Penpiexyz (2024) — Crypto Hack
Partially RecoveredPenpiexyz, a Pendle-inspired yield-trading protocol on Ethereum, was exploited for ~$11M through a reentrancy vulnerability in its SY token contracts.
Summary
Penpiexyz, a Pendle-inspired yield-trading protocol on Ethereum, was exploited for ~$11M through a reentrancy vulnerability in its SY token contracts.
How It Was Compromised — DeFi via Smart Contract Exploit / Reentrancy
On October 9, 2024, Penpiexyz, a Pendle-inspired yield-trading protocol on Ethereum, was exploited for approximately $11M. The attacker identified a reentrancy vulnerability in the protocol's SY (Standardized Yield) token contracts that allowed them to manipulate the protocol's accounting and extract value from its pools. The exploit was executed across multiple transactions and drained several of the protocol's pools. Penpiexyz paused the protocol and engaged with blockchain analytics firms to track the stolen funds. The protocol offered a 10% bounty for the return of the funds.
Fund Flow & Laundering Analysis
Stolen tokens were swapped to ETH and stablecoins via decentralized exchanges. The ETH was then moved through multiple intermediary wallets before being deposited into Tornado Cash. The attacker used a complex network of intermediary wallets to fragment the laundering trail. Penpiexyz engaged with the attacker, who returned approximately $1.5M worth of tokens after negotiations.