T
iTokenly

Purrlend hack — April 2026

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedApril 25, 2026
Target typeLending protocol
Loss$1,522,037Price at time of incident
MethodPrivate key compromiseCompromise of Purrlend's 2-of-3 admin multisig. Ahead of the drain the multisig executed a transaction granting BRIDGE_ROLE and other privileges to an address the team did not control; the holder then called mintUnbacked, a bridge-only function, to create pUSDm and pUSDC with no collateral behind them, posted those tokens as collateral and borrowed out the pools' real assets on both deployments.
ChainsOther
OutcomeUnresolved

What happened

Purrlend was a lending and borrowing protocol deployed on HyperEVM and on MegaETH. Its administrative controls sat behind a 2-of-3 multisig.

At 1:20 a.m. UTC on 25 April 2026 that multisig executed a transaction granting BRIDGE_ROLE and other privileges to an address the team did not control. The holder of those privileges then called the protocol's mintUnbacked function, intended for a cross-chain bridge issuing tokens against assets locked elsewhere, to create pUSDm and pUSDC with nothing behind them, posted the fabricated tokens as collateral and borrowed out the pools' real assets. Purrlend has not published how much unbacked supply was created.

On-chain analyst Kirby Ong, founder of HypurrCollective, published the first breakdown. HyperEVM lost $1,197,488, including roughly 450,000 USDC, 214,000 USDT0 and 195,000 USDH, along with smaller amounts of UBTC, UETH, wstHYPE, kHYPE and WHYPE. MegaETH lost a further $324,549, for a total of $1,522,037.

Purrlend confirmed that it had detected irregular activity and had paused the protocol, and subsequently described the cause as a breach of its admin multisig. It said the relevant permissions had been revoked and that it was working with security researchers, law enforcement and cross-chain bridge partners to trace the funds.

Purrlend has not published how the multisig signers were compromised, and no actor has been named. Because the privileged role change was executed by the team's own multisig, some observers raised the possibility of insider involvement; that is speculation and no charge, admission or published evidence supports it. No funds have been reported recovered.

Law enforcement

Purrlend said it was working with law enforcement agencies and cross-chain bridge partners to trace the funds; no agency has publicly confirmed an investigation.

Sources

  1. Crypto BriefingSecondary · retrieved 2026-08-01
  2. TheStreet (via Yahoo Finance)Secondary · retrieved 2026-08-01
  3. Purrlend statement, reported by ChainCatcher, republished by BitgetSecondary · retrieved 2026-08-01
  4. Live Bitcoin NewsSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Purrlend hack — April 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/purrlend
https://itokenly.com/hacks/purrlend

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.