{"investigation":{"slug":"compound-v2","entity_name":"Compound V2","trust_score":28,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Compound V2 is a legacy Ethereum-based decentralized lending protocol launched in May 2019 and formally deprecated in December 2025 in favor of Compound V3 (Comet). The protocol has experienced a series of material incidents including a ~$80M COMP token distribution bug in October 2021, a $89M oracle-driven liquidation cascade in November 2020, a confirmed website hijack flagged by ZachXBT in July 2024, a social media phishing hack in 2023 that resulted in $4.4M in losses, and an alleged governance attack in July 2024 in which a whale coordinated the passage of a $24M treasury transfer. V2 is now in wind-down mode with new borrows and mints paused.","sections":[{"content":"Compound V2 was deployed to Ethereum mainnet in May 2019 by Compound Labs, founded by Robert Leshner and Geoffrey Hayes. The protocol enabled algorithmic money markets where users could supply or borrow assets using cTokens as interest-bearing deposit receipts. Governance over protocol parameters was delegated to COMP token holders beginning in May 2020. Compound V3 (Comet) launched in August 2022 as its successor, featuring an isolated collateral architecture that addressed structural risks present in V2's shared pool model. A formal deprecation strategy for V2 was proposed by risk firm Gauntlet and executed through governance in late 2025. On December 7, 2025, a governance proposal to pause all new borrows and mints on V2 and set reserve factors to 100% passed with 99.99% of votes in favor. Users with outstanding positions may still repay and withdraw, but V2 is no longer receiving active protocol development support. At its peak, Compound held billions in TVL; by 2025 the protocol's share of the DeFi lending market had declined significantly relative to competitors such as Aave.","heading":"Protocol Overview and Deprecation Status","sources":[{"url":"https://cryptonews.com/cryptocurrency/compound-finance/","name":"cryptonews.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/compound-v2","name":"defillama.com","type":"other","credibility":3},{"url":"https://messari.io/governor/proposal/987c6225-ce39-4413-9019-0ec0f1d113bc","name":"messari.io","type":"other","credibility":3},{"url":"https://www.comp.xyz/t/gauntlet-compound-v2-deprecation-strategy/4596","name":"comp.xyz","type":"other","credibility":3},{"url":"https://thedefiant.io/news/defi/what-happened-to-compound-defi-lender","name":"thedefiant.io","type":"other","credibility":3}],"severity":"medium"},{"content":"On September 28, 2021, Compound executed Proposal 062, which was intended to split COMP liquidity mining rewards between suppliers and borrowers based on governance-set ratios rather than the previous 50/50 model. A coding error in two locations of the Comptroller contract — where '>' was used instead of '>=' — caused the contract to erroneously distribute large quantities of COMP tokens to users who were not entitled to them. The bug was discovered within hours and Compound Labs confirmed unusual activity. Up to 280,000 COMP tokens, worth approximately $80 million at prevailing prices, were at risk of being claimed incorrectly; estimates of tokens already distributed to incorrect recipients reached approximately 168,000 COMP (~$50 million). Because the protocol has no administrative override controls on COMP distribution, any fix required a full 7-day governance process, during which additional tokens could be claimed. Founder Robert Leshner publicly called it 'the worst day in the history of the Compound protocol.' A second related incident occurred on October 3, 2021, when approximately $22 million more flowed from the still-vulnerable contract before a remediation proposal could take effect. Only two users voluntarily returned a combined 37,493 COMP (~$12 million). In a widely criticized response, Leshner posted on social media threatening to report recipients who did not return funds to the IRS, implying they were 'doxxed.' He later retracted the statement, calling it 'bone-headed.' The episode demonstrated both the risks of immutable smart contract logic in V2 and the absence of emergency shutdown mechanisms.","heading":"October 2021 COMP Token Distribution Bug (~$80M)","sources":[{"url":"https://www.coindesk.com/tech/2021/10/01/compound-founder-says-80m-bug-presents-moral-dilemma-for-defi-users","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.theblock.co/linked/119086/compound-bug-comp-risk-misreward","name":"theblock.co","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2021/10/03/66m-in-tokens-added-to-recently-hacked-still-vulnerable-compound-contract","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cryptoslate.com/how-the-tiniest-of-errors-resulted-in-an-80-million-loss-for-compound-finance/","name":"cryptoslate.com","type":"other","credibility":3},{"url":"https://fortune.com/crypto/2021/10/01/crypto-compound-defi-doxxed-irs/","name":"fortune.com","type":"other","credibility":3},{"url":"https://decrypt.co/82387/defi-community-blasts-compound-ceo-for-doxxed-comment","name":"decrypt.co","type":"other","credibility":3},{"url":"https://www.cnbc.com/2021/10/01/defi-protocol-compound-mistakenly-gives-away-millions-to-users.html","name":"cnbc.com","type":"other","credibility":3}],"severity":"medium"},{"content":"In November 2020, approximately $89 million in user collateral was liquidated on Compound following what analysts described as a price oracle exploit affecting the DAI stablecoin. Compound's Open Price Feed oracle drew price data primarily from Coinbase Pro, with Uniswap as a secondary sanity check. A manipulation of the DAI price on Coinbase Pro caused the oracle to report DAI trading at approximately $1.30 — a 30% premium above its $1.00 peg. When the protocol accepted this inflated price as valid, it recalculated collateralization ratios across borrower accounts and determined many positions to be undercollateralized, triggering automatic liquidations. The protocol's third-largest COMP farmer was liquidated for approximately $46–$49 million in a single event. The incident exposed the systemic risk of V2's reliance on a limited set of price sources and the potential for a single-venue manipulation to cascade across the protocol's entire shared liquidity pool. Compound did not compensate affected users and no external attacker was definitively identified; the incident is classified as an oracle vulnerability exploitation rather than a direct smart contract hack.","heading":"November 2020 Oracle Manipulation and Mass Liquidations (~$89M)","sources":[{"url":"https://decrypt.co/49657/oracle-exploit-sees-100-million-liquidated-on-compound","name":"decrypt.co","type":"other","credibility":3},{"url":"https://news.bitcoin.com/100-million-liquidated-on-defi-protocol-compound-following-oracle-exploit/","name":"news.bitcoin.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/compound-user-liquidated-49-million-price-oracle-blamed/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/compound-liquidator-makes-4m-as-oracles-post-inflated-dai-price","name":"cointelegraph.com","type":"other","credibility":3}],"severity":"medium"},{"content":"In July 2024, Compound DAO was the target of an alleged governance attack orchestrated by a group calling itself the Golden Boys, led by a whale known as Humpy. The group sought to redirect $24 million in COMP tokens from the protocol treasury to a yield-bearing protocol they controlled called goldCOMP. Three separate governance proposals were submitted over several months. Proposals 118 (May 2024) and 247 (early July 2024) failed due to community opposition and insufficient quorum. For Proposal 289, five wallets coordinated to withdraw approximately 230,333 COMP from the Bybit exchange and delegate voting power to the Golden Boys' delegate. Combined with existing holdings, the group controlled over 81% of the 400,000 COMP quorum threshold. Proposal 289 passed on July 28, 2024 with 682,191 votes in favor to 633,636 against. COMP's price fell 6.7% upon news of the passage. Major stakeholders including Gauntlet, Wintermute, and Consensys publicly labeled it a governance attack. After approximately 48 hours of negotiation, Humpy agreed to rescind the proposal in exchange for a counter-proposal to build a Compound DAO-controlled staking product. The incident exposed fundamental structural vulnerabilities in the COMP governance system: low average participation rates enabled a coordinated whale to acquire a blocking and then a controlling position through a centralized exchange. Humpy had previously been accused of analogous governance attacks on the Balancer and SushiSwap protocols.","heading":"July 2024 Governance Attack — Golden Boys / Humpy ($24M COMP