{"investigation":{"slug":"compounder-finance","entity_name":"Compounder Finance","trust_score":2,"severity_base":null,"score_modifier":0,"confidence":0.92,"status":"published","content_type":"investigation","summary":"Compounder Finance was an Ethereum-based DeFi yield aggregator that launched in November 2020 and executed a deliberate rug pull approximately 22 days later, stealing between $10.8 million and $12.5 million from investors. Anonymous developers embedded hidden 'Evil Strategy' smart contracts behind a publicly visible but unmonitored 24-hour timelock, then drained all user funds and deleted the project's website and social media accounts. No funds were recovered and the perpetrators have never been publicly identified.","sections":[{"content":"Compounder Finance presented itself as a meta yield aggregator on Ethereum, marketing its CP3R token as a means for investors to earn compounding returns across multiple DeFi protocols. The project described itself as cloning effective yield strategies from Yearn Finance and Harvest Finance, while adding CP3R token emissions. Its name and ticker were deliberately designed to evoke associations with Compound Finance (COMP) and Keep3r Network (KP3R), two established and reputable DeFi projects with which Compounder had no affiliation. Compound Finance founder Robert Leshner publicly noted the impersonation. The contract was deployed on November 8 or 9, 2020, according to Etherscan records, and the rug pull was executed on or around December 1, 2020 — approximately 22 days after launch.","heading":"Overview","sources":[{"url":"https://www.coindesk.com/tech/2020/12/02/108m-stolen-developers-implicated-in-alleged-smart-contract-rug-pull","name":"coindesk.com","type":"other","credibility":3},{"url":"https://coingeek.com/compounder-dev-team-steals-over-10-million-in-latest-defi-attack/","name":"coingeek.com","type":"other","credibility":3},{"url":"https://etherscan.io/token/0x7ef1081ecc8b5b5b130656a41d4ce4f89dbbcc8c","name":"etherscan.io","type":"other","credibility":3}],"severity":"medium"},{"content":"According to post-incident analysis by CoinDesk, CoinGeek, and Decrypt, the Compounder developer team pre-loaded a malicious withdrawal function into several of the project's smart contracts. The team subsequently swapped the safe, audited Strategy contracts with malicious 'Evil Strategy' contracts that stripped restrictions from the withdraw function. This swap was processed through a 24-hour timelock — a mechanism publicly presented to investors as a safety feature — but the timelock was not independently monitored by the community or auditors after the audit was completed. Once the threshold of approximately $10 million in deposited assets was reached, the developer-controlled address called inCaseStrategyTokenGetStuck() on the StrategyController, which abused the manipulated withdraw() function to transfer funds to the developer team's wallets across seven malicious strategy contracts. The scheme was characterized as an exit scam or rug pull rather than an external exploit: the losses were caused by the project's own developers acting against user interests.","heading":"The Rug Pull Mechanism","sources":[{"url":"https://www.coindesk.com/tech/2020/12/02/108m-stolen-developers-implicated-in-alleged-smart-contract-rug-pull","name":"coindesk.com","type":"other","credibility":3},{"url":"https://decrypt.co/50196/defi-auditor-death-threats-12-million-rug-pull","name":"decrypt.co","type":"other","credibility":3},{"url":"https://cryptoslate.com/this-defi-app-based-on-ethereum-just-stole-12-million-from-its-users/","name":"cryptoslate.com","type":"other","credibility":3},{"url":"https://coingeek.com/compounder-dev-team-steals-over-10-million-in-latest-defi-attack/","name":"coingeek.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Reported figures for the total amount stolen vary across sources, ranging from $10.8 million (CoinDesk, Nasdaq) to $12 million or $12.5 million (Decrypt, Cryptoslate, Quadriga Initiative). The discrepancy likely reflects different token valuations at the time of reporting. CoinDesk's itemized breakdown — based on contemporaneous on-chain data — identifies the stolen assets as approximately $750,000 in Wrapped Bitcoin (39 WBTC), $4.8 million in Ether (8,080 ETH), $5 million in DAI, and smaller amounts of other tokens including COMP, UNI-V2, and CP3R. The exploit address associated with the drain is reported as 0x079667f4f7a0b440ad35ebd780efd216751f0758. Funds were reportedly routed through Tornado.cash to obscure the trail. One investor, DeFiYield.info, claimed losses of approximately $1 million and subsequently organized victim coordination efforts. CP3R, the project's native token, fell from a peak of near $100 to $0.24–$0.27 within 24 hours of the rug pull — a decline of approximately 98.8–99.5%.","heading":"Funds Stolen","sources":[{"url":"https://www.coindesk.com/tech/2020/12/02/108m-stolen-developers-implicated-in-alleged-smart-contract-rug-pull","name":"coindesk.com","type":"other","credibility":3},{"url":"https://decrypt.co/50196/defi-auditor-death-threats-12-million-rug-pull","name":"decrypt.co","type":"other","credibility":3},{"url":"https://www.quadrigainitiative.com/casestudy/compounderfinancerugpull.php","name":"quadrigainitiative.com","type":"other","credibility":3},{"url":"https://coingeek.com/compounder-dev-team-steals-over-10-million-in-latest-defi-attack/","name":"coingeek.