Skip to main content
AVOID.NET

v1 → v2

Scores

trust_score6255
severity_base
score_modifier-10-10

Sections

Protocol Overview and History

unchanged

2021 COMP Token Distribution Bug (~$90 Million at Risk) → 2021 COMP Token Distribution Bug (Tens of Millions of Dollars Overpaid)

unchanged

December 2023 X Account Compromise and $4.4 Million Phishing Theft → December 2023 X Account Compromise and Phishing Losses

unchanged

July 2024 Squarespace DNS Hijack (ZachXBT Alert) → July 2024 Squarespace DNS Hijack of the Compound Website

unchanged

July 2024 Alleged Governance Attack — Humpy / Golden Boys Proposal 289 → July–August 2024 Alleged Governance Attack — Humpy / 'Golden Boys' and Proposal 289

unchanged

On-Chain Contract Addresses → Security Audits and Protocol Safeguards

unchanged

Regulatory Standing

unchanged

Pattern of Front-End and Operational Security Failures

unchanged

Protocol Overview and Background → Current Status and Financial Trajectory (2025–2026)

- Compound Finance is a decentralized, open-source money market protocol running on Ethereum, enabling users to supply and borrow crypto assets with interest rates set algorithmically by supply and demand. The protocol was founded in 2017 by Robert Leshner (CEO) and Geoffrey Hayes (CTO) and launched its money market on Ethereum mainnet on September 27, 2018, initially supporting five assets: ETH, DAI, USDC, BAT, and REP. Compound V2 launched in 2019 with additional asset support. In June 2020, Compound launched the COMP governance token, distributing it to users and launching the 'DeFi Summer' of yield farming. At its peak in late 2021, Compound held more than $12 billion in total value locked (TVL). The protocol is developed by Compound Labs, Inc., a San Francisco-based company that raised $8.2 million in a 2018 seed round and $25 million in a November 2019 Series A, both led by Andreessen Horowitz (a16z), with participation from Bain Capital Ventures, Polychain Capital, and Paradigm. The smart contracts have been audited by OpenZeppelin and Trail of Bits, and formally verified by Certora. Robert Leshner stepped down as CEO of Compound Labs in 2023 to found Superstate, a tokenized treasury product company, after which he filed with U.S. securities regulators to create a short-term government bond fund using Ethereum as a secondary record-keeping tool.+ 

September–October 2021: COMP Token Distribution Bug → (section 10)

- On September 29, 2021, Compound executed Proposal 062, which updated the Comptroller contract (deployed at 0x3d9819210a31b4961b30ef54be2aed79b9c9cd3b) to split COMP distribution between suppliers and borrowers based on governance-set ratios rather than the previous 50/50 model. A critical coding error was introduced: the update used a greater-than operator (>) where a greater-than-or-equal-to operator (>=) was required, at two locations in the contract (approximately line 1217 of Comptroller.sol). This caused a delta of 1e36 between the supplierIndex and compInitialIndex variables in markets with zero prior COMP rewards, triggering massively inflated COMP reward claims for users of those markets (including cSUSHI and cTUSD). Within hours of the upgrade going live, users began claiming disproportionate amounts of COMP. Blockchain security researcher Mudit Gupta identified and publicly disclosed the root cause. Robert Leshner, co-founder of Compound Labs, confirmed the bug and estimated the worst-case impact at approximately 280,000 COMP tokens — valued at approximately $80–90 million at the time (COMP was trading near $322). Because the Compound protocol is governed by a 7-day timelock on contract changes, no administrative override was possible; a governance proposal to deploy a patch had to proceed through the full governance and timelock process. Leshner took to Twitter to urge recipients of excess COMP to voluntarily return funds to the Compound Timelock at 0x6d903f6003cca6255D85CcA4D3B5E5146dC33925, offering to allow recipients to keep 10% as a white-hat reward. He controversially added that those who kept the tokens could face IRS reporting exposure, drawing criticism from the crypto community for what some characterized as a threat. In a second wave on approximately October 3, 2021, an additional ~$22 million in COMP was claimed. One address claimed 37,504 COMP tokens worth $12 million, and another claimed 14,995 COMP tokens worth approximately $4.9 million. Additional claims of 9,499, 1,699, and 2,999 COMP were also recorded. These claims came from contracts generated by the MakerDAO DSProxy factory. A governance patch proposal was submitted on October 2, 2021 and approved on October 9, 2021 after clearing the 7-day timelock. In total, approximately 117,000 COMP tokens were voluntarily returned to the community. The total undistributed COMP remaining in the Comptroller contract was estimated at around 136,000 tokens before the patch was applied, meaning a substantial portion of the ~280,000 tokens at risk was never actually claimed.+ 

