Purrlend hit by $1.5M DeFi exploit after wallet breach
Purrlend lost $1.5M in a DeFi exploit on HyperEVM and MegaETH after a suspicious admin wallet update. The protocol paused operations and began investigating the theft.
Purrlend, a decentralized lending protocol operating on HyperEVM and MegaETH, suffered a coordinated exploit resulting in losses of approximately $1.5 million. The attack impacted both networks, with HyperEVM losing around $1.2 million and MegaETH about $325,000. Stolen assets included USDC, USDT0, USDH, wrapped Bitcoin, and ecosystem tokens such as wstHYPE, kHYPE, WHYPE, and UETH. The breach was traced to a suspicious update of the admin multisig wallet, which granted unauthorized bridge privileges to an unknown address. This allowed the attacker to mint unbacked tokens and extract large sums from the protocol. Security researcher Kirby Ong was the first to flag the suspicious contract activity. In response, Purrlend paused all operations and launched an internal investigation. The attacker's addresses have been identified on block explorers. April 2026 is shaping up to be one of the worst months for DeFi theft, with over $600 million lost in just 18 days.