Treasury)","sources":[{"url":"https://www.coindesk.com/markets/2024/07/29/comp-down-67-after-supposed-governance-attack-on-compound-dao","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.theblock.co/post/307943/24-million-compound-finance-proposal-passed-by-whale-over-dao-objections","name":"theblock.co","type":"other","credibility":3},{"url":"https://unchainedcrypto.com/humpy-accused-of-governance-attack-on-compound-finance-dao/","name":"unchainedcrypto.com","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/?id=compound-dao-governance-attack","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://thedefiant.io/news/defi/compound-governance-attack-reveals-inherent-vulnerabilities-of-daos","name":"thedefiant.io","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/compound-finance-proposals-elicit-governance-attack-allegations-dao","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://unchainedcrypto.com/compound-governance-attackers-agree-to-cancel-proposal-in-exchange-for-staking-product/","name":"unchainedcrypto.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On July 11, 2024, blockchain investigator ZachXBT published a warning via his Telegram channel that the Compound Finance website (compound.finance) had been hijacked and was redirecting visitors to a newly registered phishing domain, compound-finance[.]app. The phishing site was designed to mimic the legitimate interface and solicit wallet connections in order to drain user funds. Compound Labs confirmed the breach the same day via the protocol's official X account, stating: 'The Compound Labs website (compound[.]finance) has been compromised. Please do not visit the website or click any links until further notice.' Security consultant Michael Lewellen clarified that the smart contract protocol itself was not compromised and that on-chain user funds were unaffected. This incident occurred less than a month after the Golden Boys governance attack, compounding reputational risk for the protocol during a period of elevated scrutiny.","heading":"July 2024 Website Hijack — ZachXBT Warning (Phishing)","sources":[{"url":"https://cointelegraph.com/news/compound-finance-website-hijacked-security-warning","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://cryptonews.com/news/compound-finance-website-appears-hijacked-zachxbt-warns/","name":"cryptonews.com","type":"other","credibility":3},{"url":"https://cryptoslate.com/compound-finance-confirms-website-hack-redirecting-users-to-phishing-site/","name":"cryptoslate.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/compound-finance-phishing-hack-alert/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://www.cryptonewsz.com/compound-finance-confirms-zachxbts-hack-warning/","name":"cryptonewsz.com","type":"other","credibility":3}],"severity":"medium"},{"content":"In 2023, Compound Finance's official X (formerly Twitter) account was compromised by attackers who used it to promote a phishing website impersonating the Compound interface. The fraudulent post offered 'free $COMP tokens' and directed users to a site built using Pink Drainer software, a phishing kit designed to drain connected wallets. Cybersecurity researcher Officer's Notes identified the scam post within approximately 17 minutes of its publication. ZachXBT traced funds stolen via the phishing site and reported that approximately $4.4 million worth of Chainlink (LINK) tokens were taken from victims. Compound Labs recovered control of the account within four hours. The incident marked the first of two successive infrastructure security failures; the second followed in July 2024 with the website domain hijack.","heading":"2023 X (Twitter) Account Hack — $4.4M in LINK Stolen","sources":[{"url":"https://cointelegraph.com/news/compound-finance-x-twitter-account-hacked-posted-scam-link","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://cryptodaily.co.uk/2024/07/security-breach-compound-finance-website-compromised-in-phishing-scam","name":"cryptodaily.co.uk","type":"other","credibility":3}],"severity":"medium"},{"content":"Compound V2's shared pool architecture, in which all supported assets draw from common liquidity, creates systemic contagion risk that is absent in V3's isolated market design. A vulnerability or sharp price movement affecting one asset can cascade to all markets. Security researchers have identified that Compound V2's exchange rate mechanism between cTokens and underlying assets becomes exploitable when a pool is empty or near-empty, due to Solidity integer arithmetic rounding — attackers can artificially inflate the cToken exchange rate by manipulating totalCash without increasing totalSupply, generating inflated collateral values. While Compound V2 itself was not