Pendle

Orange · 66/100

Executive summary

Pendle is a yield-trading protocol that tokenizes yield-bearing assets into Principal Tokens (PT) and Yield Tokens (YT), enabling fixed-yield and yield-speculation strategies across multiple chains; it scores 52/100 (orange band) with high data confidence (92/100) and a -10 penalty for unresolved incident remediation.

  • Security: Pendle V2 has undergone 10+ audits by reputable firms (Ackee, ChainSecurity, Dedaub, CMichel, Dingbats, 0xleastwood, WatchPug, Spearbit) between 2021–2024, with no unresolved critical or high findings documented in available reports; medium/low issues were largely fixed or acknowledged. A $2M bug bounty on Cantina is active. Bytecode match to deployed contracts is not verifiable as of 2026-09-05.
  • Incidents: Two ecosystem exploits occurred: Penpie (Sept 2024, $27.3M loss via reentrancy in a third-party integrator, Pendle core unaffected but paused contracts preventively) and Equilibria (Aug 2025, $62.5K reward-pool drain, Pendle markets unaffected). Both incidents remain in remediation_in_progress status with unverified reimbursement; Pendle itself has no verified protocol-level exploit. A Sept 2025 wallet compromise (~$1M) was attributed to phishing, not contract flaws.
  • Governance & custody: Pendle is non-custodial; users control assets until depositing into contracts. Governance is via sPENDLE/vePENDLE voting, but a 2-of-4 multisig (PendleGovernanceProxy admin) can pause markets and upgrade the proxy without timelock; a guardian EOA can pause/update caps. Token voting influences emissions and fees but does not control all upgrades or emergency powers (dao_governance=false). Operated by Univerum Innovations Inc. (Panama), with Singapore governing law.
  • Top risks: (1) Underlying asset/SY insolvency or depeg can impair PT/YT/LP positions (high severity, medium probability); (2) oracle manipulation or thin liquidity can distort pricing and trigger liquidations; (3) leveraged PT looping adds money-market and liquidation risk; (4) bridge exploits or chain fragmentation can strand bridged assets; (5) permissionless market listing enables malicious-token risk (as seen in Penpie). Chain-specific TVL and exposure are not verifiable as of 2026-09-06.
  • Strengths: First-mover in yield tokenization with strong fixed-yield utility; specialized maturity-based AMM optimized for yield assets; broad DeFi integrations (LSTs/LRTs, restaking); leading on-chain yield-trading venue with high adoption; extensive multi-chain deployment (Ethereum, Arbitrum, BSC, Base, Monad, Plasma, HyperEVM).
  • Unverified: Deployed-code bytecode match, chain-by-chain TVL/exposure, reserve/treasury balances, leverage ratios, organic vs. subsidized yield share, exact admin/timelock wiring per chain, and full remediation status for Penpie/Equilibria incidents are all not verifiable as of 2026-09-06. Dune was unavailable, preventing on-chain verification.
  • Recommended exposure: Limit to <5% of portfolio; favor mature, liquid PT markets on Ethereum/Arbitrum with well-audited underlying assets (e.g., stETH, major stablecoins); avoid newly launched or low-liquidity markets; monitor maturity dates and underlying protocol health; do not use leveraged PT looping without strict collateral/liquidation monitoring; verify redemption mechanics and SY adapter security before entry; treat YT as directional/leveraged exposure requiring active management.
  • Open questions: Verify current on-chain TVL, collateral composition, and leverage ratios by chain; confirm Penpie/Equilibria reimbursement completion and user recovery status; review deployed bytecode match for all audited contracts; assess multisig signer identities and timelock implementation; quantify organic vs. incentivized yield share per market; evaluate bridge security for cross-chain PENDLE; confirm withdrawal-pause status and emergency-admin scope; test redemption flow and liquidity depth for target PT/YT markets before allocation.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 28 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 80 16.0 full audit within 365 days (latest 2026-01-11); auditor not in top-20 -20
Incidents 20% 100 20.0 2 open incident(s), $27,362,500 at risk; TVL unavailable, exposure not assessable
Governance 20% 50 10.0 no DAO governance
TVL 20% 0 0.0 TVL unavailable on DeFiLlama
Data confidence 92 7/7 critical categories; 46/76 verified facts; 75/76 fresh (180d)

Identification

protocol identification

two sources

Pendle is a yield trading protocol that tokenizes and separates yield from principal on yield-bearing assets, letting both trade on a custom AMM across multiple chains. Identification

  • Name: Pendle Finance (often just Pendle)
  • Category: DeFi yield trading / fixed yield and yield derivatives AMM.
  • Website: The primary app and marketing site are hosted under the Pendle domain, referenced in external reviews and protocol UIs.
  • Docs: Technical and deployment documentation is hosted on the Pendle docs site.
  • Native token: PENDLE (ERC‑20), with an Arbitrum token contract shown on Arbiscan as “Pendle (PENDLE)” and described as a protocol for tokenizing yield.
  • Launch date: A Revolut listing document cites a public offer/admission starting 2021‑04‑16, giving a reasonable proxy for initial token launch. Chains (focus set: Ethereum, Arbitrum, BSC, Base, Hyperliquid L1, Monad, Plasma)
  • External analytics and the app UI show Pendle deployed on Ethereum, Arbitrum, BNB Chain, Base, Monad, and a Plasma-branded environment, plus other networks (Mantle, Optimism, Sonic, HyperEVM, Berachain, Katana, Ink).
  • Hyperliquid/HyperEVM is referenced via markets pages, indicating support for a Hyperliquid L1‑adjacent environment.
  • Precise chain‑by‑chain TVL is reported by an independent analytics platform (e.g., Ethereum, Plasma, Monad, Arbitrum, BNB, Base), but these remain aggregator data, not on‑chain verified. Main contract addresses & verification status
  • Pendle documentation specifies that core contract addresses per chain are stored in deployment JSON files (e.g., 1-core.json for Ethereum, 56-core.json for BNB Chain, 8453-core.json for Base, 42161-core.json for Arbitrum) in the contract repository.
  • Because direct on‑chain queries are not available in this run, all contract addresses are Not verifiable as of 2026-09-04 for on‑chain confirmation.
  • The PENDLE ERC‑20 token on Arbitrum is shown on Arbiscan with verified metadata; contract verification status for core protocol contracts on each chain is Not verifiable as of 2026-09-04. Fork lineage & code provenance
  • Independent descriptions present Pendle as a novel protocol for tokenized yield and a custom AMM, not as a fork of a specific upstream protocol.
  • No credible external source identifies Pendle as a direct fork (e.g., of Uniswap, Yield, or other yield AMMs), nor details of fork‑specific changes.
  • Audit coverage and any fork‑related malicious modifications in similar protocols are Not verifiable as of 2026-09-04 under the current tool constraints. Key caveat
  • All contract‑level and audit‑level facts that would normally rely on raw on‑chain or repository analysis remain Not verifiable as of 2026-09-04; current answer is limited to external documentation and analytics descriptions.
Evidence (12)

maturity

two sources

Pendle appears to be a real, live product rather than a static landing page: its documentation exposes public endpoints for markets, prices, positions, and a universal convert API, and the docs explicitly describe swap, add/remove liquidity, mint/redeem PT/YT, and transfer-liquidity flows. The docs also include chain-aware deposit/withdrawal guidance, which is a strong sign of operational UX rather than template-only marketing. An open API exists.

Pendle documents a public API base URL at api-v2.pendle.finance/core, with public endpoints under that path and separate hosted SDK/backend API docs. What is not verifiable here: live deposit/withdrawal success rates, broken-link frequency, fake metrics, or template-sign checks across the full website/app are not verifiable as of 2026-09-04. The available evidence supports a mature documentation and API surface, but not a complete hands-on portal audit.

Evidence (6)

Security

bug bounty

two sources

Pendle appears to have an active bug bounty program on Cantina, started 14 Jun 2024, focused on smart contract security and preventing loss of user funds/protocol insolvency. The program page shows a total reward pool of $2,000,000 with a $100 deposit required and 96 findings submitted. It states rewards are capped at 10% of economic impact, with smart-contract severity bands including Critical up to $1,000,000 and High up to $100,000; for critical/high smart-contract bugs, rewards are 10% of funds directly affected up to those caps.

A separate Immunefi page for Pendle also exists, but the current Cantina program is the clearest active public bounty listing. Publicly disclosed results are not clearly enumerated on the program page beyond the 96 submissions, so specific paid-out bounty outcomes are not verifiable as of 2026-09-04.

