- An attacker praised a fellow hacker for a successful raid on the Penpie protocol.
- The Penpie breach resulted in a loss of over $27 million in assets.
- In March 2023, Euler Finance was hacked, losing $197 million, but recovered 90% of the stolen funds.
- The Euler Finance hacker commended the Penpie hacker’s decision not to return the stolen assets.
- Penpie is part of the Pendle ecosystem and lost significant amounts of Ethereum and stablecoins in the attack.
- The stolen Penpie assets were converted to ETH and partially laundered through Tornado Cash.
- Cybersecurity expert Kankodu took partial responsibility for the Euler Finance breach due to a bug introduced during a fix.
Introduction
In a recent series of events that have sent ripples through the cryptocurrency world, the hacker responsible for the $197 million Euler Finance breach has expressed admiration for the hacker behind the attack on the Penpie protocol. The headline, ‘Укравший $197 млн хакер похвалил взломщика протокола Penpie’, highlights the growing sophistication and boldness of cybercriminals targeting decentralized finance (DeFi) platforms.
Hacker Commendation for Penpie Attack
The attacker who infiltrated Euler Finance in March 2023 lauded the efforts of the hacker responsible for the Penpie raid. Penpie, part of the Pendle ecosystem, suffered significant losses amounting to more than $27 million, including 2695 rswETH ($6.62 million), 4101 agETH ($10.17 million), 2723 wstETH ($7.77 million), and $2.77 million in sUSDe stablecoins. The stolen assets were subsequently converted into 11,109 ETH, with some funds being funneled through Tornado Cash.
The Euler Finance hacker praised the Penpie attack as a “good job” and commended the decision not to return the stolen assets, stating: “I am glad you kept all the money and didn’t let those scumbags get a single dollar back. You won, they lost. Great job.”
Background on the Euler Finance Hack
In March 2023, Euler Finance, a prominent credit protocol, fell victim to a massive cyberattack, resulting in the loss of $197 million in assets. The Euler Finance team managed to negotiate with the hacker, successfully recovering 90% of the stolen funds by April 4, 2023. The hacker retained approximately $20 million as part of the agreement, leading the Euler Finance team to cease pursuing legal action.
Penpie’s Response and Future Plans
Following the attack on Penpie, the project’s team attempted to reach out to the hacker but received no response. Penpie developers announced plans to devise a strategy to compensate users for their losses. This incident underscores the ongoing vulnerabilities within DeFi platforms and the need for robust security measures.
Cybersecurity Expert’s Involvement
Cybersecurity expert Kankodu revealed his partial responsibility for the Euler Finance breach. He had alerted the Euler Finance team to a vulnerability, and the subsequent fix inadvertently introduced a new bug that the hacker exploited. This highlights the complexities and unintended consequences that can arise during security updates.
Broader Implications for the Crypto Market
These incidents shed light on the persistent threats facing the DeFi sector. As hackers continue to target vulnerabilities, the importance of rigorous security protocols and swift incident response measures cannot be overstated. The successful recovery of funds by Euler Finance offers a glimmer of hope, but the challenges remain substantial.
The cryptocurrency industry must prioritize security enhancements to protect assets and maintain user trust. While the innovative nature of DeFi presents opportunities, it also demands heightened vigilance against cyber threats. As the market evolves, stakeholders must collaborate to fortify defenses and develop effective strategies to mitigate risks, ensuring the sustainable growth of decentralized financial systems.
