According to ChainCatcher, Purrlend suffered a security breach on its HyperEVM and MegaETH deployments on May 2, losing approximately $1.52 million. Attackers compromised the protocol’s 2/3 admin multi-signature wallet and granted themselves BRIDGE_ROLE permissions, then minted unbacked pUSDm and pUSDC tokens to borrow assets from the lending pool.
Purrlend has paused the protocol and revoked the compromised permissions. The team is working with security experts, law enforcement, and cross-chain bridge partners to track and recover the stolen funds.
Related News
Hundreds of Ethereum Wallets Simultaneously Hacked, Assets Transferred
500+ Ethereum Wallets Drained in Coordinated Attack, Funds Laundered via ThorChain
Kelp completes a full upgrade of its cross-chain bridge in two weeks, and ether.fi simultaneously hardens WeETH