Purrlend exploited on Hyperliquid; team offers 90% fund return + 10% bounty within 48 hours to resolve as whitehat action.
Security & Exploits ·
An exploit affecting Purrlend on the Hyperliquid network has prompted the project team to issue a public recovery offer to the attacker. In an onchain message, the Purrlend team stated they are tracking fund movements and have identified the wallet involved in removing user assets. They are proposing to classify the incident as a whitehat action if the attacker returns 90% of the stolen funds while keeping 10% as a bug bounty.
The proposal carries a 48-hour deadline and includes assurances that the team will make no further pursuit and publicly acknowledge the resolution as such if terms are accepted. The message also warns that failure to return funds will lead the team to escalate efforts with exchanges, analytics firms, and law enforcement to trace and recover the assets. The Purrlend team indicated willingness to communicate directly with the attacker via Blockscan chat.
The specifics of how the exploit was executed and the total amount of funds involved remain unclear from the available information. It is not yet known whether the attacker has responded to the proposal or whether any funds have been returned as of reporting.