What is Pendle (PENDLE)?
Pendle is a decentralised finance (DeFi) protocol that tokenises and creates a market for future yield, allowing users to trade interest-rate exposure on yield-bearing crypto assets. It was founded by TN Lee — previously Head of Business Development at Kyber Network — together with a small core team, originally under the working name "Benchmark" around 2020, with the PENDLE token and first mainnet version launching in 2021 and the current Pendle V2 launching in 2022. (Source: CoinGecko | OAK Research)
The protocol solves a gap that traditional finance fills with bonds and interest-rate derivatives but that DeFi historically lacked: it wraps any yield-bearing asset (for example stETH, USDe, or aUSDC) into a Standardised Yield (SY) token, then splits it into a Principal Token (PT), which redeems at par at a fixed maturity, and a Yield Token (YT), which captures all yield until maturity — effectively building an on-chain zero-coupon bond and rate-trading market, settled through a purpose-built automated market maker (AMM) and governed by the PENDLE token. (Source: LayerZero)
Risk Associated to the Digital Asset
Pendle (PENDLE) carries a risk profile typical of a mid-cap DeFi governance/utility token layered on top of complex financial smart contracts. Participants should weigh the following:
Market Volatility Risk: PENDLE is a volatile crypto asset. It reached an all-time high of approximately $7.50 in April 2024 and an all-time low near $0.034 in November 2022, and as at June 2026 traded roughly 80% below its peak. Price is highly correlated with broader crypto-market sentiment and with the rise and fall of DeFi yield "narratives" (e.g. the 2024 restaking/points cycle). (Source: CoinGecko)
Regulatory & Adoption Risk: As a DeFi governance token tied to yield derivatives, PENDLE faces an evolving and uncertain regulatory landscape, and its value depends heavily on continued protocol adoption and the persistence of attractive on-chain yields. A contraction in DeFi yields or adverse regulatory treatment of yield-derivative products could materially reduce demand. (Source: Coin Bureau)
Cybersecurity & Custody Risk: PENDLE is an ERC-20 token interacting with — and incentivising — a large body of smart-contract code and a wide ecosystem of integrated protocols. While Pendle's own core contracts have not been exploited, the broader "Pendlecosystem" has suffered a material third-party exploit (see Operational Description below), illustrating contagion risk. (Source: The Block) Self-custody of PENDLE also carries the usual private-key and phishing risks.
Concentration & Liquidity Risk: PENDLE is a mid-cap asset with moderate daily turnover; large orders can move the market, and liquidity is concentrated on a handful of major exchanges. A significant share of supply is held in protocol/staking contracts and exchange wallets (see Section 5), and governance influence has historically been concentrated among a few "Pendle Wars" actors. (Source: CoinGecko | OAK Research)
Smart-Contract & Protocol-Complexity Risk: Pendle's PT/YT/SY mechanics, time-decaying AMM, oracles, and cross-chain deployment are sophisticated. Bugs, oracle mispricing, or failures in an integrated yield source could impair token markets even without a direct exploit of PENDLE itself. (Source: MixBytes)
Emission/Dilution & Governance-Transition Risk: PENDLE has no fixed hard cap; it follows a declining emission schedule that transitions to a terminal ~2% annual inflation, creating ongoing dilution. The token's core staking model is also mid-transition from the legacy vePENDLE system to a new sPENDLE model, which introduces design and adoption uncertainty. (Source: Pendle Documentation | Coin Bureau)
Users should ensure they fully understand the nature, mechanics, and risks of this asset — including its yield-derivative design and smart-contract dependencies — before trading, and should only commit capital they can afford to lose.
Trading History of Digital Asset
Market Capitalisation & Liquidity: Pendle is a mid-cap DeFi token. Across June 2026, reported market capitalisation sat broadly in the ~$225 million–$325 million range (circulating supply ~165–171 million PENDLE), with a CoinGecko rank in the ~#120–#155 band. (Source: CoinMarketCap | CoinGecko) Reported 24-hour spot volume in the same period typically ranged from roughly $24 million to $72 million, with the most active venues including Binance, Kraken, OKX, Coinbase and MEXC. (Source: Coinbase)
Protocol Scale & Institutional Integration: Pendle is the dominant yield-tokenisation protocol, controlling an estimated 50–60% of that DeFi sub-sector, and grew to multiple billions of dollars in total value locked across Ethereum and other chains through the 2024–2025 cycle. (Source: EarnPark | LayerZero) Pendle Principal Tokens have been integrated as collateral within major lending venues such as Aave and Morpho, and Pendle has launched "Boros," a platform extending its model into funding-rate / perpetual-rate derivatives. (Source: OAK Research)
Historical Data Source: For full historical price and volume series, refer to the live PENDLE market pages on CoinGecko and CoinMarketCap. (Source: CoinMarketCap | CoinGecko)
Incidents of Manipulation or Security Failures
PENDLE is an application-layer ERC-20 token; it does not run its own Layer-1 blockchain or consensus mechanism. Its security therefore derives from (a) the Ethereum network on which it primarily settles, (b) the audited, open-source Pendle smart contracts, and (c) the protocol's operational monitoring and pause controls. Native cross-chain expansion of the token is handled via LayerZero's Omnichain Fungible Token (OFT) standard. (Source: LayerZero)
To date, Pendle's own core protocol contracts have not suffered a critical exploit, and the codebase is fully open source. The most material documented incident in the ecosystem was the September 2024 exploit of Penpie, an independent third-party yield optimiser built on top of Pendle. An attacker used a malicious ("evil") market contract and a reentrancy flaw in Penpie's reward-distribution logic to drain approximately $27.3 million; the root cause was attributed to Penpie's own code, not Pendle's. (Source: The Block | Three Sigma) Pendle's in-house monitoring detected the suspicious Tornado-Cash-funded contract, and the team paused all Pendle contracts roughly twenty minutes after the exploit, an action Pendle stated protected around $105 million in user funds from further drainage before normal operations resumed. (Source: CoinMarketCap Academy | CryptoNews) PENDLE's price fell roughly 9–11% in the 24 hours around the incident. (Source: The Defiant)
On price-manipulation surveillance, the Penpie episode demonstrated functioning controls: the protocol's logging captured the attacker's frontend activity and the incident was escalated to law-enforcement and security partners (including Seal 911, PeckShield and Chainalysis-linked responders). (Source: Three Sigma) The protocol's ability to pause contracts is itself a centralisation trade-off: it provides a safety backstop but means a privileged operator can halt activity.