directly exploited via this vector, multiple forks built on V2's code suffered significant losses. On April 30, 2022, Rari Capital lost approximately $80 million when an attacker exploited a missing reentrancy guard in borrowed V2 code. On May 16, 2024, Sonne Finance lost approximately $20 million to the same class of vulnerability. These incidents demonstrate that the core V2 codebase carries known, documented risks that operators of the canonical protocol must also consider. Compound V2 has been audited by Trail of Bits and OpenZeppelin and formally verified by Certora.","heading":"Smart Contract Architecture Risks — Shared Pool Model and Fork Exploits","sources":[{"url":"https://hacken.io/discover/defi-security-lessons-compound/","name":"hacken.io","type":"other","credibility":3},{"url":"https://docs.compound.finance/v2/security/","name":"docs.compound.finance","type":"other","credibility":3},{"url":"https://hindenrank.com/protocol/compound-v2","name":"hindenrank.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Compound V2 governance operates through on-chain COMP token voting. Proposals require a quorum of approximately 400,000 COMP and a minimum 7-day voting period before execution, with an additional timelock delay. These parameters were designed to prevent rushed changes but proved insufficient against coordinated whale accumulation. The Golden Boys episode demonstrated that a single actor with exchange access can acquire enough tokens to control a vote, particularly given historically low voter participation among COMP holders. The absence of emergency pause functionality specific to governance — separate from individual market supply/borrow pauses — means that once a malicious or contested proposal clears timelock, remediation requires executing another governance cycle. Compound implemented no meaningful anti-plutocracy safeguards such as conviction voting, delegation minimums, or time-weighted voting power. The protocol has no regulatory registration or oversight, operating as a fully decentralized autonomous organization.","heading":"Governance Structure Weaknesses","sources":[{"url":"https://thedefiant.io/news/defi/compound-governance-attack-reveals-inherent-vulnerabilities-of-daos","name":"thedefiant.io","type":"other","credibility":3},{"url":"https://research.despread.io/compound-finance-governance-attack/","name":"research.despread.io","type":"other","credibility":3},{"url":"https://unchainedcrypto.com/humpy-accused-of-governance-attack-on-compound-finance-dao/","name":"unchainedcrypto.com","type":"other","credibility":3}],"severity":"medium"},{"content":"As of December 2025, Compound V2 entered formal wind-down with new borrows and mints paused. Users with existing positions may still repay debt and withdraw collateral. Risk analysis firm Hindenrank assigned Compound V2 a C+ grade at the time of active operations. The protocol's TVL declined sharply from its peak as users migrated to V3 or competitor platforms; by late 2025 V2 retained approximately $139–$153M in deposits from users who had not yet migrated. For users currently holding assets in Compound V2, the primary residual risks are: (1) smart contract bugs in a codebase no longer receiving active patches; (2) oracle failures affecting collateral valuations and triggering unwanted liquidations; (3) governance actions on remaining treasury funds; and (4) continued infrastructure targeting by phishing actors who exploit the Compound brand. The protocol has no administrator capable of returning mistakenly distributed funds and no insurance fund covering user losses from bugs.","heading":"Current Risk Assessment — Legacy Protocol in Wind-Down","sources":[{"url":"https://hindenrank.com/protocol/compound-v2","name":"hindenrank.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/compound-v2","name":"defillama.com","type":"other","credibility":3},{"url":"https://messari.io/governor/proposal/987c6225-ce39-4413-9019-0ec0f1d113bc","name":"messari.io","type":"other","credibility":3},{"url":"https://thedefiant.io/news/defi/what-happened-to-compound-defi-lender","name":"thedefiant.io","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2019-05","event":"Compound V2 deployed to Ethereum mainnet, introducing cTokens and algorithmically derived interest rates.","source":"","date_original":"2019-05-01"},{"date":"2020-05","event":"COMP governance token launched; protocol governance transferred to token holders.","source":"","date_original":"2020-05-01"},{"date":"2020-11-26","event":"Oracle