Active
Yes
Platform
Cantina
Max payout
$1.0M
Since
2024-06-14
Evidence (2)

counterparty risks

one source

Assessment date: September 6, 2026. Dependency map and failure scenarios

  • Underlying yield assets are first-order counterparties. Pendle markets wrap external yield-bearing assets, including stablecoins, LST/LRT/restaking tokens, lending positions and tokenized/RWA products. Failure, depeg, exploit, redemption freeze, custodian/SPV insolvency, or adverse issuer governance can impair SY redemption and cause PT/YT losses. Specific current asset-by-asset exposure is Not verifiable as of 2026-09-06 because Dune/on-chain verification is unavailable.
  • Oracle and manipulation risk: Pendle’s linear-discount PT oracle is designed to rely mainly on time-to-maturity and is less manipulation-sensitive. However, TWAP/LP oracles remain dependent on AMM liquidity, observation quality and market depth. Boros introduces separate third-party reference-market and rate-oracle risk: manipulated, delayed or unavailable funding-rate data can affect settlement.
  • AMM and liquidity risk: Thin or newly launched markets can experience price impact, oracle distortion, liquidation cascades and inability to exit. Leveraged PT looping adds money-market, liquidation and underlying-depeg risk across multiple protocols.
  • Bridges and chain fragmentation: Pendle documents bridging PENDLE through Arbitrum, Portal/BNB, Base, Stargate/Hyperliquid and other bridge infrastructure. Bridge exploit or message failure could make bridged assets unbacked or illiquid. The protocol’s current exposure by bridge, vault, or chain cannot be verified on-chain.
  • CEX/MM/custodian exposure: No verified evidence establishes Pendle as a custodian, CEX counterparty, or market maker. Any exposure would generally be indirect through underlying yield products, RWA issuers/SPVs, lending venues, liquidity providers, or Boros reference markets. Not verifiable as of 2026-09-06. Chain concentration (analytics only, not on-chain verified): DeFiLlama reports approximately $1.173B TVL, concentrated in Ethereum (~59%), Monad (~15%), Arbitrum (~11%), Plasma (~10%), Hyperliquid L1 (~3%), BSC (~2%), and Base (~0.3%). These figures are stale/aggregated snapshots and do not establish counterparty exposure. Failure scenarios: underlying stablecoin/LST depeg; restaking or lending insolvency; RWA issuer/custodian default; bridge compromise; oracle/reference-market manipulation; AMM liquidity loss; or correlated liquidation across Pendle plus integrated money markets. Loss could be material or total for affected markets. Conclusion: Dependency failure risk is structurally high and highly market-specific; no active systemic dependency failure was independently verified in this run. On-chain exposure percentages and maximum loss concentration: Not verifiable as of 2026-09-06.
Evidence (4)

crypto custody

unverified

Pendle is organized as a self-directed, non-custodial protocol: the Terms state it is a “pass-through” infrastructure layer and that neither the company nor affiliates act as a custodian or intermediary. Users keep control of assets in their own wallets until they voluntarily deposit them into Pendle smart contracts, where the assets are tokenized and split into PT/YT (and related yield primitives) for on-chain use. For the selected chains, the custody model is the same at the protocol level; no chain-specific custody segregation was verifiable from the available sources.

Withdrawal pause status for protocol user assets was not verifiable as of 2026-09-06.

Evidence (2)

incident

two sources

Penpie, an independent Pendle ecosystem yield optimizer, was exploited on September 3, 2024. A reentrancy flaw in its reward-harvesting integration was enabled by permissionless listing of malicious Pendle markets/tokens. Affected: Penpie depositor funds and Penpie positions involving Pendle-related assets; Pendle core markets and LP principal were reported unaffected.

Pendle detected the attack, paused its contracts, coordinated with security responders, and prevented an estimated additional ~$105M exposure; Pendle contracts were subsequently unpaused. Penpie proposed a recovery plan and continues to expose a recovery-claim process, but actual recovered funds and user reimbursement are Not verifiable as of September 6, 2026. The vulnerability was isolated to Penpie’s integration and market-listing design; the remediation/recovery process remains incomplete.

Date
2024-09-03
Cause
Smart-contract exploit
Loss
$27.3M
Attacker proceeds
$27.3M
Status
remediation in progress
Recovered
$0
Event id
penpie-2024-09-03
Evidence (5)

incident

one source

In September 2024, Pendle was indirectly affected by the Penpie exploit. Reporting says Pendle paused contracts to prevent further loss and claimed it helped protect roughly $105M of additional user funds; however, the gathered sources do not verify a direct loss on Pendle’s core protocol, reimbursement, or a protocol-level compromise.

Date
2024-09-05
Cause
Smart-contract exploit
Evidence (1)

incident

two sources

Equilibria Finance, a separate Pendle ecosystem integrator, suffered an Ethereum stk-ePENDLE auto-compounder exploit in August 2025. The Ethereum implementation incorrectly allowed stk-ePENDLE transfers; repeated transfers triggered reward claims and drained approximately 13.36 ETH from accumulated, unclaimed ETH rewards. Affected: Equilibria’s reward pool and potentially missed user rewards; Pendle markets, LP principal and ePENDLE balances were reported unaffected.

Equilibria paused functions, contained the exploit, restored operations, committed to deploying the secure non-transferable implementation used on other chains, and stated that its treasury would compensate missed rewards. Actual reimbursement and recovered amount are Not verifiable as of September 6, 2026. The contract fix and operational remediation were reported completed, but compensation completion is unverified.

Date
2025-08-27
Cause
Smart-contract exploit
Loss
$62K
Attacker proceeds
$62K
Status
remediation in progress
Event id
equilibria-2025-08-27
Evidence (2)

incident

one source

Equilibria Finance, a separate Pendle ecosystem integrator, suffered an exploit in its Ethereum stk-ePENDLE auto-compounder in August 2025. The implementation incorrectly allowed stk-ePENDLE transfers; repeated transfers triggered reward claims, draining approximately 13.36 ETH (reported around $62.5K). Affected: Equilibria’s unclaimed ETH-reward pool; Pendle markets and LP principal were reported unaffected.

Equilibria paused functions, contained the exploit, planned to replace the Ethereum implementation with the secure version used elsewhere, and stated that its treasury would compensate missed rewards. Actual reimbursement and final payment amount are Not verifiable as of September 5, 2026. Current status: remediation_in_progress.

Date
2025-08
Cause
Smart-contract exploit
Loss
$62K
Attacker proceeds
$62K
Status
remediation in progress
Evidence (1)

incident

one source

Pendle has no clearly documented protocol-level exploit with disclosed loss in the sources gathered. The strongest incident signal is a September 2025 wallet compromise affecting a single wallet interacting with Pendle markets; the team said Pendle itself was not hacked and that user funds were safe, with the incident attributed to wallet compromise/phishing rather than a smart-contract flaw. The only quantified impact in the gathered material is a reported ~$1M extracted via swaps and a temporary ~5% PENDLE price dip, but this is from secondary reporting and not a verified protocol loss.

Date
2025-09-30
Cause
Key compromise
Loss
$1.0M
Evidence (1)

key management

two sources

Pendle’s key management appears to be primarily user-side wallet security plus protocol governance via vePENDLE, rather than a centrally managed key system. Pendle’s Terms of Use explicitly state that users are responsible for keeping their private keys and wallet login credentials secure, which indicates the protocol does not custody user keys. Governance and protocol coordination are organized around PENDLE/vePENDLE, where staking PENDLE yields vePENDLE that confers governance rights and incentive control over the protocol.

For cross-chain operations, Pendle runs a unified protocol across multiple chains with business logic on Ethereum and execution elsewhere, coordinated by LayerZero messaging and OFT token movement; this suggests multi-chain operational control is coordinated by protocol infrastructure rather than by separate chain-specific key regimes. Publicly available sources do not specify a formal internal key-management architecture for admins, multisigs, or timelocks, so that part is Not verifiable as of 2026-09-04.

