Purrlend discloses a security incident, with damages totaling approximately $1.52 million.

Purrlend reports that the protocol experienced a security attack on April 25th, causing estimated damages of approximately $1.52 million on HyperEVM and MegaETH deployments.

The attacker is believed to have gained control of two-thirds of the team’s multisignature governance wallet, thereby acquiring additional administrative rights, including BRIDGE_ROLE. They then minted about 2 million pUSDm and 4.85 million pUSDC without collateral using the mintUnbacked function, and used these assets as collateral to borrow real assets from the liquidity pool.

The damage on HyperEVM is approximately $1.2 million, and on MegaETH about $325,000. Purrlend has temporarily paused the protocol, revoked access rights, and contacted law enforcement agencies along with blockchain analysis firms to monitor the flow of funds.

The team stated that the root cause was not in the smart contract logic but in the multisignature configuration lacking a time lock. The group is currently considering compensation options but has not announced further details.

Thank you for reading this article!

Please Like, Comment, and Follow TinTucBitcoin to stay updated with the latest news in the cryptocurrency market and not miss any important information!

MEGA-2.68%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin