被盗约 2700 万美元的加密资产,Penpie 为何被黑客「血洗」?

深潮Publicado a 2024-09-04Actualizado a 2024-09-04

9 月 4 日,建立在 Pendle 上的 DeFi 协议 Penpie 遭到黑客攻击,被盗取约 2700 万美元的加密资产。

撰文:Beosin

2024 年 09 月 04 日,据 Beosin Alert 监测显示,建立在 Pendle 上的 DeFi 协议 Penpie 遭到黑客攻击,被盗取约 2700 万美元的加密资产。Beosin 安全团队第一时间对事件进行了分析,结果如下。

Penpie 是一个与 Pendle Finance 集成的 DeFi 平台,专注于锁定 PENDLE 代币以获得 Pendle Finance 内的治理权和增强的收益收益。Penpie 旨在为 Pendle Finance 用户提供收益和 veTokenomics 提升服务。

事件相关信息

●攻击交易

0x56e09abb35ff12271fdb38ff8a23e4d4a7396844426a94c4d3af2e8b7a0a2813

●攻击者地址

0xc0Eb7e6E2b94aA43BDD0c60E645fe915d5c6eb84

●攻击合约

0x4aF4C234B8CB6e060797e87AFB724cfb1d320Bb7

●被攻击合约

0x6e799758cee75dae3d84e09d40dc416ecf713652

漏洞分析

本次事件主要是攻击者利用 market 合约中 claimRewards 函数重入质押以提高 staking 合约余额,再将 staking 合约中多余的代币和质押资产提取以获利。

攻击流程

攻击准备阶段:

1. 攻击者通过攻击合约调用用 Penpie 协议中的 Factory 合约创建了新的 market 以及 Yield,其中将 SY 设置为攻击合约。

0xfda0dde38fa4c5b0e13c506782527a039d3a87f93f9208c104ee569a642172d2

2.攻击者进行闪电贷了四种代币,为后续抵押资金作储备。并调用 staking 合约中的 batchHarvestMarketRewards 函数对新创建的 market 进行奖励更新。

3.在 batchHarvestMarketRewards 函数中,对 market 进行奖励更新时,会调用 market 合约中的 redeemRewards 函数。并且合约记录了 redeemRewards 函数前后的余额变化。

4.在 market 的 redeemRewards 函数中,会调用到 SY 合约中的 claimReward 函数。然而 SY 合约是攻击合约,攻击合约通过这个函数完成了对 Staking 合约的重入,将闪电贷的资金抵押到 Staking 合约,共 4 次。

5.这时回到 Staking,由于 redeemRewards 函数前后余额差明显,触发了_sendRewards 函数,_sendRewards 函数最后调用的_queueRewarder 会将多余的代币授权给 market 合约并记录为奖励。

6.攻击者领取记录的奖励。

7.攻击者将质押的资产通过 withdraw 函数提取,并归还闪电贷进行获利。

Pendle 随后发布攻击分析报告:发现漏洞后立即暂停合约,使 1.05 亿美元资产免受进一步损失。

资金追踪

截止发文时,被盗资金约 2700 万美元,Beosin Trace 追踪发现攻击者已将被盗资金全部转换为 ETH,资金先存放在 0x2f2dDE668e5426463E05D795f5297dB334f61C39 地址。

截止发文,Penpie 攻击者地址向 Tornado Cash 陆续转移了 2900 枚 ETH(价值约 690 万美元)。

目前,Penpie 项目方也通过链上向黑客喊话,希望与黑客进行沟通返还被盗资金,如果返还可以支付赏金。并附上了联系方式。

总结

针对本次事件,Beosin 安全团队建议:1.对合约的相关函数增加防重入修饰器;2.不使用白名单对传入代币进行校验的话,最好使用统一的包装合约重新生成代币;3.项目上线前,强烈建议选择专业的安全审计公司进行全面的安全审计,规避安全风险。

Lecturas Relacionadas

Has Microsoft Lost Its Way in the AI Race, and Can Copilot Bring It Back on Track?

Microsoft, once seen as an early AI frontrunner due to its investment in OpenAI, is navigating a strategic shift amid increased competition. Its initial reliance on OpenAI’s GPT models has been complicated by OpenAI’s growing ambitions as a direct competitor, rapid advancements from rivals like Claude and Gemini, and the disruptive rise of AI agents, which challenge its traditional SaaS business model. These factors contributed to stock declines and slower-than-expected adoption of its flagship Copilot products. In response, CEO Satya Nadella has taken a hands-on role in product development, signaling the urgency of change. Microsoft is pivoting from a model-centric strategy to a "model-agnostic" enterprise platform approach. It aims to become the foundational layer connecting various AI models—from OpenAI, Anthropic, or its own new "Superintelligence" team—with enterprise workflows, data, security, and cloud services. Recent organizational changes merged consumer and enterprise Copilot teams to accelerate innovation, exemplified by new products like Copilot Tasks and Copilot Cowork. However, this transformation comes at a high cost. Microsoft faces massive capital expenditures, potentially reaching ~$190 billion by 2026, to support AI infrastructure. While its platform strategy shows early signs of traction with growing Azure AI revenue, it must balance startup-like agility with the reliability expected by enterprise clients. The core challenge is no longer being the sole AI winner but defending its position as the essential enterprise software entry point amidst rapid technological commoditization and the shift towards always-on AI agents.

marsbitHace 6 min(s)

Has Microsoft Lost Its Way in the AI Race, and Can Copilot Bring It Back on Track?

marsbitHace 6 min(s)

Why Haven't Forex Stablecoins Taken Off?

Why FX Stablecoins Never Took Off: A Path Forward via Synthetic FX Despite the explosive growth of stablecoin-powered digital banking, which has seen ~$6B in VC investment and a 24x surge in crypto card spending in under a year, a major limitation persists: these banks are essentially dollar-only accounts. This leaves 95-99% of global accounts, which are denominated in non-USD currencies, underserved. Attempts to create native foreign currency (FX) stablecoins (like EURC) have largely failed, with total FX stablecoin TVL at ~$600M compared to $400B for USD stablecoins—a 700x gap. These FX tokens face critical challenges: fragile pegs due to low liquidity, limited exchange/FinTech acceptance, poor on/off-ramps, complex regional compliance, and a chicken-and-egg adoption problem. The article argues that the solution lies not in competing with entrenched USD stablecoin networks (USDT/USDC), but in adopting a synthetic FX model inspired by traditional finance. Specifically, it advocates for Mark-to-Market Non-Deliverable Forwards (NDFs)—cash-settled FX derivatives that allow users to maintain underlying USD stablecoin holdings while having their account balance and P&L denominated in a foreign currency. This approach offers key advantages: strong oracle-based pegs, retention of deep USD stablecoin liquidity and yield, superior on/off-ramps, scalability to any currency with a reliable feed, and capital efficiency. It mirrors how modern institutional FX markets operate. Primary use cases for on-chain NDFs include: 1. **Digital Banks/Wallets:** Enabling multi-currency accounts for international users without leaving the USD stablecoin ecosystem, boosting deposits and retention. 2. **FX Carry Trade Vaults:** Offering access to sovereign interest rate differentials (e.g., earning yield on BRL) in a more stable and scalable format than crypto-native products like Ethena. 3. **Global Enterprise Payments:** Allowing merchants to receive payments in local currency equivalents while settling in USD stablecoins, similar to services offered by Stripe for fiat. The conclusion is that synthetic FX, not native FX stablecoins, is the viable path to integrating foreign exchange into the growing stablecoin digital banking landscape, potentially unlocking the next phase of institutional DeFi and multi-trillion-dollar global adoption.

链捕手Hace 41 min(s)

Why Haven't Forex Stablecoins Taken Off?

链捕手Hace 41 min(s)

IOSG Founder: Web3 Is 'Losing Blood,' How Can Practitioners Survive Better?

IOSG Founder: Web3 Is "Bleeding Out" – How Can Practitioners Survive Better? In a candid reflection, the founder of IOSG Ventures voices deep concerns about the current state of Web3, describing an ecosystem experiencing severe "blood loss." Despite the recent MuShanghai event showcasing a successful pivot towards a more diverse, global community, a somber reality persists: many crypto-native attendees were there exploring exits or new labels in biotech, AI, and robotics. The core issue is identified as a breakdown in the ecosystem's positive feedback loop. Alarmingly, underestimated "low-probability bad events" are occurring simultaneously: a significant brain drain of Chinese developers to AI, a lack of breakout applications despite massive funding, and a widening credibility gap for practitioners globally, often stigmatized as scam artists. This has created a dire接班人 (successor) problem, with the next generation seeing little professional prestige or financial upside in crypto compared to fields like AI. A significant portion of the critique focuses on Ethereum and Vitalik Buterin. While not pessimistic about Ethereum's technology, the founder worries that critical development windows were missed by focusing on niche technical narratives like ZK and L2 instead of mass-market applications. A more urgent concern is that Vitalik may be isolated in an "information bubble," shielded from the grassroots community's hardships by layers of intermediaries, preventing crucial feedback from reaching him. The call is for Vitalik to return to a founder's mindset, re-engage directly with the community, and rally efforts for the next decade. The divergence between U.S. and Chinese OG (Original Gangster) ecosystems is stark. While many U.S. builders reinvest their wealth into the ecosystem, the Chinese scene suffers from a severe lack of "造血能力" (blood-making ability), with most market-driven funds struggling and many early success stories cashing out entirely. This threatens the entire Asian Web3 ecosystem's survival. For individual practitioners, survival advice is pragmatic: find your core "why," maintain life balance beyond token prices, continuously learn new skills (like AI), form small, trusted alliances for mutual support, and practice self-compassion. The industry's greatest need is not money or tech, but lighthouses—individuals at all levels who offer mentorship, grants, referrals, and honest reflection to guide others. The piece concludes with a direct appeal: OGs must pay forward the opportunities the industry gave them; founders must not struggle alone; and builders must continue their work, ensuring it remains a viable profession. The survival of Web3's "cathedral" depends not on any single leader but on the collective responsibility of everyone who remains.