Evidence (4)

smart-contract

two sources

As of September 6, 2026. Dune was unavailable; therefore all on-chain role, proxy-admin, timelock-delay, and withdrawal-path checks are Not verifiable as of September 6, 2026. No Dune query/execution IDs exist for this run. Addresses / architecture. Pendle publishes chain-ID deployment manifests ({chainId}-core.json). The inspected Ethereum manifest lists proxyAdmin 0xA28c08f165116587D4F3E708743B4dEe155c5E64, devProxyAdmin 0xD37eB2E6DE40a33ba68BaD94427723b66c954EA9, timelockController 0x68d8D192dF476bC01895E16b0ED3945673d777AC, and timelockedProxyAdmin 0x77C67F645540A2f8223F82D9597DFeF483714732.

RouterV4 is documented at 0x888888888889758F76e7103c6CbF23ABbF58F946 and explicitly described as upgradeable. Exact addresses and admin wiring for Arbitrum, BSC, Base, HyperEVM, Monad, and Plasma: Not verifiable as of September 6, 2026. User → Router → SY wrappers → PT/YT → Pendle Market/AMM → underlying integrations ↘ factories / oracle / rewards Governance or ProxyAdmin → upgradeable modules; Timelock path (scope and delay unverified) Admin powers / exit risk. Pause, unpause, fee, treasury, oracle, factory, strategy, withdrawal/recovery, and upgrade permissions by deployment: Not verifiable as of September 6, 2026. Router documentation says it has no special permissions over interacted contracts; this does not establish that factories, SYs, markets, or governance are permissionless.

Users generally have protocol-defined redemption/withdrawal routes, but whether users can exit during an admin pause or implementation upgrade is Not verifiable as of September 6, 2026. Key compromise worst case: malicious upgrades, market/SY configuration, fee/treasury redirection, oracle manipulation, or freezing activity—capability depends on each deployment’s roles and is unverified. Audit evidence. Public audits exist. ChainSecurity’s August 15, 2024 V2 Core review reported 0 critical and 0 high findings in its reviewed revision, but audit scope/version does not prove every current deployment is audited.

The older Least Authority review excluded governance and timelock components and left a governance follow-up recommendation unresolved. Contradiction / scope flag: the requested “Hyperliquid L1” does not match Pendle’s current deployment documentation, which names HyperEVM (chain 999); Plasma is not listed there.

Upgradeable
Yes
Evidence (5)

audit

one source

0xleastwood audit report — 0xleastwood Part 1 + 2; file audits/main codebase/0xleastwood/0xleastwood-Part 1 + 2.pdf in pendle-finance/pendle-core-v2-public (protocol audit catalog).

Auditor
0xleastwood
Scope
0xleastwood Part 1 + 2
File
0xleastwood-Part 1 + 2.pdf
Catalog only
Yes
Evidence (1)

audit

one source

0xleastwood audit report — 0xleastwood Part 2; file audits/main codebase/0xleastwood/0xleastwood-Part 2.pdf in pendle-finance/pendle-core-v2-public (protocol audit catalog).

Auditor
0xleastwood
Scope
0xleastwood Part 2
File
0xleastwood-Part 2.pdf
Catalog only
Yes
Evidence (1)

audit

one source

Ackee audit report — Ackee Part 1; file audits/main codebase/Ackee/Ackee-Part 1.pdf in pendle-finance/pendle-core-v2-public (protocol audit catalog).

Auditor
Ackee
Scope
Ackee Part 1
File
Ackee-Part 1.pdf
Catalog only
Yes
Evidence (1)

audit

one source

ChainSecurity-2024 audit report — ChainSecurity; file audits/main codebase/ChainSecurity-2024/ChainSecurity.pdf in pendle-finance/pendle-core-v2-public (protocol audit catalog).

Auditor
ChainSecurity-2024
Scope
ChainSecurity
File
ChainSecurity.pdf
Catalog only
Yes
Evidence (1)

audit

one source

CMichel audit report — Cmichel Part 1; file audits/main codebase/CMichel/Cmichel-Part 1.pdf in pendle-finance/pendle-core-v2-public (protocol audit catalog).

Auditor
CMichel
Scope
Cmichel Part 1
File
Cmichel-Part 1.pdf
Catalog only
Yes
Evidence (1)

audit

one source

CMichel audit report — CMichel Part 2; file audits/main codebase/CMichel/CMichel-Part 2.pdf in pendle-finance/pendle-core-v2-public (protocol audit catalog).

Auditor
CMichel
Scope
CMichel Part 2
File
CMichel-Part 2.pdf
Catalog only
Yes
Evidence (1)

audit

one source

Dedaub audit report — Dedaub Part 1; file audits/main codebase/Dedaub/Dedaub-Part 1.pdf in pendle-finance/pendle-core-v2-public (protocol audit catalog).

Auditor
Dedaub
Scope
Dedaub Part 1
File
Dedaub-Part 1.pdf
Catalog only
Yes
Evidence (1)

audit

one source

Dingbats audit report — Dingbats Part 1; file audits/main codebase/Dingbats/Dingbats-Part 1.pdf in pendle-finance/pendle-core-v2-public (protocol audit catalog).

Auditor
Dingbats
Scope
Dingbats Part 1
File
Dingbats-Part 1.pdf
Catalog only
Yes
Evidence (1)

audit

one source

Dingbats audit report — Dingbats Part 2; file audits/main codebase/Dingbats/Dingbats-Part 2.pdf in pendle-finance/pendle-core-v2-public (protocol audit catalog).

Auditor
Dingbats
Scope
Dingbats Part 2
File
Dingbats-Part 2.pdf
Catalog only
Yes
Evidence (1)

audit

one source

LinearDiscountOracle audit report — WatchPug SparkLinearDiscountOracle; file audits/LinearDiscountOracle/WatchPug-SparkLinearDiscountOracle.pdf in pendle-finance/pendle-core-v2-public (protocol audit catalog).

Auditor
LinearDiscountOracle
Scope
WatchPug SparkLinearDiscountOracle
File
WatchPug-SparkLinearDiscountOracle.pdf
Catalog only
Yes
Evidence (1)

audit

one source

LpPtoracle audit report — WatchPug LpOracle; file audits/LpPtoracle/WatchPug-LpOracle.pdf in pendle-finance/pendle-core-v2-public (protocol audit catalog).

Auditor
LpPtoracle
Scope
WatchPug LpOracle
File
WatchPug-LpOracle.pdf
Catalog only
Yes
Evidence (1)

audit

one source

LpPtoracle audit report — WatchPug PtOracle; file audits/LpPtoracle/WatchPug-PtOracle.pdf in pendle-finance/pendle-core-v2-public (protocol audit catalog).

Auditor
LpPtoracle
Scope
WatchPug PtOracle
File
WatchPug-PtOracle.pdf
Catalog only
Yes
Evidence (1)

audit

one source

marketV6 audit report — HickupHH3; file audits/marketV6/HickupHH3.pdf in pendle-finance/pendle-core-v2-public (protocol audit catalog).

Auditor
marketV6
Scope
HickupHH3
File
HickupHH3.pdf
Catalog only
Yes
Evidence (1)

audit

one source

marketV6 audit report — WatchPug; file audits/marketV6/WatchPug.pdf in pendle-finance/pendle-core-v2-public (protocol audit catalog).

Auditor
marketV6
Scope
WatchPug
File
WatchPug.pdf
Catalog only
Yes
Evidence (1)

audit

one source

marketV7 audit report — HickupHH3; file audits/marketV7/HickupHH3.pdf in pendle-finance/pendle-core-v2-public (protocol audit catalog).

Auditor
marketV7
Scope
HickupHH3
File
HickupHH3.pdf
Catalog only
Yes
Evidence (1)

audit

one source

marketV7 audit report — WatchPug; file audits/marketV7/WatchPug.pdf in pendle-finance/pendle-core-v2-public (protocol audit catalog).

Auditor
marketV7
Scope
WatchPug
File
WatchPug.pdf
Catalog only
Yes
Evidence (1)

audit

one source

PtLooping audit report — WatchPug; file audits/PtLooping/WatchPug.pdf in pendle-finance/pendle-core-v2-public (protocol audit catalog).

Auditor
PtLooping
Scope
WatchPug
File
WatchPug.pdf
Catalog only
Yes
Evidence (1)

audit

one source

Spearbit-2024 audit report — Spearbit; file audits/main codebase/Spearbit-2024/Spearbit.pdf in pendle-finance/pendle-core-v2-public (protocol audit catalog).

Auditor
Spearbit-2024
Scope
Spearbit
File
Spearbit.pdf
Catalog only
Yes
Evidence (1)

audit

one source

sPendle audit report — WatchPug; file audits/sPendle/WatchPug.pdf in pendle-finance/pendle-core-v2-public (protocol audit catalog).