manipulation causes DAI price to report at $1.30 on Compound's Open Price Feed; approximately $89M in user collateral liquidated, including a single account for ~$46-49M.","source":""},{"date":"2021-09-28","event":"Compound executes Proposal 062 containing a '>' vs '>=' coding error in the Comptroller contract.","source":""},{"date":"2021-09-29","event":"Bug discovered; up to 280,000 COMP (~$80M) identified as at risk of incorrect distribution. No admin controls available to halt distributions; governance fix requires 7-day process.","source":""},{"date":"2021-10","event":"Founder Robert Leshner tweets threatening IRS reporting against recipients who do not return funds; community backlash prompts retraction. Leshner calls the bug 'the worst day in the history of the Compound protocol.'","source":"","date_original":"2021-10-01"},{"date":"2021-10-03","event":"Second incident: approximately $22M more drained from the still-vulnerable contract before the governance remediation takes effect. Only two users return a combined ~37,493 COMP ($12M).","source":""},{"date":"2022-08","event":"Compound V3 (Comet) launches with isolated market architecture, offering improved risk isolation compared to V2's shared pool model.","source":"","date_original":"2022-08-01"},{"date":"2022-04-30","event":"Rari Capital, a Compound V2 fork, loses ~$80M to a reentrancy exploit in borrowed V2 code.","source":""},{"date":"2023","event":"Compound Finance X (Twitter) account hacked; attackers promote a Pink Drainer phishing site. ZachXBT traces approximately $4.4M in LINK stolen from victims.","source":"","date_original":"2023-01-01"},{"date":"2024-05","event":"Golden Boys submit Proposal 118 seeking 5% COMP treasury transfer; proposal fails after community raises concerns.","source":"","date_original":"2024-05-01"},{"date":"2024-07","event":"Golden Boys submit Proposal 247 via goldCOMP vault mechanism; fails to reach quorum.","source":"","date_original":"2024-07-01"},{"date":"2024-07-11","event":"ZachXBT warns via Telegram that compound.finance has been hijacked and is redirecting to a phishing site. Compound Labs confirms the breach; protocol smart contracts unaffected.","source":""},{"date":"2024-07-28","event":"Proposal 289 passes with 682,191 votes in favor after Golden Boys coordinate withdrawal of ~230,333 COMP from Bybit to meet quorum. COMP price falls 6.7%. Gauntlet, Wintermute, and Consensys characterize it as a governance attack.","source":""},{"date":"2024-07-30","event":"Humpy agrees to rescind Proposal 289 in exchange for development of a Compound DAO-controlled staking product (goldCOMP replacement). COMP price recovers.","source":""},{"date":"2024-05-16","event":"Sonne Finance, a Compound V2 fork, loses ~$20M to the known empty-pool exchange rate manipulation vulnerability.","source":""},{"date":"2025-12-07","event":"Governance proposal to pause all new borrows and mints on Compound V2 and set reserve factors to 100% passes with 99.99% of votes in favor, formally beginning V2 wind-down.","source":""}],"sources_used":[{"url":"https://cryptonews.com/cryptocurrency/compound-finance/","name":"cryptonews.com","type":"other","archive_url":"http://web.archive.org/web/20251005183929/https://cryptonews.com/cryptocurrency/compound-finance/","credibility":3,"archive_timestamp":"2025-10-05T18:39:29+00:00"},{"url":"https://defillama.com/protocol/compound-v2","name":"defillama.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://messari.io/governor/proposal/987c6225-ce39-4413-9019-0ec0f1d113bc","name":"messari.io","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.comp.xyz/t/gauntlet-compound-v2-deprecation-strategy/4596","name":"comp.xyz","type":"other","archive_url":"https://web.archive.org/web/20260830092919/https://www.comp.xyz/t/gauntlet-compound-v2-deprecation-strategy/4596","credibility":3,"archive_timestamp":"2026-08-30T09:29:19+00:00"},{"url":"https://thedefiant.io/news/defi/what-happened-to-compound-defi-lender","name":"thedefiant.io","type":"other","archive_url":"http://web.archive.org/web/20260527145554/https://thedefiant.io/news/defi/what-happened-to-compound-defi-lender","credibility":3,"archive_timestamp":"2026-05-27T14:55:54+00:00"},{"url":"https://www.coindesk.com/tech/2021/10/01/compound-founder-says-80m-bug-presents-moral-dilemma-for-defi-users","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20260802025150/https://www.coindesk.com/tech/2021/10/01/compound-founder-says-80m-bug-presents-moral-dilemma-for-defi-users","credibility":3,"archive_timestamp":"2026-08-02T02:51:50+00:00"},{"url":"https://www.theblock.co/linked/119086/compound-bug-comp-risk-misreward","name":"theblock.co","type":"other","archive_url":"http://web.archive.org/web/20260719162230/https://www.theblock.co/linked/119086/compound-bug-comp-risk-misreward","credibility":3,"archive_timestamp":"2026-07-19T16:22:30+00:00"},{"url":"https://www.coindesk.com/business/2021/10/03/66m-in-tokens-added-to-recently-hacked-still-vulnerable-compound-contract","name":"coindesk.