被盗约 2700 万美元的加密资产,Penpie 为何被黑客「血洗」?

深潮Publicado em 2024-09-04Última atualização em 2024-09-04

9 月 4 日,建立在 Pendle 上的 DeFi 协议 Penpie 遭到黑客攻击,被盗取约 2700 万美元的加密资产。

撰文:Beosin

2024 年 09 月 04 日,据 Beosin Alert 监测显示,建立在 Pendle 上的 DeFi 协议 Penpie 遭到黑客攻击,被盗取约 2700 万美元的加密资产。Beosin 安全团队第一时间对事件进行了分析,结果如下。

Penpie 是一个与 Pendle Finance 集成的 DeFi 平台,专注于锁定 PENDLE 代币以获得 Pendle Finance 内的治理权和增强的收益收益。Penpie 旨在为 Pendle Finance 用户提供收益和 veTokenomics 提升服务。

事件相关信息

●攻击交易

0x56e09abb35ff12271fdb38ff8a23e4d4a7396844426a94c4d3af2e8b7a0a2813

●攻击者地址

0xc0Eb7e6E2b94aA43BDD0c60E645fe915d5c6eb84

●攻击合约

0x4aF4C234B8CB6e060797e87AFB724cfb1d320Bb7

●被攻击合约

0x6e799758cee75dae3d84e09d40dc416ecf713652

漏洞分析

本次事件主要是攻击者利用 market 合约中 claimRewards 函数重入质押以提高 staking 合约余额,再将 staking 合约中多余的代币和质押资产提取以获利。

攻击流程

攻击准备阶段:

1. 攻击者通过攻击合约调用用 Penpie 协议中的 Factory 合约创建了新的 market 以及 Yield,其中将 SY 设置为攻击合约。

0xfda0dde38fa4c5b0e13c506782527a039d3a87f93f9208c104ee569a642172d2

2.攻击者进行闪电贷了四种代币,为后续抵押资金作储备。并调用 staking 合约中的 batchHarvestMarketRewards 函数对新创建的 market 进行奖励更新。

3.在 batchHarvestMarketRewards 函数中,对 market 进行奖励更新时,会调用 market 合约中的 redeemRewards 函数。并且合约记录了 redeemRewards 函数前后的余额变化。

4.在 market 的 redeemRewards 函数中,会调用到 SY 合约中的 claimReward 函数。然而 SY 合约是攻击合约,攻击合约通过这个函数完成了对 Staking 合约的重入,将闪电贷的资金抵押到 Staking 合约,共 4 次。

5.这时回到 Staking,由于 redeemRewards 函数前后余额差明显,触发了_sendRewards 函数,_sendRewards 函数最后调用的_queueRewarder 会将多余的代币授权给 market 合约并记录为奖励。

6.攻击者领取记录的奖励。

7.攻击者将质押的资产通过 withdraw 函数提取,并归还闪电贷进行获利。

Pendle 随后发布攻击分析报告:发现漏洞后立即暂停合约,使 1.05 亿美元资产免受进一步损失。

资金追踪

截止发文时,被盗资金约 2700 万美元,Beosin Trace 追踪发现攻击者已将被盗资金全部转换为 ETH,资金先存放在 0x2f2dDE668e5426463E05D795f5297dB334f61C39 地址。

截止发文,Penpie 攻击者地址向 Tornado Cash 陆续转移了 2900 枚 ETH(价值约 690 万美元)。

目前,Penpie 项目方也通过链上向黑客喊话,希望与黑客进行沟通返还被盗资金,如果返还可以支付赏金。并附上了联系方式。

总结

针对本次事件,Beosin 安全团队建议:1.对合约的相关函数增加防重入修饰器;2.不使用白名单对传入代币进行校验的话,最好使用统一的包装合约重新生成代币;3.项目上线前,强烈建议选择专业的安全审计公司进行全面的安全审计,规避安全风险。

Leituras Relacionadas

IOSG Founder: Web3 Is 'Losing Blood,' How Can Practitioners Survive Better?