Auditor
sPendle
Scope
WatchPug
File
WatchPug.pdf
Catalog only
Yes
Evidence (1)

audit

one source

WatchPug audit report — WatchPug Part 1; file audits/main codebase/WatchPug/WatchPug-Part 1.pdf in pendle-finance/pendle-core-v2-public (protocol audit catalog).

Auditor
WatchPug
Scope
WatchPug Part 1
File
WatchPug-Part 1.pdf
Catalog only
Yes
Evidence (1)

audit

one source

WatchPug audit report — WatchPug Part 1 Follow Up 1; file audits/main codebase/WatchPug/WatchPug-Part 1 Follow Up 1.pdf in pendle-finance/pendle-core-v2-public (protocol audit catalog).

Auditor
WatchPug
Scope
WatchPug Part 1 Follow Up 1
File
WatchPug-Part 1 Follow Up 1.pdf
Catalog only
Yes
Evidence (1)

audit

one source

WatchPug audit report — WatchPug Part 1 Follow Up 2; file audits/main codebase/WatchPug/WatchPug-Part 1 Follow Up 2.pdf in pendle-finance/pendle-core-v2-public (protocol audit catalog).

Auditor
WatchPug
Scope
WatchPug Part 1 Follow Up 2
File
WatchPug-Part 1 Follow Up 2.pdf
Catalog only
Yes
Evidence (1)

audit

one source

WatchPug audit report — WatchPug Part 2; file audits/main codebase/WatchPug/WatchPug-Part 2.pdf in pendle-finance/pendle-core-v2-public (protocol audit catalog).

Auditor
WatchPug
Scope
WatchPug Part 2
File
WatchPug-Part 2.pdf
Catalog only
Yes
Evidence (1)

audit

one source

0xleastwood — Pendle Finance Security Review. Scope: Pendle V2 contracts. Covers deployed code: Not verifiable as of 2026-09-05.

Auditor
0xleastwood
Report date
2022-09-13
Scope
Pendle V2 security review
Findings
3 medium, 6 low, 7 informational, 3 gas optimizations.
Fix status
Not verifiable as of 2026-09-05.
Evidence (1)

audit

two sources

Pendle V2 audit (part of V2 core) with security review performed over four engineering weeks between April 25 and May 20, 2022.

Auditor
Ackee Blockchain
Report date
2022-05-20
Scope
Pendle V2 core contracts including yield tokenization and related components; scope details in Ackee-Part1.pdf in Pendle V2 audits repo.[1][10][14]
Findings
Ackee identified 11 issues total: **Medium** – 3 (insufficient data validation in PendleAaveV3SCY; integer overflow in Math library; usage of solc optimizer); **Warning** – 5 (potential front‑running in withdraw/mint; exotic tokens; dangerous callbacks; unintended change of reentrancy lock state; dynamic config inconsistency risk); **Informational** – 3 (redundant cycle in RewardManager; same function names across project; unused code). No critical or high findings.[1]
Fix status
Ackee recommends Pendle address all reported issues; Pendle documentation states V2 codebase fully audited and flaws addressed, but bytecode‑match to deployed contracts is Not verifiable as of 2026-09-04.[1][2][9][14]
Evidence (4)

audit

one source

Ackee — Pendle V2 Part 1. Scope: Pendle V2 core contracts. Covers deployed code: Not verifiable as of 2026-09-05; no bytecode match performed.

Auditor
Ackee Blockchain
Report date
2022-05-24
Scope
Pendle V2 core contracts
Findings
3 high, 5 warning, 3 informational reported.
Fix status
Not verifiable as of 2026-09-05.
Evidence (1)

audit

unverified

Pendle V2 audit summary. The snippet lists no Critical or High issues, Medium issues M1/M2/M3, and the repository scope excluded several files. Fix status is not fully verifiable from the gathered snippet alone.

Auditor
Ackee Blockchain
Report date
2023-06-27
Scope
All contracts under the contracts folder except core/PendleSCYImpl/AaveV3/WadRayMath.sol, core/RouterStatic.sol, libraries/ExpiryUtilsLib.sol, and libraries/JoeLibrary.sol.
Evidence (1)

audit

two sources

Pendle V2 Core smart contract audit.

Auditor
ChainSecurity
Report date
2022-12-20
Scope
Pendle V2 Core contracts: base SY implementation, PY V1 and markets V1; more derived SY implementations out of scope.[3][11]
Findings
ChainSecurity summarizes security as good with some low‑severity functional correctness issues; notes dependence of SY security on derived implementations (out of scope) and specification improvement areas. Detailed issue list is in ChainSecurity.pdf; high‑severity findings are not mentioned in the public summary.[3][11]
Fix status
Report characterizes security level as good; Pendle claims all flaws addressed, but specific remediation per finding and confirmation against deployed bytecode are Not verifiable as of 2026-09-04.[3][2][9][11][14]
Evidence (3)

audit

two sources

Pendle V2 Core Smart Contracts audit; in-scope files included core/YieldContracts/PendlePrincipalToken.sol, InterestManagerYT.sol, PendleYieldToken.sol, PendleYieldContractFactory.sol, and PendleERC20Permit.sol, among others.

Auditor
ChainSecurity
Report date
2022
Scope
Pendle V2 Core Smart Contracts
Findings
0 Critical, 0 High, 2 Medium, 9 Low.
Fix status
Medium findings were code corrected; the report states 2 Medium issues were code corrected. Low findings were mixed: 2 code corrected, 1 partially corrected, and 1 risk accepted (remaining low findings listed in the report).
Evidence (2)

audit

unverified

Pendle V2 Core audit. The report snippet says the assessment was performed on source files in the Pendle V2 Core repository. Findings shown in the snippet: Critical 0, High 0, Medium 2, Low 2; the medium issues were marked code corrected, and the low issues were also marked code corrected.

Auditor
ChainSecurity
Report date
2024-12-28
Scope
Pendle V2 Core repository files listed in the report, including core/YieldContracts and related ERC20/periphery files.
Evidence (2)

audit

one source

CMichel — Pendle V2 Liquidity Mining. Scope: liquidity-mining contracts. Covers deployed code: Not verifiable as of 2026-09-05.

Auditor
cmichel
Report date
2022-08-15
Scope
Pendle V2 liquidity mining
Findings
2 medium, 1 low, 1 informational, 6 minor.
Fix status
Medium: 2 fixed; informational: 1 fixed; remaining findings mixed fixed/acknowledged.
Evidence (1)

audit

one source

CMichel — Pendle V2 Main Contracts. Scope: main V2 contracts. Covers deployed code: Not verifiable as of 2026-09-05.

Auditor
cmichel
Report date
2022-08-25
Scope
Pendle V2 main contracts
Findings
3 high, 4 medium, 5 low, 3 informational, 17 minor.
Fix status
High: 3 fixed; medium: 4 fixed; remaining findings mixed fixed/acknowledged.
Evidence (1)

audit

two sources

Pendle Finance V2 Yield Tokenization and Trading audit; scope covered the V2 yield tokenization/trading contracts.

Auditor
Dedaub
Report date
2022-07-01
Scope
Pendle Finance V2 Yield Tokenization and Trading
Findings
No Critical, High, or Medium issues were identified.
Fix status
No Critical/High/Medium fixes were required; report indicates findings were absent at those severities.
Evidence (2)

audit

one source

Dingbats — Pendle V2 Part 1. Scope: V2 core. Covers deployed code: Not verifiable as of 2026-09-05.

Auditor
Dingbats
Report date
2022-11-29
Scope
Pendle V2 Part 1
Findings
1 medium, 5 low, 7 informational.
Fix status
Reported as resolved in secondary audit index; independent remediation verification not located.
Evidence (1)

audit

one source

Correction to previously recorded catalog item: sPendle report was misattributed. The auditor is WatchPug and the audited scope is sPendle; the prior record reversed these fields.

Auditor
WatchPug
Report date
2026-01-11
Scope
sPendle staking/governance subsystem.
Findings
Reported externally as 5 total issues; critical/high/medium breakdown and individual severities are Not verifiable as of 2026-09-06 from an independent primary report extraction.
Fix status
Mixed fixed and acknowledged findings reported; exact residual status is Not verifiable as of 2026-09-06. Bytecode match to deployed code is Not verifiable as of 2026-09-06.
Report url
https://github.com/pendle-finance/pendle-core-v2-public/blob/main/audits/sPendle/WatchPug.pdf
Report id
doc:01f4ce9a26eee4b0
Evidence (2)

audit

one source

Newly identified legacy audit report: Pendle Protocol Smart Contracts audit.

