attack transactions drain approximately $27.348 million in wstETH, sUSDe, agETH, and rswETH across Arbitrum and Ethereum.

3 September 2024

Within 20 minutes of the exploit, Pendle Finance pauses all contracts, preventing the attacker from executing a second malicious contract targeting the remaining ~$105 million.

3 September 2024

Penpie team visits Kampong Java Neighbourhood Police Centre in Singapore and files a police report.

4 September 2024

Penpie files a complaint with the FBI's Internet Crime Complaint Center (IC3) and sends an on-chain message to the attacker offering amnesty in exchange for return of funds.

4 September 2024

Attacker begins laundering stolen funds through Tornado Cash; approximately $7 million (26% of total) is laundered within 12 hours of the exploit.

6 September 2024

Euler Finance exploiter sends an on-chain congratulatory message to the Penpie attacker. Penpie offers a 10% bounty for information leading to the attacker's identification.

6 September 2024

Attacker transfers 7,262 ETH ($17.4 million) to an intermediary address; 5,600 ETH is then laundered through Tornado Cash.

8 September 2024

Attacker completes laundering of all remaining stolen ETH through Tornado Cash; full 11,261 ETH balance is confirmed laundered by PeckShield.

7 October 2024

Magpie publishes Penpie compensation plan proposing 27 million Safu Recovery Tokens (SRT) backed by 4% of MGP token supply, and launches Safupie insurance mechanism proposal. Protocol operations resume.

Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 18 of 21 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 5/4/2026, 2:54:29 AM

last updated: 8/30/2026, 5:14:06 AM

4 views

avoid.net — verified advice for a post-truth world