December 2023: X (Twitter) Account Compromise and Phishing Attack → (section 11)

- On December 29–30, 2023, Compound Finance's official X (formerly Twitter) account was compromised by an unknown attacker. Beginning at approximately 4:57 PM UTC on December 29, the attacker posted fraudulent content advertising 'free $COMP tokens,' directing followers to a phishing site at compound-labs[.]xyz. The phishing site was identified by blockchain security researchers as a 'Pink Drainer scam website,' a known malicious toolkit used to steal cryptocurrency by tricking users into signing malicious approval transactions. Blockchain investigator ZachXBT traced the losses attributed to the attack at approximately $4.4 million, primarily in Chainlink (LINK) tokens — with over 206,000 LINK tokens ($3.2 million) transferred from a Pink Drainer wallet to a scammer address, and approximately 69,000 LINK tokens ($1 million) moved from at least one victim's wallet into a Pink Drainer address. The stolen funds were subsequently laundered through the eXch exchange. Compound Labs recovered control of the X account approximately four hours after the breach and removed the fraudulent posts. On December 30, 2023, Compound Labs confirmed the compromise. Security monitoring services Scam Sniffer and Officer's Notes issued community warnings during the incident. No specific ETH wallet addresses for the Pink Drainer operator in this incident have been independently verified and published at the time of this investigation.+ 

July 2024: Alleged DAO Governance Attack (Humpy / Golden Boys / Proposal 289) → (section 12)

- In the summer of 2024, Compound Finance's DAO governance was the subject of a series of contested proposals by a group calling themselves the 'Golden Boys,' led by a pseudonymous large token holder known as 'Humpy.' Humpy is the same actor who executed a similar governance takeover on Balancer in 2022, where he accumulated approximately 35% of veBAL voting power to redirect BAL incentives to low-volume pools under his control. Beginning in May 2024, the Golden Boys submitted Proposal 247, requesting that 92,000 COMP tokens (approximately 5% of the Compound treasury) be allocated to a yield-bearing vault called 'goldCOMP Vault,' a product developed by the Golden Boys where COMP stakers would relinquish their governance rights in exchange for yield. The proposal failed. A second attempt (Proposal 279) similarly failed in mid-July 2024. The third attempt, Proposal 289, escalated the request to 499,000 COMP tokens — approximately $24 million at the time — to be sent to a trust setup address at 0xb9259d9f2249eb7fb44140926bfd376b63c4925e. Governance analysis by Michael Lewellen (Compound's security adviser and an OpenZeppelin architect) and others identified a coordinated pattern: five addresses were observed withdrawing a combined 230,333 COMP from the Bybit exchange between April 29 and May 2, 2024, delegating those votes to a proposer address beginning with 0x36cc, which also received approximately 95,000 COMP in delegations — together providing enough voting weight to meet the 400,000 COMP quorum threshold required for a proposal to pass. Proposal 289 ultimately passed on July 28, 2024 with 682,191 votes in favor across 35 addresses versus 633,636 votes against across 22 addresses — a margin of approximately 48,555 votes out of only 57 participating addresses total. Lewellen publicly stated: 'In my personal opinion, the actions of Humpy and the Golden Boys can be considered a governance attack if they persist in their attempts to take funds from the protocol in clear opposition to the will of all other Compound DAO delegates.' He further characterized the proposal as 'a malicious attempt to steal funds from the protocol.' COMP's price declined approximately 6.4–7% in the 24 hours following news of the passage. The 499,000 COMP were not transferred. Humpy and the Golden Boys agreed to withdraw Proposal 289 and cancel the planned transfer in exchange for a settlement: Compound would establish a staking product distributing 30% of the protocol's annual incremental market reserves to staked COMP holders, with governance control retained by the Compound DAO rather than the Golden Boys. The incident exposed structurally low voter participation in Compound governance and the vulnerability of token-weighted DAO voting to coordinated large-holder accumulation.+ 