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://cryptoslate.com/how-the-tiniest-of-errors-resulted-in-an-80-million-loss-for-compound-finance/","name":"cryptoslate.com","type":"other","archive_url":"http://web.archive.org/web/20260208085629/https://cryptoslate.com/how-the-tiniest-of-errors-resulted-in-an-80-million-loss-for-compound-finance/","credibility":3,"archive_timestamp":"2026-02-08T08:56:29+00:00"},{"url":"https://fortune.com/crypto/2021/10/01/crypto-compound-defi-doxxed-irs/","name":"fortune.com","type":"other","archive_url":"https://web.archive.org/web/20260830163432/https://fortune.com/crypto/2021/10/01/crypto-compound-defi-doxxed-irs/","credibility":3,"archive_timestamp":"2026-08-30T16:34:32+00:00"},{"url":"https://decrypt.co/82387/defi-community-blasts-compound-ceo-for-doxxed-comment","name":"decrypt.co","type":"other","archive_url":"http://web.archive.org/web/20260414094344/https://decrypt.co/82387/defi-community-blasts-compound-ceo-for-doxxed-comment","credibility":3,"archive_timestamp":"2026-04-14T09:43:44+00:00"},{"url":"https://www.cnbc.com/2021/10/01/defi-protocol-compound-mistakenly-gives-away-millions-to-users.html","name":"cnbc.com","type":"other","archive_url":"http://web.archive.org/web/20260826110314/https://www.cnbc.com/2021/10/01/defi-protocol-compound-mistakenly-gives-away-millions-to-users.html","credibility":3,"archive_timestamp":"2026-08-26T11:03:14+00:00"},{"url":"https://decrypt.co/49657/oracle-exploit-sees-100-million-liquidated-on-compound","name":"decrypt.co","type":"other","archive_url":"http://web.archive.org/web/20260420001629/https://decrypt.co/49657/oracle-exploit-sees-100-million-liquidated-on-compound","credibility":3,"archive_timestamp":"2026-04-20T00:16:29+00:00"},{"url":"https://news.bitcoin.com/100-million-liquidated-on-defi-protocol-compound-following-oracle-exploit/","name":"news.bitcoin.com","type":"other","archive_url":"http://web.archive.org/web/20260417152137/https://news.bitcoin.com/100-million-liquidated-on-defi-protocol-compound-following-oracle-exploit/","credibility":3,"archive_timestamp":"2026-04-17T15:21:37+00:00"},{"url":"https://cryptobriefing.com/compound-user-liquidated-49-million-price-oracle-blamed/","name":"cryptobriefing.com","type":"other","archive_url":"http://web.archive.org/web/20260312074633/https://cryptobriefing.com/compound-user-liquidated-49-million-price-oracle-blamed/","credibility":3,"archive_timestamp":"2026-03-12T07:46:33+00:00"},{"url":"https://cointelegraph.com/news/compound-liquidator-makes-4m-as-oracles-post-inflated-dai-price","name":"cointelegraph.com","type":"other","archive_url":"https://web.archive.org/web/20260830083724/https://cointelegraph.com/news/compound-liquidator-makes-4m-as-oracles-post-inflated-dai-price","credibility":3,"archive_timestamp":"2026-08-30T08:37:24+00:00"},{"url":"https://www.coindesk.com/markets/2024/07/29/comp-down-67-after-supposed-governance-attack-on-compound-dao","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20251121154553/https://www.coindesk.com/markets/2024/07/29/comp-down-67-after-supposed-governance-attack-on-compound-dao","credibility":3,"archive_timestamp":"2025-11-21T15:45:53+00:00"},{"url":"https://www.theblock.co/post/307943/24-million-compound-finance-proposal-passed-by-whale-over-dao-objections","name":"theblock.co","type":"other","archive_url":"http://web.archive.org/web/20260309031107/https://www.theblock.co/post/307943/24-million-compound-finance-proposal-passed-by-whale-over-dao-objections","credibility":3,"archive_timestamp":"2026-03-09T03:11:07+00:00"},{"url":"https://unchainedcrypto.com/humpy-accused-of-governance-attack-on-compound-finance-dao/","name":"unchainedcrypto.com","type":"other","archive_url":"https://web.archive.org/web/20260830091826/https://unchainedcrypto.com/humpy-accused-of-governance-attack-on-compound-finance-dao/","credibility":3,"archive_timestamp":"2026-08-30T09:18:26+00:00"},{"url":"https://www.web3isgoinggreat.com/?id=compound-dao-governance-attack","name":"web3isgoinggreat.com","type":"other","archive