Compound erroneously paid out millions in liquidity mining rewards following an update to one of its smart contracts. In one transaction, $27 million was claimed.
In a possible exploit on Wednesday night, decentralized money market Compound has been erroneously paying out millions of dollars in COMP tokens intended as liquidity mining rewards.
Twitter user “napgener” first flagged the issue, pointing to three Ethereum transactions showing users receiving a total of $15 million in COMP tokens in exchange for borrowing and supplying tiny quantities of tokens, including USDC, ETH and DAI.
Some funky business happening on $COMP
— napgener 0xbullmarket.eth (@napgener) September 29, 2021
possible rug in the @compoundfinance comptroller. ⚠️@rleshner https://t.co/IRTJIQnBEx
Compound has a liquidity mining program that rewards depositors and borrowers, but often at a rate of a single-digit APY. The botched payout sums indicate a flaw in the comptroller contract, which disburses the COMP liquidity mining rewards, possibly related to a recent upgrade.
Observers have noted that Compound’s comptroller contract is not managed by a multi-sig controlled by Compound Labs, and any fix to the exploit may require a governance vote among COMP holders.
Per DeFi Llama, Compound is the world’s fifth-largest decentralized finance protocol with a total value locked (TVL) of $10.2 billion.
Compound acknowledged the exploit on its official Twitter handle and said no user funds are at risk:
Some funky business happening on $COMP
— napgener 0xbullmarket.eth (@napgener) September 29, 2021
possible rug in the @compoundfinance comptroller. ⚠️@rleshner https://t.co/IRTJIQnBEx
Likewise, Compound founder Robert Leshner acknowledged the exploit in a tweet, saying that “at worst” only 280,000 COMP tokens are at risk of being erroneously claimed.
He also noted that “there are no admin controls or community tools to disable the COMP distribution; any changes to the protocol require a 7-day governance process to make their way into production. Labs, and members of the community, are evaluating potential steps to patch the COMP distribution.”
Some funky business happening on $COMP
— napgener 0xbullmarket.eth (@napgener) September 29, 2021
possible rug in the @compoundfinance comptroller. ⚠️@rleshner https://t.co/IRTJIQnBEx
Shortly after Leshner’s tweet, at 1:38 UTC on Thursday, some 91,000 COMP tokens worth $27 million were claimed in a single transaction. The user appears to have supplied $0 in crypto assets to the platform; they paid $154.77 in gas fees to take in their dubious haul.
The same wallet then swapped $140,000 in COMP for USDC via Uniswap.
The price of COMP has plunged on the news, falling from a 24-hour high of $334 to as low as $290. At the time of this story’s latest update, it sits at $290, according to CoinGecko.
A request for comment sent to Compound Labs was not returned by press time.
UPDATE (Sept. 30, 1:23 UTC): Adds comments from Compound founder Robert Leshner.
UPDATE (Sept. 30, 2:02 UTC): Adds detail on subsequent transactions.
UPDATE (Sept. 30, 2:08 UTC): Changes headline.
UPDATE (Sept. 30, 2:11 UTC): Updates current price of COMP.
All writers’ opinions are their own and do not constitute financial advice in any way whatsoever. Nothing published by CoinDesk constitutes an investment recommendation, nor should any data or Content published by CoinDesk be relied upon for any investment activities. CoinDesk strongly recommends that you perform your own independent research and/or speak with a qualified investment professional before making any financial decisions.
Recommended Content
Editors’ Picks

Ripple risks extending losses despite Ripple-SEC motion to release escrowed $125 million
XRP comes under immense pressure, falling toward $2.09 as Israel and Iran escalate conflict. Ripple and the SEC file a joint motion requesting the release of $125 million held in escrow.

Crypto Today: Bitcoin, Ethereum, XRP clamber for support amid escalating volatility on Israel-Iran tensions
The cryptocurrency market has been hit by a sudden wave of extreme volatility, triggering widespread declines as global markets react to tensions between Israel and Iran.

Sui Price Forecast: Sui eyes triangle fallout below $3 as Open Interest, TVL plunge
Sui (SUI) edges lower by over 5% at press time on Friday, concurrent with the broader crypto market crash due to the escalation of the conflict between Israel and Iran.

Bitcoin eyes a drop toward $100,000 amid cautious sentiment as Middle East tensions escalate
Bitcoin price edges below $105,000 on Friday after falling 4% over the last two days. Market sentiment sours as conflict in the Middle East escalates, with over $1.15 billion in liquidation across crypto markets.

Bitcoin: BTC could slump to $100K amid Trump-Musk tussle
Bitcoin (BTC) tumbled to a low of $101,095 on Friday amid volatility in the market. The effect of the tussle between United States (US) President Donald Trump and Tesla Chief Elon Musk negatively influenced the NASDAQ and Tesla's stock price on Thursday, although both are recovering on Friday.