T
iTokenly

Penpie hack — September 2024

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedSeptember 3, 2024
Target typeOther
Loss$27,348,259Price at time of incident
MethodReentrancyMissing reentrancy guard on PendleStakingBaseUpg::batchHarvestMarketRewards(), combined with a registration helper that accepted any market created through Pendle's permissionless factory. The attacker registered fake Pendle markets whose Standardised Yield token was a contract they controlled, then re-entered depositMarket() during reward harvesting to inflate the rewards credited to their own market before withdrawing the underlying assets.
ChainsEthereum, Arbitrum
OutcomeUnresolved

What happened

Penpie, a yield-boosting protocol built on top of Pendle Finance by the Magpie team, was drained on 3 September 2024 at 18:23 UTC. Its own post-mortem records the loss as 11,113.6 ETH, about $27.35 million, taken across its Ethereum and Arbitrum deployments.

The flaw was a missing reentrancy guard in the batchHarvestMarketRewards function of PendleStakingBaseUpg. A separate weakness let the attacker register arbitrary pools: the market registration helper treated any market created through Pendle's permissionless factory as valid. The attacker created fake Pendle markets whose Standardised Yield token was a contract they controlled, registered them with Penpie, then triggered a reward harvest. Because the harvest called into the attacker's contract before Penpie updated its accounting, the attacker re-entered depositMarket and inflated the reward balance credited to their own fake market. Flash-loaned wstETH, sUSDe, egETH and rswETH from Balancer supplied the deposits, and the inflated rewards were then claimed and the underlying assets withdrawn.

Penpie and Pendle paused their contracts on all chains. A second malicious contract was deployed shortly afterwards, which the teams read as an attempt on the funds still exposed in the affected markets; the pause prevented it.

The team filed a report with the FBI's IC3 on 4 September 2024 and worked with tracing firms to follow the funds, including efforts to demix the attacker's Tornado Cash deposits. No funds have been recovered and no suspect has been named.

Penpie resumed operations on 7 October 2024 and put a compensation framework to governance. Affected users were allocated roughly 27 million Safu Recovery Tokens, each representing one dollar, to be bought back over time using 20 per cent of Penpie's vePENDLE revenue and 20 per cent of Magpie's overall monthly revenue, alongside an allocation of 4 per cent of MGP supply drawn from the team and treasury.

Sources

  1. Penpie / MagpiePrimary · retrieved 2026-08-01
  2. HalbornSecondary · retrieved 2026-08-01
  3. The DefiantSecondary · retrieved 2026-08-01

Official post-mortem: https://blog.penpiexyz.io/penpie-post-mortem-report-1ac9863b663a

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Penpie hack — September 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/penpie
https://itokenly.com/hacks/penpie

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.