A malicious individual stole $27M in ETH from Penpie and remitted it through Tornado Cash. The breach, which occurred on September 4, 2024, resulted in the theft of approximately 11,261 ETH. The perpetrator disregarded Penpie’s efforts to recuperate the funds and moved all the missing ETH through the crypto-mixing service.
Penpie tried to get the stolen ETH back by offering the culprit a bounty and a chance to work with them as a white-hat hacker. The framework assured the thief they would not take legal action if the funds were returned. However, the criminal dismissed these offers and continued to launder the resources through Tornado currency.
Penpie also announced a 10% bounty for anyone who could provide information that would lead to the recovery of the stolen assets. Despite this incentive, the hacker transferred the entire $27 million in Ethereum through Tornado Cash, which is known for its ability to obscure cryptocurrency transactions.
On September 8, 2024, the hacker completed the final transfer of 1,661 ETH into Tornado Cash. On-chain analyst Yu Jin reported that this transaction happened just three hours before it was detected. This transfer marked the final step in laundering all the stolen Ethereum.
Tornado Cash, a network that blends crypto payments, allows users to eliminate the identifiable links between senders and receivers. Because of this, it has become a favoured weapon for cybercriminals. Even though there have been efforts to oversee it, Tornado Cash’s autonomous and private nature makes it hard to manage.
The Penpie hack emphasises the security challenges faced by decentralised finance avenues. Penpie, built on the Pendle Finance protocol, aims to enhance liquidity provision and yield farming. It offers features that let users split and trade yield-bearing assets, maximising returns.
Read CRYPTONEWSLAND onYet, the distributed structure of DeFi stages also makes them vulnerable to attacks. The hacker’s ability to wash $27 million without being traced shows the difficulties in securing digital assets in this ecosystem. As of now, there has been no recovery of the stolen funds, leaving Penpie and its users with significant financial losses.
The situation raises an important question: How can DeFi platforms improve their security to prevent such breaches?
#Solana, Aptos, and Ethereum are three #promising altcoins worth #investing in. #SOL #APT #ETH
#Kaspa, Mudrex, and BabyDoge are the #top altcoins for the #bull run. #KAS #MDX #BABYDOGE
#SHIB is nearing critical resistance at 0.00002004 after a breakout as technical indicators signal momentum…
Worldcoin and #TFH were fined $830K by #SouthKorea for privacy violations, including mishandling personal data…
Cardano and #Worldcoin are capturing whale interest with their recent developments. Meanwhile, #IntelMarkets(INTL) is gaining…
#Kaspa (KAS) sees #minor losses despite an 18% rise in #six months. #KAS #Resilient #TA