marsbitHace 1 hora(s)

IOSG Founder: Web3 Is 'Losing Blood,' How Can Practitioners Survive Better?

marsbitHace 1 hora(s)

Deficits, Inflation, and the New Fed: The Deep Logic Behind US Bond Yields Breaking 5% and the Market Reset

In the week of May 15-19, 2026, U.S. long-term Treasury yields surged to multi-year highs, with the 30-year yield hitting 5.2%, a level unseen since 2007, and the 10-year yield climbing to 4.687%. Equity markets declined in response. Four primary factors are driving the rise in yields. First, stubborn inflation persists, with April wholesale prices rising 6% year-over-year, fueling expectations of potential future Fed rate hikes instead of cuts. Second, newly confirmed Fed Chair Kevin Warsh inherits a complex inflation battle, with markets closely awaiting his first FOMC meeting. Third, deteriorating U.S. fiscal health, marked by large deficits and rising debt servicing costs, is eroding the traditional "safe-haven" premium for Treasuries. Fourth, the "One Big Beautiful Bill" tax cuts are projected to add trillions to the national debt, contributing to Moody's recent credit rating downgrade. Rising yields pressure stocks through several channels: a higher discount rate reduces the present value of future earnings (especially for growth stocks); rising risk-free rates compress equity risk premiums, making bonds relatively more attractive; higher borrowing costs impact consumers and corporations; and a stronger dollar affects multinational earnings. For investors, the environment favors value and financial stocks over long-duration growth stocks. Bond investors find attractive yields in short to intermediate maturities, while income investors see the best fixed-income opportunities in over a decade. Key developments to watch include Chair Warsh's first FOMC meeting, upcoming inflation data, Treasury auction demand, and whether the 30-year yield approaches 6%, a level that could trigger a more sustained equity valuation reset. The bond market's message is clear: the era of cheap government borrowing is over, posing a central challenge for markets in late 2026.

marsbitHace 1 hora(s)

Deficits, Inflation, and the New Fed: The Deep Logic Behind US Bond Yields Breaking 5% and the Market Reset

marsbitHace 1 hora(s)

Trading

Spot
Futuros

Artículos destacados

Cómo comprar PENDLE

¡Bienvenido a HTX.com! Hemos hecho que comprar Pendle (PENDLE) sea simple y conveniente. Sigue nuestra guía paso a paso para iniciar tu viaje de criptos.Paso 1: crea tu cuenta HTXUtiliza tu correo electrónico o número de teléfono para registrarte y obtener una cuenta gratuita en HTX. Experimenta un proceso de registro sin complicaciones y desbloquea todas las funciones.Obtener mi cuentaPaso 2: ve a Comprar cripto y elige tu método de pagoTarjeta de crédito/débito: usa tu Visa o Mastercard para comprar Pendle (PENDLE) al instante.Saldo: utiliza fondos del saldo de tu cuenta HTX para tradear sin problemas.Terceros: hemos agregado métodos de pago populares como Google Pay y Apple Pay para mejorar la comodidad.P2P: tradear directamente con otros usuarios en HTX.Over-the-Counter (OTC): ofrecemos servicios personalizados y tipos de cambio competitivos para los traders.Paso 3: guarda tu Pendle (PENDLE)Después de comprar tu Pendle (PENDLE), guárdalo en tu cuenta HTX. Alternativamente, puedes enviarlo a otro lugar mediante transferencia blockchain o utilizarlo para tradear otras criptomonedas.Paso 4: tradear Pendle (PENDLE)Tradear fácilmente con Pendle (PENDLE) en HTX's mercado spot. Simplemente accede a tu cuenta, selecciona tu par de trading, ejecuta tus trades y monitorea en tiempo real. Ofrecemos una experiencia fácil de usar tanto para principiantes como para traders experimentados.

330 Vistas totalesPublicado en 2024.12.12Actualizado en 2025.03.21

Cómo comprar PENDLE

Discusiones

Bienvenido a la comunidad de HTX. Aquí puedes mantenerte informado sobre los últimos desarrollos de la plataforma y acceder a análisis profesionales del mercado. A continuación se presentan las opiniones de los usuarios sobre el precio de PENDLE (PENDLE).

活动图片