Purrlend has reported a security incident involving its deployments on HyperEVM and MegaETH, resulting in a loss of approximately $1.52 million. According to ChainCatcher, attackers compromised the team's 2-of-3 multi-signature wallet, granting malicious EOA accounts permissions such as BRIDGE_ROLE. They exploited these permissions to mint unbacked pUSDm and pUSDC, using them as collateral to borrow assets from the pool. Purrlend has suspended the protocol, revoked the compromised permissions, and is collaborating with security teams, law enforcement, and cross-chain bridge partners to track and recover the funds.