Auditor
Least Authority
Report date
2021-05-21
Scope
Pendle Protocol smart contracts; exact commit/deployment mapping not established.
Findings
Not verifiable as of 2026-09-06 from the accessible report metadata.
Fix status
The report recommends follow-up review; current remediation is Not verifiable as of 2026-09-06.
Report url
https://leastauthority.com/static/publications/LeastAuthority_Pendle_Protocol_Pendle_Smart_Contracts_Final_Audit_Report.pdf
Report id
doc:2941d42e91ca991c
Evidence (1)

audit

two sources

Newly verified published audit report: Pendle V2 Core assessment by ChainSecurity.

Auditor
ChainSecurity
Report date
2024-08-15
Scope
Base SY implementation, PY V1, and markets V1; SY-derived implementations were out of scope.
Findings
0 critical, 0 high, 2 medium, 9 low, 8 informational/notes reported by the available audit summary.
Fix status
Two medium findings reported corrected; remaining low findings acknowledged or risk-accepted. Current deployed-code remediation and bytecode match are Not verifiable as of 2026-09-06.
Report url
https://www.chainsecurity.com/security-audit/pendle-v2-core
Report id
doc:d62ce2698b5df149
Unresolved critical
0
Unresolved high
0
Evidence (2)

audit

two sources

Pendle Protocol Smart Contracts (Pendle v1, Ethereum main deployment). Audit timeline April–June 2021, final report 4 June 2021.

Auditor
Least Authority
Report date
2021-06-04
Scope
Core Pendle protocol smart contracts (v1) on Ethereum; does not explicitly cover later V2 contracts or other chains.[7][8][13]
Findings
Report lists issues across severity levels; public summary does not enumerate exact counts per severity. No explicit statement of unresolved criticals; issues discussed and recommendations given.[7][8]
Fix status
Verification phase completed May 20–21 2021 and updated final report delivered June 4 2021, indicating identified issues were addressed to auditor’s satisfaction.[8]
Evidence (3)

audit

unverified

Pendle Protocol Smart Contracts audit of the then-current protocol implementation. The report states the scope covered the in-scope repository for the review and that the scope was sufficient to cover all security-critical components. It does not, from the gathered snippet alone, let me verify a bytecode match to today’s deployed contracts.

Auditor
Least Authority
Report date
2021-06-14
Scope
Pendle protocol smart contracts / benchmark-finance contracts repository (security-critical components); governance model out of scope.
Evidence (2)

audit

two sources

Additional Pendle V2 and component audits by Dingbats, CMichel, WatchPug, leastwood, Spearbit and others, including specific components like sPendle and oracles.

Auditor
Multi‑auditor & wardens (Dingbats, CMichel, WatchPug, leastwood, Spearbit, etc.)
Report date
2022-11-29
Scope
Various V2 core modules and extensions (including sPendle, SparkLinearDiscountOracle and others) as indicated by individual PDFs in the audits directory; exact chain/component coverage requires per‑report review, not available in snippets.[14][5]
Findings
Public listings and PDFs exist in the Pendle GitHub audits directory, but web snippets do not provide structured severity counts; forum summary notes that V2 contracts were reviewed by these auditors/wardens but without explicit issue breakdown.[14][15]
Fix status
Pendle FAQ asserts the codebase is fully audited and all flaws addressed – this is an unverified marketing claim. Detailed fix status versus findings and coverage of current deployed bytecode across Ethereum, Arbitrum, BSC, Base, Hyperliquid L1, Monad, Plasma is Not verifiable as of 2026-09-04.[2][9][14]
Evidence (4)

audit

unverified

Pendle audit entry exists in the project’s audit history, but the gathered result only confirms the presence of an audit entry and does not provide a full report snippet here. Fix status and bytecode coverage are not verifiable as of 2026-08-29.

Auditor
WatchPug
Report date
2024-10-02
Scope
Not verifiable as of 2026-08-29
Evidence (1)

Team & Reputation

founders

two sources

Pendle is a yield-trading DeFi protocol founded around 2020–2021 by TN Lee with co‑founder Vu Nguyen, supported by a partially doxxed, partially anonymous team primarily based in Asia (Singapore, Hong Kong, Vietnam). ### Founders & prior track record

  • TN Lee (Yong Ming Lau?) – Co‑founder/CEO
  • Founding team member and Head of Business at Kyber Network (major DEX) from ~2017–2019, covering Korea, China, US, Europe.
  • Founded Dana Labs, focused on FPGA/custom semiconductors.
  • Frequently described as relatively low‑profile / semi‑anonymous publicly, but gives interviews under “TN Lee”.
  • Vu Nguyen – Co‑founder/CTO
  • Former CTO at Digix / DigixDAO, an Ethereum RWA project tokenizing gold.
  • Background in computer science from Singapore. These are public, non‑anon identities with long tenure in crypto; no major hacks or enforcement actions associated with Kyber or Digix that are directly attributed to them were found in the sampled data. Not verifiable as of 2026‑09‑04. ### Broader team & anonymity profile
  • Named core contributors include Anton Buenavista (ecosystem growth, ex‑Kyber smart‑contract dev), Long Vuong Hoang (Head of Engineering, NUS CS, ex‑Jump Trading intern), Ken Chia (Head of Institutional, ex‑JPMorgan/Abra), Dan Wongso (growth), Yoko Yu Qiu (growth), ViNc (Chinese ambassador), Cropsharer (community lead).
  • Several reports note mix of doxxed and anonymous members, with some founders/early contributors known only by initials (GT, YK) and Discord handles. ### Location, corporate reality & onshore/offshore
  • Commentary and profiles indicate the team is distributed, with a concentration in Southeast Asia – Singapore, Hong Kong, Vietnam.
  • Pendle’s own site emphasizes “no single headquarters—the protocol is global,” which is an unverified marketing claim.
  • Public corporate registration details (jurisdiction, legal entity, office address) are Not verifiable as of 2026‑09‑04 based on the provided data. ### Credibility & “real business vs web front”
  • Multiple independent sources (research reports, IQ wiki, VC notes, Substack reviews) consistently attribute Pendle to experienced DeFi founders from Kyber and Digix and list named professionals in engineering and institutional coverage—this supports the view of a real operating organization, not a pure anonymous web front.
  • However, the lack of clearly surfaced legal-entity data and mixed anonymity mean institutional counterparties should treat Pendle as a decentralized protocol with partially doxxed leadership, not a fully onshore, trad‑fi style company. Contradictions box:
  • Some sources say “founded by TN Lee in 2020,” others “co‑founded by TN Lee & Vu Nguyen,” and one attributes establishment to “Yong Ming Lau” while still calling TN Lee the founder.
  • One brief history piece calls the founders “anonymous and semi‑anonymous developers led by TN Lee, GT, YK, and Vu Nguyen,” contrasting with other sources that treat TN and Vu as fully public figures.
Evidence (15)

general reputation

one source

Pendle is generally regarded as a legit, technically innovative yield-tokenization protocol with no major fraud, rug pull, or insolvency allegations to date. Not verifiable on-chain as of 2026-09-04. Founders / team / investors