_url":"http://web.archive.org/web/20260414211833/https://www.web3isgoinggreat.com/?id=compound-dao-governance-attack","credibility":3,"archive_timestamp":"2026-04-14T21:18:33+00:00"},{"url":"https://thedefiant.io/news/defi/compound-governance-attack-reveals-inherent-vulnerabilities-of-daos","name":"thedefiant.io","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cointelegraph.com/news/compound-finance-proposals-elicit-governance-attack-allegations-dao","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260206230307/https://cointelegraph.com/news/compound-finance-proposals-elicit-governance-attack-allegations-dao","credibility":3,"archive_timestamp":"2026-02-06T23:03:07+00:00"},{"url":"https://unchainedcrypto.com/compound-governance-attackers-agree-to-cancel-proposal-in-exchange-for-staking-product/","name":"unchainedcrypto.com","type":"other","archive_url":"http://web.archive.org/web/20260829195706/https://unchainedcrypto.com/compound-governance-attackers-agree-to-cancel-proposal-in-exchange-for-staking-product/","credibility":3,"archive_timestamp":"2026-08-29T19:57:06+00:00"},{"url":"https://cointelegraph.com/news/compound-finance-website-hijacked-security-warning","name":"cointelegraph.com","type":"other","archive_url":"https://web.archive.org/web/20260829191721/https://cointelegraph.com/news/compound-finance-website-hijacked-security-warning","credibility":3,"archive_timestamp":"2026-08-29T19:17:21+00:00"},{"url":"https://cryptonews.com/news/compound-finance-website-appears-hijacked-zachxbt-warns/","name":"cryptonews.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cryptoslate.com/compound-finance-confirms-website-hack-redirecting-users-to-phishing-site/","name":"cryptoslate.com","type":"other","archive_url":"http://web.archive.org/web/20260526034640/https://cryptoslate.com/compound-finance-confirms-website-hack-redirecting-users-to-phishing-site/","credibility":3,"archive_timestamp":"2026-05-26T03:46:40+00:00"},{"url":"https://cryptobriefing.com/compound-finance-phishing-hack-alert/","name":"cryptobriefing.com","type":"other","archive_url":"http://web.archive.org/web/20260526034045/https://cryptobriefing.com/compound-finance-phishing-hack-alert/","credibility":3,"archive_timestamp":"2026-05-26T03:40:45+00:00"},{"url":"https://www.cryptonewsz.com/compound-finance-confirms-zachxbts-hack-warning/","name":"cryptonewsz.com","type":"other","archive_url":"https://web.archive.org/web/20260901100518/https://www.cryptonewsz.com/","credibility":3,"archive_timestamp":"2026-09-01T10:05:18+00:00"},{"url":"https://cointelegraph.com/news/compound-finance-x-twitter-account-hacked-posted-scam-link","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260415202657/https://cointelegraph.com/news/compound-finance-x-twitter-account-hacked-posted-scam-link","credibility":3,"archive_timestamp":"2026-04-15T20:26:57+00:00"},{"url":"https://cryptodaily.co.uk/2024/07/security-breach-compound-finance-website-compromised-in-phishing-scam","name":"cryptodaily.co.uk","type":"other","archive_url":"https://web.archive.org/web/20260829192011/https://cryptodaily.co.uk/2024/07/security-breach-compound-finance-website-compromised-in-phishing-scam","credibility":3,"archive_timestamp":"2026-08-29T19:20:11+00:00"},{"url":"https://hacken.io/discover/defi-security-lessons-compound/","name":"hacken.io","type":"other","archive_url":"http://web.archive.org/web/20260516231515/https://hacken.io/discover/defi-security-lessons-compound/","credibility":3,"archive_timestamp":"2026-05-16T23:15:15+00:00"},{"url":"https://docs.compound.finance/v2/security/","name":"docs.compound.finance","type":"other","archive_url":"http://web.archive.org/web/20260724175240/https://docs.compound.finance/v2/security/","credibility":3,"archive_timestamp":"2026-07-24T17:52:40+00:00"},{"url":"https://hindenrank.com/protocol/compound-v2","name":"hindenrank.com","type":"other","archive_url":"https://web.archive.org/web/20260829193456/https://hindenrank.com/protocol/compound-v2","credibility":3,"archive_timestamp":"2026-08-29T19:34:56+00:00"},{"url":"https://research.despread.io/compound-finance-governance-attack/","name":"research.despread.io","type":"other","archive_url":"http://web.archive.org/web/20260703023409/https://research.despread.io/compound-finance-governance-attack/","credibility":3,"archive_timestamp":"2026-07-03T02:34:09+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":true,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:53.998461+00:00","updated_at":"2026-09-01T10:06:41.603143+00:00"}}