Skip to main content
Sign in

Purrlend

avoid.net/purrlend22/100·72% conf.
[AI-DRAFTED · AWAITING VERIFICATION][src:defillama]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·3ZsK3m…VU2u

Summary

Purrlend is a non-custodial DeFi lending and borrowing protocol deployed on HyperEVM and MegaETH, operating as an Aave-style fork designed for leveraged yield farming. On April 25, 2026, the protocol suffered a multisig permission exploit that drained approximately $1.52 million across both networks, collapsing its TVL by roughly 70%. As of late May 2026, the protocol remains paused with no published post-mortem, recovery plan, or user compensation details.

Connected Entities

1 entities
Organizations
Purrlend
Relationships
    Have evidence about Purrlend?

    Timeline(7 events)

    February 2025

    HyperEVM mainnet launches, enabling new DeFi deployments on Hyperliquid's EVM layer.

    25 April 2026

    At approximately 1:20 a.m. UTC, Purrlend's 2-of-3 admin multisig executes a suspicious transaction granting an unknown address the 'bridge' role with elevated permissions inherited from the underlying Aave-style implementation.

    25 April 2026

    Hours after the suspicious role assignment, the attacker uses the granted bridge privileges to mint unbacked tokens and drain liquidity pools across HyperEVM and MegaETH, stealing approximately $1.52 million.

    25 April 2026

    At approximately 9:10 a.m. UTC, Purrlend pauses all protocol operations and posts a brief statement on X: 'We have detected irregular activity on the protocol and are actively investigating.'

    25 April 2026

    Kirby Ong, founder of HypurrCollective, first publicly flags the exploit and documents attacker wallet addresses on both HyperEVM and MegaETH block explorers.

    25 April 2026

    Protocol TVL collapses from approximately $1.5 million to $444,000 as depositor flight follows news of the exploit.

    26 May 2026

    As of this investigation date, the Purrlend protocol remains paused. No post-mortem, user compensation plan, or recovery details have been published. The exploiting address has not been publicly attributed.

    Provenance & Audit Trail

    Decision Log

    This investigation is cryptographically anchored to the Solana blockchain (1 event). 6 of 11 cited source URLs have an Internet Archive snapshot.

    model: claude-sonnet-4-6

    generated: 5/4/2026, 2:54:16 AM

    last updated: 8/29/2026, 11:26:11 PM

    avoid.net — verified advice for a post-truth world