IOSG Founder: Web3 Is "Bleeding Out" – How Can Practitioners Survive Better? In a candid reflection, the founder of IOSG Ventures voices deep concerns about the current state of Web3, describing an ecosystem experiencing severe "blood loss." Despite the recent MuShanghai event showcasing a successful pivot towards a more diverse, global community, a somber reality persists: many crypto-native attendees were there exploring exits or new labels in biotech, AI, and robotics. The core issue is identified as a breakdown in the ecosystem's positive feedback loop. Alarmingly, underestimated "low-probability bad events" are occurring simultaneously: a significant brain drain of Chinese developers to AI, a lack of breakout applications despite massive funding, and a widening credibility gap for practitioners globally, often stigmatized as scam artists. This has created a dire接班人 (successor) problem, with the next generation seeing little professional prestige or financial upside in crypto compared to fields like AI. A significant portion of the critique focuses on Ethereum and Vitalik Buterin. While not pessimistic about Ethereum's technology, the founder worries that critical development windows were missed by focusing on niche technical narratives like ZK and L2 instead of mass-market applications. A more urgent concern is that Vitalik may be isolated in an "information bubble," shielded from the grassroots community's hardships by layers of intermediaries, preventing crucial feedback from reaching him. The call is for Vitalik to return to a founder's mindset, re-engage directly with the community, and rally efforts for the next decade. The divergence between U.S. and Chinese OG (Original Gangster) ecosystems is stark. While many U.S. builders reinvest their wealth into the ecosystem, the Chinese scene suffers from a severe lack of "造血能力" (blood-making ability), with most market-driven funds struggling and many early success stories cashing out entirely. This threatens the entire Asian Web3 ecosystem's survival. For individual practitioners, survival advice is pragmatic: find your core "why," maintain life balance beyond token prices, continuously learn new skills (like AI), form small, trusted alliances for mutual support, and practice self-compassion. The industry's greatest need is not money or tech, but lighthouses—individuals at all levels who offer mentorship, grants, referrals, and honest reflection to guide others. The piece concludes with a direct appeal: OGs must pay forward the opportunities the industry gave them; founders must not struggle alone; and builders must continue their work, ensuring it remains a viable profession. The survival of Web3's "cathedral" depends not on any single leader but on the collective responsibility of everyone who remains.

marsbitHá 52m

IOSG Founder: Web3 Is 'Losing Blood,' How Can Practitioners Survive Better?

marsbitHá 52m

Deficits, Inflation, and the New Fed: The Deep Logic Behind US Bond Yields Breaking 5% and the Market Reset

In the week of May 15-19, 2026, U.S. long-term Treasury yields surged to multi-year highs, with the 30-year yield hitting 5.2%, a level unseen since 2007, and the 10-year yield climbing to 4.687%. Equity markets declined in response. Four primary factors are driving the rise in yields. First, stubborn inflation persists, with April wholesale prices rising 6% year-over-year, fueling expectations of potential future Fed rate hikes instead of cuts. Second, newly confirmed Fed Chair Kevin Warsh inherits a complex inflation battle, with markets closely awaiting his first FOMC meeting. Third, deteriorating U.S. fiscal health, marked by large deficits and rising debt servicing costs, is eroding the traditional "safe-haven" premium for Treasuries. Fourth, the "One Big Beautiful Bill" tax cuts are projected to add trillions to the national debt, contributing to Moody's recent credit rating downgrade. Rising yields pressure stocks through several channels: a higher discount rate reduces the present value of future earnings (especially for growth stocks); rising risk-free rates compress equity risk premiums, making bonds relatively more attractive; higher borrowing costs impact consumers and corporations; and a stronger dollar affects multinational earnings. For investors, the environment favors value and financial stocks over long-duration growth stocks. Bond investors find attractive yields in short to intermediate maturities, while income investors see the best fixed-income opportunities in over a decade. Key developments to watch include Chair Warsh's first FOMC meeting, upcoming inflation data, Treasury auction demand, and whether the 30-year yield approaches 6%, a level that could trigger a more sustained equity valuation reset. The bond market's message is clear: the era of cheap government borrowing is over, posing a central challenge for markets in late 2026.

marsbitHá 53m

Deficits, Inflation, and the New Fed: The Deep Logic Behind US Bond Yields Breaking 5% and the Market Reset

marsbitHá 53m

Is MicroStrategy Selling Bitcoin Not a Bearish Signal? Deconstructing the 5 Financial Logics Behind Corporate Bitcoin Divestment

The article "Is Strategy Selling Bitcoin Not a Bearish Signal? Decoding 5 Financial Logics Behind Corporate Bitcoin Divestment" analyzes why companies might sell their bitcoin holdings, arguing it's not necessarily negative. It begins by noting the market's surprise at Strategy's potential sale, contrasting its previous "never sell" stance. The core argument is that corporate decisions prioritize shareholder value, and selling bitcoin can be a rational strategic choice. The article outlines five key financial reasons for such sales: 1. **Increase Bitcoin Holdings Per Share:** Companies can use proceeds from bitcoin sales to repurchase shares when the stock price is undervalued relative to its bitcoin assets. This reduces the outstanding share count, potentially increasing the bitcoin amount backing each remaining share. 2. **Optimize Capital Structure & Reduce Financing Costs:** Building cash reserves through bitcoin sales can improve credit ratings (as favored by agencies like S&P), leading to lower future borrowing costs. Repaying debt with sale proceeds also reduces financial leverage. 3. **Legitimate Tax Planning:** In the absence of wash-sale rules for bitcoin in the US, companies can sell to realize capital losses, then repurchase, lowering the tax basis of their holdings and creating tax offsets. 4. **Counter Negative Market Narratives:** A controlled, non-disruptive sale could demonstrate market resilience and disprove fears that corporate selling would crash the market, thereby normalizing bitcoin as a corporate treasury asset. 5. **Repurchase Preferred Stock at a Discount:** If a company's preferred stock trades significantly below its face value, using bitcoin sale proceeds to repurchase it can retire expensive liabilities at a profit, saving on future dividend payments. The conclusion emphasizes that bitcoin's monetary properties offer flexibility. Strategic sales can protect corporate and shareholder interests, making asset utilization more important than rigid "hold" mandates.

