Эксперты Beosin изучили атаку на Pendle Penpie

cryptonews.ruPublished on 2022-06-04Last updated on 2024-09-04

По данным на 4 сентября 2024 года DeFi-протокол Penpie, построенный на базе Pendle Finance, стал жертвой хакерской атаки, в результате которой было похищено около $27 млн в криптовалюте. Сразу после инцидента команда безопасности Beosin провела собственный анализ произошедшего и выявила ключевые уязвимости, которые позволили злоумышленникам успешно осуществить атаку.

Penpie — это платформа DeFi, интегрированная с Pendle Finance, которая предоставляет пользователям возможность блокировать токены PENDLE для получения прав управления и увеличения доходности в рамках экосистемы. Цель площадки заключается в улучшении доходности для клиентов и предоставлении услуг по усилению veTokenomics.

Атака была проведена с использованием уязвимости функции reentrant в контракте вознаграждений, что позволило злоумышленнику манипулировать балансом стейкингового контракта и получить чрезмерные вознаграждения. Основной этап подготовки атаки включал создание злоумышленником нового рынка и Yield с помощью «фабричного контракта» в протоколе Penpie, где контракт SY был использован в качестве атакующего.

Хакер также воспользовался флэш-займом, чтобы получить необходимую ликвидность для проведения атаки, и инициировал функцию batchHarvestMarketRewards, которая позволила ему управлять балансом рынка и получать неправомерные вознаграждения. В процессе атаки злоумышленник несколько раз повторил эту операцию, увеличивая свою прибыль за счет манипуляций с функцией redeemRewards.

Команда Pendle, узнав о случившемся, незамедлительно приостановила работу контрактов, что позволило предотвратить дальнейшие убытки и сохранить активы на сумму $105 млн. Однако хакеру удалось вывести около $27 млн, из которых 2900 ETH (приблизительно $6,9 млн) уже были переведены в Tornado Cash — сервис, известный своими возможностями по анонимизации транзакций.

В настоящее время Penpie активно пытается связаться с хакером, предлагая ему вознаграждение за возвращение украденных средств. В рамках реагирования на инцидент, команда безопасности Beosin рекомендовала добавить модификаторы для защиты от повторных входов в функции контракта, использовать единый контракт для генерации токенов, а также провести полный аудит безопасности перед запуском проекта.

Ошибка в тексте? Выделите её мышкой и нажмите Ctrl + Enter

Trending Cryptos

Related Reads

'Bear' Doomsday Prophecy: AI 'Reaching Its Peak', U.S. Stocks to Top Out Fastest in Q3, Down 30-50%

"A Short Seller's Dire Prediction: AI Boom Fading, US Stocks to Peak by Q3 with 30-50% Decline" Prominent macro investors Jeffrey Gundlach and Felix Zulauf warn that the AI-driven market rally is nearing its end, forecasting a major US stock market correction of 30-50%, potentially beginning as early as Q3. Their analysis points to alarming parallels with historical market tops, citing extreme concentration in the top AI-related stocks within the S&P 500. Zulauf's bearish thesis hinges on unsustainable capital expenditure trends among major cloud companies, negative free cash flow emergence, and soaring semiconductor prices. Gundlach highlights dangerous parallels to the 1999 tech bubble peak. A key divergence from conventional wisdom is Gundlach's view that long-term Treasury yields will not fall meaningfully even during a recession, due to America's structurally out-of-control fiscal deficits and soaring interest costs. He warns this could force the government into yield curve control or even a sovereign debt restructuring. Both investors express severe concerns about the opaque private credit market, drawing parallels to the pre-2008 financial crisis environment. They allege widespread rating inflation, misrepresented credit quality, liquidity illusions, and fraudulent asset valuations within this sector. The analysis links the AI boom and private credit crisis through financing costs. They argue that as AI companies' cash flows weaken and they seek funding, a high and sticky long-term interest rate environment will severely stress lower-rated corporate borrowers, exposing cracks in credit markets. Finally, they predict a regime shift where the US dollar weakens and US equities underperform global markets, marking the end of their long dominance. The stage is set for a significant market reversal.

marsbit5m ago

'Bear' Doomsday Prophecy: AI 'Reaching Its Peak', U.S. Stocks to Top Out Fastest in Q3, Down 30-50%

marsbit5m ago

Why Does No One Buy DeFi Insurance?

**Title: Why Isn't DeFi Insurance Being Bought?** DeFi insurance, which promised automated, unbiased payouts via smart contracts, has failed to gain traction. The core issue is economic: high premiums severely erode the yields that attract users to DeFi in the first place. For example, insuring a USDC deposit on Aave V3 could cost 1.5–2.5% of the annual yield, leaving a net return barely above a savings account. For riskier platforms like Maple Finance or Ethena, premiums can even turn net yields negative. Consequently, users often forgo insurance, as it nullifies their profit motive. The market also suffers from structural flaws. First, DeFi risks are highly correlated (e.g., an oracle failure can impact multiple protocols simultaneously), unlike the independent risks in traditional insurance. This makes large-scale events potentially catastrophic for insurers. Second, the total capital in DeFi insurance pools (e.g., Nexus Mutual's ~$81.5M) is minuscule compared to the hundreds of billions in total value locked (TVL), creating a massive capacity gap. A single major hack could drain the entire industry's reserves. Furthermore, the governance model where tokenholders vote on claims creates a conflict of interest, incentivizing them to deny payouts to protect their own funds. As a result, the sector is shrinking. While pioneers like Nexus Mutual are pivoting to preventative measures (bug bounties) and seeking external capital via reinsurance, the fundamental problems remain. DeFi insurance represents a public good—its stability benefits the entire ecosystem—but without a mechanism to share costs, a "tragedy of the commons" ensues where no one is willing to pay, leaving the system vulnerable.

marsbit19m ago

Why Does No One Buy DeFi Insurance?

marsbit19m ago

Trading

Spot
Futures

Hot Articles

How to Buy PENDLE

Welcome to HTX.com! We've made purchasing Pendle (PENDLE) simple and convenient. Follow our step-by-step guide to embark on your crypto journey.Step 1: Create Your HTX AccountUse your email or phone number to sign up for a free account on HTX. Experience a hassle-free registration journey and unlock all features.Get My AccountStep 2: Go to Buy Crypto and Choose Your Payment MethodCredit/Debit Card: Use your Visa or Mastercard to buy Pendle (PENDLE) instantly.Balance: Use funds from your HTX account balance to trade seamlessly.Third Parties: We've added popular payment methods such as Google Pay and Apple Pay to enhance convenience.P2P: Trade directly with other users on HTX.Over-the-Counter (OTC): We offer tailor-made services and competitive exchange rates for traders.Step 3: Store Your Pendle (PENDLE)After purchasing your Pendle (PENDLE), store it in your HTX account. Alternatively, you can send it elsewhere via blockchain transfer or use it to trade other cryptocurrencies.Step 4: Trade Pendle (PENDLE)Easily trade Pendle (PENDLE) on HTX's spot market. Simply access your account, select your trading pair, execute your trades, and monitor in real-time. We offer a user-friendly experience for both beginners and seasoned traders.

5.5k Total ViewsPublished 2024.03.29Updated 2026.06.02

How to Buy PENDLE

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of PENDLE (PENDLE) are presented below.

活动图片