Purrlend disclosed that it experienced a security incident last week, resulting in losses of approximately $1.52 million.

PANews reported on May 1st that Purrlend suffered a security incident on April 25th, resulting in a loss of approximately $1.52 million on its HyperEVM and MegaETH deployments. Attackers compromised two-thirds of the team's administrator multisignature wallets, granting malicious addresses multiple administrator privileges, including BRIDGE_ROLE. They then minted approximately 2 million pUSDm and 4.85 million pUSDC without collateral using the mintUnbacked function, using these as collateral to borrow real assets from the liquidity pool. HyperEVM lost approximately $1.2 million, and MegaETH lost approximately $325,000. Purrlend has suspended the protocol, revoked permissions, and contacted law enforcement and blockchain analytics firms to trace the funds. The root cause of the incident was the lack of a time lock in the multisignature configuration, rather than a vulnerability in the smart contract logic. The team is exploring compensation options.

Share to:

Author: PA一线

This content is for market information only and is not investment advice.

Follow PANews official accounts, navigate bull and bear markets together
PANews APP
黄立成本周已亏损442万美元,近7个半月累计亏损7560万美元
PANews Newsflash