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Compounder Finance was audited by Solidity Finance (also referred to as Solidity Labs in some reports). The audit was released on or around November 19, 2020. Solidity Finance's audit report identified that several functions — specifically the treasury contract and the ability to update strategy pools — remained under the centralized control of the Compounder team via a single address. The audit linked the timelock for users to monitor and flagged the centralized control as unusual and creating unnecessary risk. However, the audit firm later acknowledged it 'should have been clearer about the implications' of that centralized control. After going back and forth with the Compounder team, Solidity Finance ultimately characterized the protocol as safe from external attacks, but did not adequately communicate the internal attack vector to investors. No community members monitored the timelock in the weeks following the audit, during which time the malicious Evil Strategy contracts were deployed. Solidity Finance received death threats within 36 hours of the theft becoming public and declined to elaborate further.","heading":"Audit and Pre-Incident Warning Signs","sources":[{"url":"https://decrypt.co/50196/defi-auditor-death-threats-12-million-rug-pull","name":"decrypt.co","type":"other","credibility":3},{"url":"https://www.coindesk.com/tech/2020/12/02/108m-stolen-developers-implicated-in-alleged-smart-contract-rug-pull","name":"coindesk.com","type":"other","credibility":3},{"url":"https://coingeek.com/compounder-dev-team-steals-over-10-million-in-latest-defi-attack/","name":"coingeek.com","type":"other","credibility":3},{"url":"https://www.quadrigainitiative.com/casestudy/compounderfinancerugpull.php","name":"quadrigainitiative.com","type":"other","credibility":3}],"severity":"medium"},{"content":"All members of the Compounder Finance development team remained pseudonymous throughout the project's existence and have not been publicly identified as of the time of reporting. No handles, Discord usernames, or other identifying information were disclosed in primary reporting from CoinDesk, Decrypt, or CoinGeek. Following execution of the rug pull, the team deleted the project website, Twitter account, Medium blog, and Discord server without issuing any statement. The Quadriga Initiative case study notes that the founders may have been a single individual operating under the guise of a team, and that funding was allegedly sourced through Tornado.cash to prevent on-chain attribution. A Telegram group of affected investors was organized to pursue legal action and attempt to identify the perpetrators; no public identification or arrest has been reported.","heading":"Developer Identity and Anonymity","sources":[{"url":"https://www.quadrigainitiative.com/casestudy/compounderfinancerugpull.php","name":"quadrigainitiative.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/tech/2020/12/02/108m-stolen-developers-implicated-in-alleged-smart-contract-rug-pull","name":"coindesk.com","type":"other","credibility":3},{"url":"https://chainbulletin.com/compounder-finance-developers-allegedly-involved-in-10-8-million-rug-pull-scheme","name":"chainbulletin.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Compounder Finance deliberately mimicked the branding and naming of Compound Finance, one of the most established DeFi lending protocols, in order to attract users who might conflate the two projects. The CP3R ticker also evoked KP3R, the ticker of Keep3r Network, a legitimate DeFi project. Robert Leshner, founder of Compound Finance, publicly acknowledged that Compounder Finance had impersonated Compound Finance's name to lure victims. Neither Compound Finance nor Keep3r Network had any affiliation with Compounder Finance.","heading":"Brand Impersonation","sources":[{"url":"https://www.coindesk.com/tech/2020/12/02/108m-stolen-developers-implicated-in-alleged-smart-contract-rug-pull","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cryptoslate.com/this-defi-app-based-on-ethereum-just-stole-12-million-from-its-users/","name":"cryptoslate.