If all three parties say their own mechanism worked as designed, whose responsibility is the $36 million loss?
This is exactly why this event is hard to answer in a single sentence — the traditional way of assigning responsibility is to find which specific piece had a design flaw, but every piece here holds up fine in isolation. Pendle's PT/YT split mechanism was always designed so the two prices move mechanically together — that's the product's basic logic, not a bug. Morpho's Oracle logic of "take the lower of TWAP and a fixed curve" was intended to prevent instantaneous price manipulation, and that design rationale is sound on its own. Steakhouse, as curator, choosing to accept PT-reUSD as collateral was also a reasonable business judgment under the market conditions at the time.
What actually went wrong wasn't any single piece — it was the aggregate fragility that emerged once these three pieces stacked together. Nobody was responsible for verifying whether these three individually reasonable designs, all occurring simultaneously in the same extremely thin-liquidity market, could produce an outcome nobody wanted. That's also why the accountability question doesn't have a simple answer: three independent, individually reasonable decisions stacking together is the actual cause of this loss, not any single party's negligence.
This address "manipulated" the PT price, yet nobody has accused it of violating any rules — why?
Because every action it took — buying YT, participating in the liquidations, redeeming PT — was a normal function both Pendle and Morpho publicly offer to every user, none of which required bypassing any permission restriction or exploiting a code vulnerability. This is fundamentally different from the conventional notion of a "hack": a hack typically means circumventing a boundary the system wasn't meant to let you cross, but this address operated entirely within the rules the system was designed to allow — it just precisely calculated how those rules connected to each other, and then deliberately triggered that connection.
That's also why Re Protocol later said it was investigating "whether the principal Token's market price was intentionally manipulated," but as of now, none of the involved protocols has formally accused this address of any violation — because proving "manipulation" typically requires showing an actor did something the rules didn't allow, and every step this address took fell within what the rules permitted. This incident is therefore often cited as a case study illustrating that, in DeFi, "technically compliant" and "doesn't harm other users" are not the same thing.
Given that someone flagged this risk on the forum eight days earlier, why didn't Steakhouse or Morpho adjust parameters in time to prevent this event?
Publicly available information doesn't explain the specific reason, but the timeline reveals a structural gap: eight days passed between someone pointing out on the forum that borrowing volume had far outstripped underlying liquidity and the actual event occurring — which suggests this warning was more in the nature of "someone observing and raising a concern" than "a protocol actively executing an emergency response procedure," with a governance-and-execution time gap sitting between the two.
The more fundamental issue may be that this warning pointed to a structural risk (borrowing volume far exceeding liquidity) rather than a specific, immediately actionable fix — going from governance discussion to an actual risk parameter adjustment (raising collateral requirements, capping borrowing in a single market, for example) typically requires going through a proposal, discussion, and vote process, and that process's speed was never designed to keep pace with a risk that could be exploited within a matter of days. Steakhouse itself had already publicly acknowledged back in 2025 that market-based oracles are susceptible to manipulation in thin-liquidity environments, suggesting this wasn't a gap in awareness — it was more likely a gap between knowing the risk existed and the actual action of adjusting parameters keeping up with it.
If I'm also looping PT tokens to farm yield, how do I assess whether my position is exposed to a similar risk?
The first thing to check is the type of Oracle this market uses and its time window — like the 15-minute TWAP used in this event, the shorter the window, the more susceptible it is to concentrated trading volume in a short burst. You should also check the actual liquidity depth of this collateral in its corresponding maturity-yield market (the same pool on Pendle, for instance). In this event, the Morpho market's borrowing scale ($52.2 million) far outstripped the underlying Pendle pool's liquidity ($8.97 million) — that kind of severely disproportionate ratio between borrowing scale and underlying liquidity is itself a warning sign worth watching for.
Second, check how much buffer your own position's Health Factor has before it hits the Liquidation threshold — if you're amplifying yield through looping, your effective Leverage is higher than it appears on the surface, and a seemingly mild 2-3% price move can be enough to push you past the liquidation line. Third, you can proactively check the governance forum for the market you're in to see whether someone has already raised similar liquidity concerns — as this event shows, these warnings sometimes surface in advance but don't necessarily get translated into a parameter adjustment in time; spotting that discussion yourself lets you react sooner than waiting for the protocol's full governance process to run its course.