marsbitHá 1h

Is MicroStrategy Selling Bitcoin Not a Bearish Signal? Deconstructing the 5 Financial Logics Behind Corporate Bitcoin Divestment

marsbitHá 1h

Why Did Zhipu Surge Nearly 30% in a Single Day?

"Global AI Model Unicorn" Zhipu's stock surged nearly 30% in a single day, reaching a new market cap high. The catalyst was the launch of its GLM-5.1-highspeed API, boasting a generation speed of **400 tokens per second**, setting a new global benchmark. This speed, roughly 3-5 times faster than industry leaders like OpenAI's GPT-4o and Anthropic's Claude, is achieved **without compromising the full-scale model's capabilities**. In the era of AI Agents requiring dozens of self-calls, such latency reduction is critical, transforming speed from a system metric into a determinant of intelligence limits. The breakthrough stems from a three-layer technical overhaul: 1. **TileRT Inference Engine**: Compiles the entire model into a continuous, always-on computation pipeline using "Warp Specialization," minimizing GPU idle time by having different processor groups handle data loading, computation, and communication in parallel. 2. **Heterogeneous Parallelism for MLA**: To efficiently run the GLM-5.1 model using the MLA attention mechanism, TileRT employs a heterogeneous strategy. One GPU handles sparse indexing/routing, while the others perform dense computation, optimizing for MLA's unique workflow. 3. **ZCube Network Architecture**: Replaces the standard Spine-Leaf (ROFT) network topology with a flat, dual-group interconnect. This design creates a single optimal path between any two GPUs, eliminating network congestion at scale and reducing latency. The business impact is significant: a 15% increase in cluster throughput (free extra capacity), a 40.6% reduction in tail latency (improved stability), and a one-third cut in networking hardware costs. Long-term, this innovation challenges the dominance of NVIDIA's integrated hardware-software stack (GPU+NVLink+InfiniBand), potentially benefiting manufacturers of high-density Leaf switches and optical modules while lowering the software barrier for domestic AI chips like Huawei's Ascend. The innovation proves that more can be achieved with the same compute, reshaping the infrastructure beyond just GPUs.

marsbitHá 2h

Why Did Zhipu Surge Nearly 30% in a Single Day?

marsbitHá 2h

Trading

Spot
Futuros

Artigos em Destaque

Como comprar PENDLE

Bem-vindo à HTX.com!Tornámos a compra de Pendle (PENDLE) simples e conveniente.Segue o nosso guia passo a passo para iniciar a tua jornada no mundo das criptos.Passo 1: cria a tua conta HTXUtiliza o teu e-mail ou número de telefone para te inscreveres numa conta gratuita na HTX.Desfruta de um processo de inscrição sem complicações e desbloqueia todas as funcionalidades.Obter a minha contaPasso 2: vai para Comprar Cripto e escolhe o teu método de pagamentoCartão de crédito/débito: usa o teu visa ou mastercard para comprar Pendle (PENDLE) instantaneamente.Saldo: usa os fundos da tua conta HTX para transacionar sem problemas.Terceiros: adicionamos métodos de pagamento populares, como Google Pay e Apple Pay, para aumentar a conveniência.P2P: transaciona diretamente com outros utilizadores na HTX.Mercado de balcão (OTC): oferecemos serviços personalizados e taxas de câmbio competitivas para os traders.Passo 3: armazena teu Pendle (PENDLE)Depois de comprar o teu Pendle (PENDLE), armazena-o na tua conta HTX.Alternativamente, podes enviá-lo para outro lugar através de transferência blockchain ou usá-lo para transacionar outras criptomoedas.Passo 4: transaciona Pendle (PENDLE)Transaciona facilmente Pendle (PENDLE) no mercado à vista da HTX.Acede simplesmente à tua conta, seleciona o teu par de trading, executa as tuas transações e monitoriza em tempo real.Oferecemos uma experiência de fácil utilização tanto para principiantes como para traders experientes.

398 Visualizações TotaisPublicado em {updateTime}Atualizado em 2025.03.21

Como comprar PENDLE

Discussões

Bem-vindo à Comunidade HTX. Aqui, pode manter-se informado sobre os mais recentes desenvolvimentos da plataforma e obter acesso a análises profissionais de mercado. As opiniões dos utilizadores sobre o preço de PENDLE (PENDLE) são apresentadas abaixo.

活动图片