  • Pendle was founded by TN Lee (CEO) and team; they previously worked in DeFi/crypto and are publicly known, which reduces anonymity-related risk.
  • The project has received backing from recognized crypto funds (e.g., Mechanism Capital, CMS, etc.), indicating institutional confidence, though this is still investment risk, not a guarantee of safety. Audits / security track record
  • Pendle core contracts have been audited multiple times by reputable firms (e.g., PeckShield, Dingaling, others depending on version). Exact coverage and dates vary by deployment and upgrade.
  • No widely reported protocol-wide exploit or catastrophic loss has surfaced in major crypto media or incident trackers.
  • There have been minor issues (e.g., UI bugs, oracle and integration concerns typical for DeFi) but nothing that is consistently cited as unresolved critical risk. Sentiment & criticisms
  • Market and social sentiment around Pendle is largely positive, focused on its fixed yield / yield-tokenization innovation, integrations with LSTs/LRTs, and role in restaking ecosystems.
  • Common criticisms:
  • Complexity: yield-tokenization, PT/YT mechanics, and interest rate market structure are hard for retail users to fully understand, raising user error and mispricing risk.
  • Composability risk: heavy reliance on other protocols (LST/LRT issuers, restaking platforms, stablecoin collateral) creates cascading risk if upstream protocols fail.
  • Smart-contract upgrade and governance risk typical of DeFi (admin roles, parameter changes, new markets). Fraud / rug / insolvency / legal / sanctions
  • No credible reports of founder malfeasance, rug pulls, or deliberate user fund misappropriation linked to Pendle in major media, security incident databases, or institutional research.
  • No publicly listed regulatory enforcement actions, criminal cases, or sanctions specifically naming Pendle or its core team in major regulatory databases or sanction trackers.
  • As with most DeFi protocols, Pendle operates in a regulatory-grey zone: users may face evolving treatment under securities/derivatives laws due to interest-rate-like exposure and tokenization of yield. Unresolved concerns (risk analyst view)
  • Structural risk from multi-protocol dependencies and complex yield instruments.
  • Need to continuously track: new deployments on Arbitrum/BSC/Base/Ethereum/Hyperliquid/Monad/Plasma, audit coverage per chain, admin privileges, and any regulatory developments around tokenized yields. Overall, reputation is relatively strong but not risk-free, with main concerns centered on complexity and ecosystem dependency rather than integrity or solvency. Not verifiable on-chain as of 2026-09-04.
Evidence (5)

Economy

model

one source

Economic model. Pendle tokenizes yield-bearing assets into SY, then separates principal (PT) and future yield/points (YT). PT is economically market-neutral to underlying yield after purchase—fixed discount converges to 1 unit at maturity—while YT is directional and economically leveraged to future yield/points. LPs provide PT/SY liquidity and earn underlying yield, swap fees, and incentives.

Assets out are SY, PT, YT, LP tokens, or the underlying through router redemption. Yield and subsidies. Base yield originates from the underlying asset/protocol; PENDLE emissions, partner incentives, and points are subsidized/variable components. Pendle’s displayed underlying APY is a 7-day average, so APY volatility and sustainability depend heavily on the external asset and incentive schedule. Organic-yield share: Not verifiable as of September 6, 2026.

APY history/volatility by market: Not verifiable as of September 6, 2026. Leverage/exposure. Native PT looping is available through money-market borrowing; it adds collateral, liquidation, interest-rate, and external-protocol risk. Restaking or lending exposure is market-specific rather than Pendle-native. Protocol-wide leverage ratio: Not verifiable as of September 6, 2026.

External smart-contract risk is material because Pendle depends on third-party yield protocols. Maturity/withdrawal. Positions are not contractually locked: PT/YT/LP can generally be sold or withdrawn at market prices before expiry, subject to liquidity/slippage. At maturity, PT redeems 1:1 for the accounting underlying; YT loses future value. Matured PT/LP can remain idle, but future yield/points are redirected to the fee wallet if not redeemed. Fees/revenue. Pendle charges YT fees (currently 5% of accrued yield/points) and maturity-scaled swap fees.

Current documented allocation is 20% of swap fees to LPs, with remaining swap fees and YT fees split 80% buyback, 10% treasury, and 10% operations. TVL snapshot (DeFiLlama; not Dune). Total $1.177B; Ethereum $696.98M (59.2%), Monad $174.66M (14.8%), Arbitrum $133.57M (11.3%), Plasma $111.75M (9.5%), Hyperliquid L1 $30.92M (2.6%), BSC $18.27M (1.6%), Base $3.88M (0.3%); these requested chains represent 99.4%. TVL fell 1% over 30 days; product-level TVL and Dune-vs-DeFiLlama reconciliation: Not verifiable as of September 6, 2026. Contradiction/coverage box: the current official deployment page lists HyperEVM but not Hyperliquid L1 or Plasma, while DeFiLlama reports both; chain-level attribution requires reconciliation.

Evidence (6)

reserves

unverified

Assessment — as of September 6, 2026 Liquid reserves: nullNot verifiable as of September 6, 2026. Dune was unavailable in this run, so no on-chain balances, USD valuation, token composition, or per-chain exposure can be verified. This applies separately to Arbitrum, BSC, Base, Ethereum, Hyperliquid L1, Monad, and Plasma. Liabilities: nullNot verifiable as of September 6, 2026. No reliable reserve-liability statement or proof-of-reserves attestation was identified in the reviewed sources. Known reserve/treasury-related addresses: Pendle’s tokenomics documentation excludes five categories from circulating supply: sPENDLE, vePENDLE, the Ecosystem Fund, Governance Multisig, and Team Multisig. The linked Ethereum addresses are:

  • Ecosystem Fund: 0x399be606db281a054e359eb709df9f21e922ec9a
  • Governance Multisig: 0x8119ec16f0573b7dac7c0cb94eb504fb32456ee1
  • Team Multisig: 0x918cf6b16d1426b5aa0edf0492ced1aa89f9659a
  • sPENDLE: 0x999999999991E178D52Cd95AFd4b00d066664144
  • vePENDLE: 0x4f30a9d41b80ecc5b94306ab4364951ae3170210 These are designated token-accounting addresses, not proof of total treasury assets or liquid reserves. Pendle states that its core deployments are organized by chain ID, so the Ethereum address set cannot be assumed to represent custody on every listed chain. Custody/control: The protocol describes itself as self-directed and non-custodial; users transact directly with smart contracts, while the company disclaims being a custodian or intermediary. Governance control is associated with the Governance Multisig, but signer identities, threshold, current permissions, and complete treasury-control mapping were not independently verified here. Reserve policy and attestations: No formal reserve policy, minimum liquidity requirement, segregated custody policy, or recurring third-party reserve attestation was found. Not verifiable as of September 6, 2026. Risk conclusion: Treasury transparency is partial: designated PENDLE holding addresses are disclosed, but aggregate size, composition, cross-chain balances, custody controls, liabilities, and attestations remain unverified.
Evidence (4)

tokenomics

two sources

Pendle has a native token PENDLE; the protocol also issues interest-bearing PT and yield-bearing YT tokens for underlying assets, but these are not governance tokens. Because Dune MCP is unavailable, all on-chain-specific checks are Not verifiable as of 2026-09-04. Native token & contracts (major chains)

  • Ethereum: PENDLE (ERC‑20) commonly referenced at the address starting 0x8087… (verify via Etherscan yourself). This is the canonical deployment used by CEXs and bridges.
  • Arbitrum, Base, BSC, Monad, Plasma, Hyperliquid L1: PENDLE exists mainly as bridged/wrapped representations; exact contract addresses per chain are Not verifiable as of 2026-09-04. Supply, market cap & FDV
  • Total/max supply is widely reported around 258–260M PENDLE.
  • Circulating supply, market cap, and FDV figures differ slightly across aggregators and move with price; concrete values are Not verifiable as of 2026-09-04. Token utility & governance
  • PENDLE is used for liquidity incentives, fee capture, and governance via vePENDLE (vote-escrowed PENDLE locked for up to several years).
  • vePENDLE holders govern pool incentives, parameter changes, and receive a share of protocol fees (swap fees and yield from Pendle AMM). Revenue share, buybacks, burns, staking
  • Protocol fees are partially distributed to vePENDLE lockers, effectively giving them a revenue share.
  • Some sources describe PENDLE buybacks funded from protocol revenue, routed to vePENDLE participants, but specifics and burn mechanics are Not verifiable as of 2026-09-04. Emissions & unlocks
  • PENDLE followed a multi‑year emission schedule with liquidity mining, partner incentives, and vePENDLE boosts; remaining emissions decrease over time.
  • Detailed unlock calendar (team/investors) and whether scheduled unlocks occurred on-chain are Not verifiable as of 2026-09-04. Allocations & concentration
  • Public token distribution charts usually show buckets for team, investors, treasury, and community/liquidity mining.
  • Exact percentages by bucket, insider wallet labels, and top-holder concentration are Not verifiable as of 2026-09-04. Contract controls (mint/blacklist/fee switch)
  • Whether PENDLE has remaining mint authority, any blacklist features, or admin fee switches, and who controls them (multisig/DAO) is Not verifiable as of 2026-09-04. DEX liquidity & listings
  • PENDLE is listed on major CEXs (e.g., Binance) and large DEXs on Ethereum and Arbitrum; liquidity depth and per‑pair TVL are Not verifiable as of 2026-09-04. > Due to lack of Dune/on-chain tooling in this run, all figures should be treated as aggregator-sourced, not on-chain verified.
Evidence (3)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

A BTC break below $10,000 would be a *macro stress* event for Pendle, but the direct impact on Pendle’s core protocol is not documented as a BTC-specific solvency risk in the sources provided. Pendle’s main exposure is through its yield-tokenized markets and any cross-protocol collateral/strategy positions built on those markets, not through native BTC balance-sheet exposure. The clearest stressed pathways are market-structure and contagion effects: if BTC crashes, risk appetite, liquidity, and leverage typically contract, which can weaken PT/YT demand, compress liquidity, and trigger redemptions or liquidations in integrated lending venues.

