Pendle Secures $105 Million in Assets Following $27 Million Penpie Exploit
Penpie, a yield optimizer built on Pendle's infrastructure, lost roughly $27.3 million in a Tuesday exploit — and the underlying protocol says it absorbed none of the blow.

According to Pendle's Wednesday post-mortem, in-house monitoring flagged the malicious contract almost immediately, even if the first wave couldn't be blocked, and roughly $105 million in additional funds exposed to the same attack surface were shielded before deeper damage compounded. The gap between $27 million drained and $105 million claimed-saved is exactly where LP exposure sits, and it deserves a closer look.
Mechanics of the Breach
PeckShield pegged the root cause to an "evil market" — a malicious contract injected into Penpie's reward accounting that inflated staking balances and siphoned rewards that were never legitimately earned. The attacker funded the deployment through Tornado Cash, then swapped the stolen basket for 11,109 ETH. Pendle's own monitoring caught the contract before it fully landed, but the protocol couldn't intervene fast enough to stop the initial drain. Once the $27.3 million cleared, coordination with white-hat partners froze further movement, and Pendle contracts have since been unpaused with normal operations restored.
Price Action and Contagion
The market response was textbook short-term repricing rather than protocol-level collapse. Penpie's PNP token dropped more than 33% in the immediate aftermath; PENDLE itself traded down roughly 9% over 24 hours. That divergence matters: PNP carries direct operational and treasury risk, while PENDLE reflects governance and fee-revenue confidence in the parent protocol. The kind of overnight re-ranking across competing yield platforms — when a top-tier protocol absorbs a hit and liquidity depth migrates within hours — echoes the shift in competitive standings that reshapes the stakes in tournament play the moment a favorite gets knocked out.
Practical Steps for LP and PT/YT Holders
1. Audit exposure. Pull active Pendle positions and isolate any with Penpie as the underlying yield source. Reward logic in those markets was rewritten during the incident response.
2. Verify redemption. Confirm PT tokens still redeem 1:1 at maturity against the redeployed contracts. Any deviation from par pricing before maturity is the real liquidity-depth signal.
3. Track the bounty outcome. Penpie has publicly signaled willingness to negotiate with the attacker in exchange for returned funds and anonymity. Resolution materially affects PNP recovery and any future reimbursement mechanics.
A 33% drawdown on PNP paired with a 9% sympathetic drop on PENDLE is the asymmetry worth tracking. If the $105 million claim holds through full post-mortem audit — and frozen funds actually return to depositors rather than being absorbed by a recovery pool — the implied recovery case on PNP at current levels is a setup where position sizing, not conviction, decides the P&L. Size to the bounty outcome, not the headline.