Token Ownership Concentration
Supply: PENDLE has a total supply of approximately 281.5 million tokens and, as at mid-2026, a circulating supply of roughly 165–171 million (around 59–61% of total). (Source: Tokenomist | CoinGecko) Unlike fixed-cap assets, PENDLE has no hard maximum supply; emissions decline by ~1.1% per week and were scheduled to transition around April 2026 to a terminal inflation rate of ~2% per annum dedicated to incentives. (Source: Pendle Documentation)
Vesting / Lock-ups: Pendle's tokenomics page states that, as of September 2024, all team and investor tokens had fully vested, and that any subsequent increase in circulating supply comes from incentives and ecosystem building rather than insider unlocks. The earliest investor allocation traces to an April 2021 seed round that raised approximately $3.7 million for ~14.9% of supply at a then-$35 million fully diluted valuation. (Source: Coin Bureau | Binance Research)
Holder Distribution & Concentration: A large portion of supply is held in protocol-controlled and staking contracts rather than by individual beneficial owners. Historically, a meaningful share of PENDLE was locked as vote-escrowed vePENDLE (with average locks well over a year), and reported "circulating supply" excludes PENDLE held in the staking, vote-escrow and ecosystem/team contracts. Governance influence has been concentrated among "Pendle Wars" actors — Penpie and Equilibria together historically controlled around half of delegated vePENDLE. Many of the largest on-chain addresses are therefore contracts (staking/incentive contracts) or exchange omnibus wallets rather than single owners. (Source: OAK Research | Coin Bureau)
Security Audit
PENDLE is an application-layer token rather than a sovereign Layer-1, its security model rests on smart-contract auditing and open-source peer review rather than a proprietary consensus mechanism: it settles on Ethereum and expands cross-chain through LayerZero's OFT standard, so the relevant audit surface is its contract code, not network consensus.
Third-party smart-contract audits. Pendle V2 was audited by multiple independent firms and competitive-audit wardens, with reports published openly in Pendle's GitHub repository. Ackee Blockchain conducted a security review of Pendle V2 over roughly four engineering weeks between 25 April and 20 May 2022, reporting no critical, high or low severity issues. Dedaub audited the Pendle V2 yield-tokenisation-and-trading contracts (a ~5,000-line codebase) over three weeks, identifying no Critical, High or Medium issues and describing the codebase as professional-grade. Additional reviews were performed by Dingbats and by leading Code4rena wardens (including cmichel, WatchPug and leastwood), and the earlier Pendle V1 contracts were reviewed by Least Authority. Pendle also operates a bug-bounty programme and keeps its contracts open source.
Security-posture developments. The September 2024 Penpie incident (detailed above) was a third-party-protocol exploit, not a breach of Pendle's audited core contracts; Pendle's monitoring-and-pause response is the most notable real-world test of its operational security to date.
Hata custody controls. For client assets held on Hata, Hata maintains its standard institutional custody and compliance framework: SOC 2 Type II certified custody, multi-signature (Multi-Sig) withdrawal authorisation, segregation of client assets, audited operational governance, continuous blockchain-analytics monitoring, and FATF Travel Rule compliance aligned with major regimes (EU/MiCA, Singapore, Japan and the UAE). These controls govern how Hata safeguards PENDLE held with the exchange and are independent of the asset's own protocol-level security.
Sources
The information provided here is presented "as is" and is intended for general informational and educational purposes only. It does not come with any representation or warranty of any kind. This content should not be interpreted as financial, legal, or other professional advice, and it is not intended to endorse or recommend the purchase of any specific product or service. It is advisable to consult with appropriate professional advisors for personalized guidance. In cases where the article is contributed by a third-party author, please note that the expressed views belong to the author alone and may not necessarily reflect the opinions of Hata. For further details, we encourage you to read our complete disclaimer. Please be aware that the prices of digital assets can be highly volatile. The value of your investment may increase or decrease, and there is a risk that you may not recover the full amount invested. You are solely responsible for making your own investment decisions, and Hata cannot be held liable for any losses you may incur. This material is not to be construed as financial, legal, or other professional advice. For more information, please refer to Hata’s Term of Use and Risk Warning.