Pendle-related analyses specifically flag risks such as liquidation cascades, front-run redemptions, liquidity crunches, and cross-protocol contagion in major PT collateral pools. For asset-specific price mechanics, Pendle’s PT/YT design means the PT price plus YT price equals the underlying asset price, so a sharp fall in collateral values can feed through to token pricing and collateral health in downstream markets. Pendle also clarified in a recent liquidation episode that even a brief ~3% PT move was enough to liquidate undercollateralized positions in an external lending market, illustrating how sensitive integrations can be under stress.

What is *not verifiable as of 2026-09-04*: Pendle’s exact chain-by-chain exposure to BTC-linked pools across Arbitrum, BSC, Base, Ethereum, Hyperliquid L1, Monad, and Plasma; the percentage of TVL tied to BTC-sensitive assets; and whether any protocol treasury or contract balances would be directly impaired by BTC below $10,000. Those figures require on-chain verification that is unavailable in this run. The practical risk view is that Pendle itself is more likely to face secondary effects—lower volumes, thinner liquidity, weaker incentives, and greater liquidation risk in partner protocols—than a direct protocol insolvency from BTC/USD moving below $10,000.

Evidence (8)

stress scenario - largest collateral depegs 20%,

unverified

Pendle’s own documentation explicitly warns that if a PT collateral price drops sharply versus the borrow asset—*for example, 20%*—liquidation liquidity may be insufficient, creating potential bad debt. For a stress test, the protocol’s stated intuition is that the loss is not just the mark-to-market depeg itself; it is the combination of the collateral haircut, liquidation capacity, and market depth available to liquidators. The key documented mechanism is that, in a PT depeg, liquidators can only repay and liquidate up to a bounded amount of debt determined by the protocol’s risk parameters, summarized in the docs as a cap based on the PT borrow/liquidation model.

If the depeg is large enough and secondary liquidity is thin, some undercollateralized loans may remain unresolved, which is the path to bad debt. For Pendle across Arbitrum, BSC, Base, Ethereum, Hyperliquid L1, Monad, and Plasma, chain-by-chain exposure under a 20% collateral depeg is Not verifiable as of 2026-09-04 because no on-chain query tool is available in this run, and the provided sources do not contain chain-level borrow/collateral balances or protocol-wide PT collateral concentrations. Any precise estimate of losses, affected loans, or bad-debt size would require live on-chain positions by chain and market, which is unavailable here.

The most defensible conclusion is therefore qualitative: a 20% depeg in the largest PT collateral is a documented stress case that can exceed liquidation capacity and produce bad debt if liquidity is insufficient, but the magnitude of loss by chain cannot be verified from the available sources.

Evidence (2)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

For Pendle, “top counterparty insolvent” usually means a major underlying yield source or collateral protocol fails (e.g., LST/LRT issuer, money market, restaking protocol). On‑chain verification is not possible in this run: Not verifiable as of 2026‑09‑04. ### 1. Where counterparty risk sits Pendle is a tokenized yield AMM: users trade principal (PT) and yield (YT) on top of external yield-bearing assets (LSTs, LRTs, LP tokens, money market claims).

The key counterparty is the issuer / protocol of the underlying asset, not Pendle itself. ### 2. Stress path: underlying protocol default Assume a major underlying (e.g., stETH, a large LRT, or Aave/aLST position) becomes insolvent or frozen. 1. Price breakdown

  • PT and YT for that market rapidly trade toward near‑zero because the underlying token is impaired.
  • Pendle AMM pools for that market become imbalanced; LPs eat the mark‑to‑market loss on their inventory. 2. Who absorbs the loss
  • PT/YT holders: bear full economic loss; Pendle contracts do not guarantee principal or yield.
  • LPs in the affected pools: suffer inventory loss and potential adverse selection as traders arbitrage prices down.
  • No socialized loss across other markets; each market is isolated by asset. 3. Smart‑contract impact path
  • Pendle contracts continue to function; they just reference an underlying token that may be worthless or non‑redeemable.
  • If the yield source stops paying, YT cashflows drop to zero; if redemptions are blocked (e.g., staking protocol halted), PT can’t be redeemed for real value.
  • Any integration using oracles could be at risk of stale/incorrect pricing if the oracle lags the collapse. ### 3. Compensation / backstops
  • Pendle does not advertise protocol‑level insurance or loss backstops for underlying asset failure; risk is borne by market participants.
  • Bug bounties and smart‑contract audits address implementation bugs, not economic insolvency of counterparties. ### 4. Cross‑chain impact For chains where Pendle is deployed (Ethereum, Arbitrum, BSC, Base, etc.), each market on each chain is structurally local:
  • Insolvency of an underlying on one chain impacts that chain’s markets referencing that asset.
  • Systemic effect arises only if the same compromised asset is widely used across chains (e.g., a dominant LST/LRT), propagating similar loss paths on every chain where it backs Pendle markets. No chain‑specific TVL or exposure shares can be verified: Not verifiable as of 2026‑09‑04.
Evidence (4)

stress scenario - committed fraud by the DAO or owners

two sources

For Pendle, I found no verified evidence that the DAO or owners themselves committed fraud. The available material instead points to user phishing/scams and to a third-party exploit involving Penpie, a protocol built on Pendle, where Pendle’s team said funds on Pendle remained secure. Relevant incident evidence is mixed but does not support a committed-fraud finding against Pendle’s DAO/owners.

A post-mortem on X from Pendle stated that normal operations resumed and that funds on Pendle were not at risk. Independent coverage of the Penpie incident describes a reentrancy exploit against Penpie’s staking/reward logic, with attackers creating a fake market; those reports attribute the loss to Penpie’s contract design and market-validation assumptions, not to fraudulent conduct by Pendle’s DAO or owners. There are also phishing reports using the Pendle name, including a “Pendle Permit” scam and a fake PendleSwap site, but these are external scams targeting users, not evidence of fraud by Pendle’s governance or ownership. Assessment: committed fraud by the DAO or owners is Not verifiable as of 2026-09-04.

The strongest supported reading is that Pendle has been associated with external scams and with a downstream exploit in a partner/protocol built on Pendle, but not with verified fraud by its own DAO/owners.

Evidence (10)

stress scenario - primary yield source negative 30d,

one source

Pendle’s documented stress behavior for a negative 30-day primary yield source is that the underlying interest-bearing token (IBT) value can decline, which can make the market’s exchange rate fall below the Watermark Rate. In that case, PT may redeem below its expected 1:1 value at maturity, while YT stops earning yield until the exchange rate recovers to the Watermark Rate. Pendle also states that if the Watermark Rate is artificially elevated by oracle mispricing or a temporary spike, the market can appear to be in negative yield even after the asset’s true value normalizes.

For risk interpretation, this is a direct loss-transfer mechanism in favor of PT over YT: negative yield pressure is absorbed by YT holders first, and PT holders may realize a redemption shortfall if the exchange rate remains depressed through maturity. Pendle’s own guidance also says that if you expect yield to fall, the appropriate action is to hedge yield rather than buy it outright. What is not verifiable as of 2026-09-04 from the provided sources is which of the listed chains—Arbitrum, BSC, Base, Ethereum, Hyperliquid L1, Monad, or Plasma—currently contributes the primary yield source, or whether the negative 30d condition is actually present on-chain for any specific market.

Evidence (2)

Governance & Legal

governance

one source

Assessment date: September 13, 2026. Pendle is not fully token-sovereign. sPENDLE holders vote through Pendle Protocol Proposals (PPPs); voting power is based on an sPENDLE snapshot when a proposal is created, with virtual balances from legacy vePENDLE locks. Documentation says sPENDLE will become the sole governance/revenue token after legacy locks expire.

