Yield protocol Penpie got exploited for $27 million on Sept. 3 after a malicious agent explored a vulnerability in the protocol’s smart contracts.
Penpie is a yield protocol on Pendle that aims to boost rewards for users on the network.
Reentrancy exploited
In a Sept. 4 breakdown, blockchain security firm Hacken explained that the attacker used a pool with fake tokens to perform the heist. The exploiter created valueless versions of Pendle’s yield-bearing tokens, Standardized Yield (SY), and tied them to valuable assets.
The attacker deployed five malicious contracts to act as legitimate liquidity pools and trick Penpie’s rewards system, but only three of them were used. He then leveraged the fake SY tokens as tickets to claim real yield.
Three attack transactions were executed between 6:25 P.M. and 6:42 P.M. UTC. The first transaction extracted the highest amount, siphoning $15.7 million, followed by two other transactions that took $5.6 million each out of Penpie’s contract.
We współpracy z: https://cryptoslate.com/penpie-exploited-for-27-million-in-reentrancy-attack/