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The Compounder Finance rug pull became one of the more prominent early examples of an audited DeFi project conducting a deliberate exit scam, raising industry-wide questions about the limitations of smart contract audits when developer-controlled admin keys or timelocks are not adequately disclosed to users. The incident prompted discussion about whether auditors bear responsibility for communicating the social/trust risks of centralized control — not just code vulnerabilities — to retail investors. Solidity Finance publicly committed to providing more robust disclosures about developer control risks in future audits. No funds have been publicly reported as recovered, no perpetrators have been identified, and no law enforcement action has been reported as of publicly available records through 2025.","heading":"Aftermath and Industry Impact","sources":[{"url":"https://decrypt.co/50196/defi-auditor-death-threats-12-million-rug-pull","name":"decrypt.co","type":"other","credibility":3},{"url":"https://www.coindesk.com/tech/2020/12/02/108m-stolen-developers-implicated-in-alleged-smart-contract-rug-pull","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.quadrigainitiative.com/casestudy/compounderfinancerugpull.php","name":"quadrigainitiative.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2020-11-08","event":"Compounder Finance smart contract deployed on Ethereum (CP3R token contract: 0x7ef1081ecc8b5b5b130656a41d4ce4f89dbbcc8c).","source":""},{"date":"2020-11-19","event":"Solidity Finance releases audit report, flagging centralized developer control over strategy pools via a 24-hour timelock but concluding the protocol is safe from external attacks.","source":""},{"date":"2020-11-19","event":"In the weeks following the audit, developers begin deploying malicious 'Evil Strategy' contracts through the publicly visible but unmonitored timelock.","source":""},{"date":"2020-12","event":"Developers execute the rug pull, calling inCaseStrategyTokenGetStuck() across seven malicious strategy contracts and draining all user funds. Website, Twitter, Medium, and Discord are deleted.","source":"","date_original":"2020-12-01"},{"date":"2020-12-02","event":"CoinDesk reports $10.8 million stolen; Compound Finance founder Robert Leshner publicly condemns the scheme and confirms no affiliation.","source":""},{"date":"2020-12-02","event":"CP3R token collapses approximately 98.8% in 24 hours, trading at $0.24.","source":""},{"date":"2020-12-03","event":"Decrypt reports Solidity Finance received death threats within 36 hours of the rug pull. DeFiYield.info — which claims $1 million in losses — announces a $50,000 bounty for information leading to fund recovery and organizes a Telegram victim group.","source":""},{"date":"2020-12-03","event":"Solidity Finance publicly acknowledges it should have been clearer about the implications of developer-controlled admin keys and commits to more robust future disclosures.","source":""}],"sources_used":[{"url":"https://www.coindesk.com/tech/2020/12/02/108m-stolen-developers-implicated-in-alleged-smart-contract-rug-pull","name":"coindesk.com","type":"other","archive_url":"https://web.archive.org/web/20260915185858/https://www.coindesk.com/tech/2020/12/02/108m-stolen-developers-implicated-in-alleged-smart-contract-rug-pull","credibility":3,"archive_timestamp":"2026-09-15T18:58:58+00:00"},{"url":"https://coingeek.com/compounder-dev-team-steals-over-10-million-in-latest-defi-attack/","name":"coingeek.com","type":"other","archive_url":"http://web.archive.org/web/20251216144954/https://coingeek.com/compounder-dev-team-steals-over-10-million-in-latest-defi-attack/","credibility":3,"archive_timestamp":"2025-12-16T14:49:54+00:00"},{"url":"https://etherscan.io/token/0x7ef1081ecc8b5b5b130656a41d4ce4f89dbbcc8c","name":"etherscan.io","type":"other","archive_url":"http://web.archive.org/web/20260310133015/https://etherscan.io/token/0x7Ef1081Ecc8b5B5B130656a41d4cE4f89dBBCC8c","credibility":3,"archive_timestamp":"2026-03-10T13:30:15+00:00"},{"url":"https://decrypt.co/50196/defi-auditor-death-threats-12-million-rug-pull","name":"decrypt.co","type":"other","archive_url":"http://web.archive.org/web/20260413021746/https://decrypt.co/50196/defi-auditor-death-threats-12-million-rug-pull","credibility":3,"archive_timestamp":"2026-04-13T02:17:46+00:00"},{"url":"https://cryptoslate.com/this-defi-app-based-on-ethereum-just-stole-12-million-from-its-users/","name":"cryptoslate.com","type":"other","archive_url":"https://web.archive.org/web/20260830125520/https://cryptoslate.com/this-defi-app-based-on-ethereum-just-stole-12-million-from-its-users/","credibility":3,"archive_timestamp":"2026-08-30T12:55:20+00:00"},{"url":"https://www.quadrigainitiative.com/casestudy/compounderfinancerugpull.php","name":"quadrigainitiative.com","type":"other","archive_url":"https://web.archive.org/web/20260830164337/https://www.quadrigainitiative.com/casestudy/compounderfinancerugpull.php","credibility":3,"archive_timestamp":"2026-08-30T16:43:37+00:00"},{"url":"https://chainbulletin.com/compounder-finance-developers-allegedly-involved-in-10-8-million-rug-pull-scheme","name":"chainbulletin.com","type":"other","archive_url":"https://web.archive.org/web/20260830083114/https://chainbulletin.com/compounder-finance-developers-allegedly-involved-in-10-8-million-rug-pull-scheme","credibility":3,"archive_timestamp":"2026-08-30T08:31:14+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:59.772273+00:00","updated_at":"2026-09-15T19:04:31.665571+00:00"}}