However, team-controlled administration remains material: the documented PendleGovernanceProxy admin is a 2-of-4 Safe that can pause PT/YT/SY markets and upgrade the governance proxy; a separate guardian EOA can also pause/update supply caps. Aave’s technical review found no timelock and immediate upgrade/pause capability. DAO assessment: real but constrained/partly symbolic.

Token voting appears relevant to emissions, fee-share and PPP decisions, but the evidence does not establish token-holder control over all upgrades, pool deployment, frontend operation, treasury administration, or emergency powers. Thus dao_governance=false. Frontend/company: Pendle’s Terms identify Univerum Innovations Inc., established under Panamanian law, as the operator.

The company may modify or discontinue the website/interface at its discretion, while users can interact directly with contracts. Reg. number and directors: Not verifiable as of September 13, 2026. Multichain caveat: deployment files exist for Ethereum, BSC, Base, Arbitrum, Monad and other chains, but active admin roles, timelock wiring, signer sets and treasury controls were not independently verified for every user-specified chain.

Voting concentration/top holders via Dune: Not verifiable as of September 13, 2026. Multisig signer independence is not established; the four addresses are public in the Aave review, but identities/relationships were not proven independent.

Timelock
No
Multisig threshold
2
Multisig owners
4
Admin can drain
No
Emergency bypass
Yes
Dao governance
No
Evidence (4)

legal & regulatory

two sources

Pendle is operated via a Panamanian corporate entity and offers a permissionless, non‑KYC public protocol plus emerging permissioned, KYC‑based institutional rails; there is currently no evidence of direct regulatory enforcement or sanctions against the protocol itself. Not verifiable as of 2026-09-04. Entity & jurisdiction

  • Blockworks’ token transparency filing states that Pendle’s legal materials identify Univerum Innovations Inc., incorporated under the laws of the Republic of Panama, as the operator of the Website and Pendle Protocol.
  • Pendle’s Terms of Use specify that disputes under the Terms are governed by Singapore law, with arbitration and enforcement in courts having jurisdiction over the parties or their assets. Terms of use, excluded users & jurisdictions
  • The Terms of Use define “Excluded Persons” and “Excluded Jurisdictions”, referencing FATF high‑risk jurisdictions and major sanctions lists (OFAC, EU, UN), and state that such persons must not access or use the Pendle Protocol.
  • The protocol and website are provided on an “as‑is” basis, with broad disclaimers of warranties and limitations of liability for indirect or consequential losses; users access the protocol at their own risk. KYC/AML & user classification
  • Pendle is described in multiple sources as a permissionless yield‑trading protocol, with no built‑in centralized KYC/AML for the public app.
  • A UK crypto-asset statement and independent commentary note that Pendle does not assume responsibility for funds lost due to third‑party smart contract exploits, reinforcing its protocol‑only posture rather than custodial or advisory status.
  • An AML‑focused watchdog article criticizes Pendle for enabling anonymous DeFi yield strategies and layering, pointing to the absence of centralized KYC or UK authorization; this is an external risk assessment, not a formal enforcement action.
  • Pendle is developing a “Pendle Permissioned” layer that is intended to operate with full KYC/AML compliance and act as a gateway for institutional capital, implying a segregated, compliant venue distinct from the public permissionless protocol. Regulatory status, enforcement, and sanctions
  • No credible evidence of direct regulatory enforcement (e.g., actions by FCA, SEC, MAS, or Panamanian authorities) against Pendle or Univerum Innovations Inc. was identified. Not verifiable as of 2026-09-04.
  • No indication that Pendle or its core entity is itself on sanctions lists; restrictions in the Terms rely on external lists (OFAC, EU, UN) to define excluded persons. Not verifiable as of 2026-09-04. Data protection & user risk profile
  • As a non‑custodial, wallet‑connected DeFi app, Pendle primarily interacts with on‑chain addresses; detailed data‑protection practices (e.g., GDPR, PDPA policies) are not clearly documented in the sources reviewed. Not verifiable as of 2026-09-04.
  • Legal materials and risk warnings emphasize smart‑contract and third‑party protocol risks, and clarify that protocol users bear the economic risk of interacting with Pendle and underlying DeFi strategies. Chain‑specific note
  • Pendle operates across Ethereum and multiple L2s (e.g., Arbitrum, Base, BSC), but legal materials and Terms appear to be chain‑agnostic, applying to use of the protocol regardless of chain. Exposure distribution by chain is on‑chain data and Not verifiable as of 2026-09-04.
Entity
Univerum Innovations Inc.
Jurisdiction
Republic of Panama (incorporation); Singapore (governing law for Terms)
Evidence (9)

Stability

stability

two sources

Pendle does not issue its own stablecoin. The available evidence identifies Pendle as a yield-trading/yield-tokenization protocol, and the stablecoins used in its markets are third-party assets such as USDC, USDT, USDe, USDG, AUSD, sUSDS, and sUSDD. A stablecoin depeg relevant to Pendle’s stablecoin markets is not verifiable as of 2026-09-06 from the available sources alone, so depeg_count, last_depeg_date, and max_depeg_pct cannot be confirmed.

Stable is also not verifiable as of 2026-09-06.

Own stablecoin
No
Stablecoin ids
  • USDC
  • USDT
  • USDe
  • USDG
  • AUSD
  • sUSDS
  • sUSDD
Evidence (3)

Risks & Strengths

risks

one source

Pendle’s primary risks arise from permissionless yield-asset integrations, complex smart-contract composition, oracle-dependent leverage, and fragmented multi-chain deployment. Audits and deterministic oracle designs reduce—but do not eliminate—tail risk. Chain-specific TVL, exposure, and concentration are Not verifiable as of September 5, 2026 because on-chain verification was unavailable.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Underlying and SY insolvencyPT redemption depends on the underlying yield asset and SY adapter remaining solvent, redeemable, correctly priced, and operational. A depeg, adapter failure, or issuer event can impair PT, YT, and LP positions.HighMediumAsset/SY review for official listings, documented redemption mechanics, permissionless architecture disclosure, and user risk warnings.High tail risk remains for novel, upgradeable, or weakly collateralized underlying assets.
Smart-contract and integration exploitPendle combines factories, markets, routers, SY adapters, rewards, and external protocols. A core bug or unsafe integration could create broad losses; the 2024 Penpie exploit illustrates downstream integration risk.HighMediumMultiple audits, open-source contracts, Code4rena participation, bug-bounty/security processes, and selective frontend curation.High; audits are point-in-time and cannot cover every adapter or composability path.
Oracle manipulation and liquidationTWAP-based PT pricing depends on observation readiness and liquidity depth; manipulated or stale prices can cause incorrect collateral valuation and liquidations in PT lending strategies.HighMediumRecommended Linear Discount Oracle, immutable oracle parameters, TWAP duration guidance, and market-depth requirements for integrations.Medium to High for thin markets, external price wrappers, and volatile underlying assets.
Liquidity, maturity, and basis riskYT can expire worthless; LP returns depend on implied rates, incentives, fees, and exit liquidity. Thin markets can produce material slippage or losses before maturity.MediumHighMaturity disclosure, pool liquidity/APY displays, AMM curve design, and improved convergence toward par at maturity.Medium; liquidity can disappear during stress and advertised APY is not guaranteed.
Governance and multichain operationsDeployments across multiple chains and integrations increase upgrade, admin-key, RPC, chain-halt, bridge, and operational failure surfaces.HighMediumOpen-source deployments, audited releases, chain-specific contracts, immutable oracle wrappers, and governance-controlled administration where applicable.Medium to High; cross-chain incidents and privileged-key compromise remain difficult to neutralize.
Evidence (5)

strengths

two sources

Pendle’s top strengths are: (1) first-mover innovation in yield tokenization, because it separates yield-bearing assets into Principal Tokens (PT) and Yield Tokens (YT) so users can trade principal and future yield independently; (2) strong fixed-yield and yield-trading utility, enabling strategies like locking in fixed returns, speculating on yield, or hedging rate exposure; (3) a specialized market design, including a maturity-based structure and AMM optimized for yield assets rather than generic spot trading; (4) broad ecosystem fit and integrations, with support across major DeFi narratives such as LSTs/LRTs and integration/cross-chain reach noted by multiple independent sources; and (5) position as a leading, high-adoption yield venue, with several sources describing Pendle as a dominant on-chain yield-trading protocol and a large, growing DeFi platform.

Evidence (15)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 25 two independent sources, 44 one source, 7 unverified.
  • Oldest fact verification date: 2026-08-29.