In the early morning of August 25, 2026, a single address spent roughly $320,000 executing 11 consecutive trades on Pendle within nine minutes, ultimately triggering approximately $36.14 million in liquidations on the lending protocol Morpho. What's most unusual about this event isn't the dollar amount — it's that it wasn't an attack in any conventional sense at all. Pendle stated its Oracle was configured correctly and functioned as intended; curator Steakhouse Financial said lenders suffered no losses and no Bad Debt was created; and reUSD's issuer, Re Protocol, confirmed the underlying Stablecoin itself never lost its peg. All three original designs worked exactly as intended, and yet $36 million in leveraged positions still got force-closed within 14 minutes — which is precisely what makes this event worth remembering: sometimes a Liquidation cascade isn't caused by anyone's design being flawed, but by several individually normal-functioning mechanisms stacking together into an outcome nobody had anticipated.
Understanding this event first requires understanding what protocols like Pendle actually do. reUSD is a Yield-Bearing Stablecoin, and Pendle splits it into two separately tradable tokens: the Principal Token (PT), representing the principal redeemable at maturity, and the Yield Token (YT), representing the floating yield generated over that period. Because PT and YT are cut from the same underlying asset, their prices are mechanically linked to each other — buying YT pushes the implied annualized yield up while simultaneously pressing the PT price down. Many users had been looping PT-reUSD as collateral on Morpho — depositing it, borrowing against it, and buying more PT-reUSD with the proceeds — to amplify returns, but this also made their positions unusually sensitive to any movement in the PT price.
Per on-chain tracking from blockchain security firm PeckShield, wallet 0x854e…690d executed 11 consecutive trades between 4:28 and 4:37 AM UTC that morning, converting roughly $320,000 worth of SY-reUSD into more than 9.5 million YT-reUSD tokens with a December 10 maturity date. That burst of activity pushed the implied annualized yield from roughly 11% to over 20% almost instantly, while pulling the corresponding PT-reUSD price down about 2.8% to 3%. The oracle mechanism this Morpho market relies on takes the lower of two values: a 15-minute tiTime-Weighted Average Price (TWAP)or PT-reUSD, and a fixed curve gradually climbing toward $1 as maturity approaches. When the market price got knocked down by this activity, it triggered the "take the lower value" logic, and highly leveraged looped positions whose health factors were already sitting close to the threshold cascaded through 33 liquidation events within a tight 14-minute window between 4:37 and 4:51 AM UTC — the USDC market absorbed about $35.19 million in repayments, the USDT market about $960,000, and liquidators collectively seized roughly 38.6 million principal tokens as collateral.
PeckShield's on-chain analysis further shows that the same address that pushed the price down and triggered the liquidations also participated in the liquidations that followed — combining the newly acquired YT with the PT captured through liquidation to redeem the underlying reUSD with minimal slSlippagefor an estimated realized profit of at least $360,000, with additional unrealized gains on remaining open positions not yet counted. This entire sequence involved zero code vulnerabilities — it used functions both Pendle and Morpho publicly offer for ordinary users. The only difference is that an ordinary user buys or sells YT to hedge or speculate on the yield itself, while this address had precisely calculated how buying YT would mechanically ripple through to the PT price and Morpho's liquidation thresholds.
Worth noting: this risk wasn't entirely without warning. Per subsequent reporting, a user had already flagged on Morpho's governance forum, eight days before the event, that borrowing volume in this market had far outstripped the available liquidity in the underlying Pendle pool — at the time, Pendle's reUSD maturity pool held roughly $8.97 million in liquidity, far below the $67.5 million in collateral and $52.2 million in outstanding borrows sitting in the Morpho market. Steakhouse Financial itself had even acknowledged in a 2025 forum post that market-based oracles, while closer to true prices than fixed pricing, remain susceptible to manipulation in thinly traded pools — that self-aware warning ultimately never translated into a parameter adjustment sufficient to prevent this incident. In the aftermath, risk firm LlamaGuard has proposed a "bounded oracle" redesign aimed at giving similar maturity-based yield-token markets a more robust liquidation benchmark.