July 2024: Front-End DNS Hijacking Attack (Squarespace / Inferno Drainer) → (section 13)

- On July 11, 2024, the front-end website of Compound Finance (compound.finance) was compromised as part of a broader coordinated DNS hijacking attack targeting decentralized finance protocols. Blockchain investigator ZachXBT first reported suspicious activity, and Web3 security firm Harpie confirmed that the compound.finance domain was redirecting visitors to a phishing page at compound-finance.app that deployed a wallet drainer. Security firm Blockaid identified the attack vector: the DNS records for compound.finance were modified at the domain registrar level to redirect traffic to a malicious IP address. Celer Network was simultaneously affected, and researchers identified over 120–228 additional DeFi protocol front-end domains at risk. The root cause traced to a structural security failure created by Squarespace's acquisition of Google Domains in 2023. As part of the forced migration of approximately 10 million domains from Google Domains to Squarespace, multi-factor authentication (2FA) that had previously protected these accounts was deactivated, leaving them accessible via password-only authentication and vulnerable to account takeover. The malicious pages deployed a drainer kit associated with the Inferno Drainer group, which as of mid-2024 was alleged to have stolen over $180 million from approximately 189,000 victims since August 2023 using a kit that tricks users into signing malicious transactions. Compound Labs confirmed on July 11, 2024 that 'all smart contract funds are safe' and that the attack was limited to the front-end website. Michael Lewellen advised users not to interact with the Compound Finance website until further notice. The exact financial losses attributable specifically to the Compound Finance front-end compromise have not been publicly confirmed in on-chain forensics reports reviewed for this investigation. Specific Inferno Drainer wallet addresses for this incident have not been independently verified in sources available at the time of writing.+ 

Governance Structure and Systemic Risks → (section 14)

- Compound Finance operates a fully on-chain governance system in which COMP token holders (or delegates they authorize) propose and vote on protocol changes. Any governance proposal must reach a quorum of 400,000 COMP votes. A mandatory 7-day timelock delays execution of all approved proposals. While this timelock was originally designed as a security measure, the 2021 COMP distribution bug demonstrated that it can prevent emergency remediation — the bug could not be patched for seven days while exploitable funds remained in the Comptroller contract. The 2024 governance incident illustrated a different systemic risk: token-weighted governance with low overall participation is susceptible to coordinated accumulation by large token holders. Only 57 addresses participated in the vote on Proposal 289, and the margin of victory was approximately 48,555 COMP. Researchers noted that five coordinated addresses withdrew 230,333 COMP from Bybit exchange to provide the decisive vote margin. The 2024 incident drew comparisons to Humpy's 2022 Balancer governance attack, in which he accumulated approximately 35% of veBAL tokens. Both incidents ended in negotiated settlements rather than protocol-level code changes. The structural concern — that any actor able to accumulate or borrow sufficient COMP can force governance outcomes opposed by the rest of the community — has not been resolved at the protocol level.+ 

Security Audits and Protocol Safeguards → (section 15)

- Compound's smart contracts have been independently audited by multiple reputable security firms. OpenZeppelin has performed several audits of Compound contracts across protocol versions, including an audit of Compound III (codenamed Comet), an audit of Compound's Timelock contract, and an audit of the Polygon Bridge Receiver. Trail of Bits conducted a separate audit of Compound Chain in May 2021. Formal verification has been performed by Certora using Accurate Static Analysis (ASA), integrated into Compound's continuous integration pipeline. Despite these measures, the September 2021 COMP distribution bug — introduced by a seemingly minor operator change (> vs. >=) in a governance-approved upgrade — was not caught by the pre-deployment review process and resulted in significant unintended token distribution. Compound v2 documentation lists all audit reports and security contacts publicly at compound.finance/docs/security.+ 

Regulatory Context → (section 16)

- No direct SEC or CFTC enforcement action against Compound Finance or Compound Labs has been identified in sources reviewed for this investigation. Legal analysis has been published examining whether the COMP governance token could be classified as a security under U.S. law given its distribution mechanism and the expectation of profit among token holders, but no formal regulatory determination has been made. The broader DeFi lending sector remains subject to ongoing regulatory uncertainty in the United States. Robert Leshner's new venture, Superstate, has engaged directly with U.S. securities regulators, filing for a short-term government bond fund that uses Ethereum as a secondary record-keeping tool, suggesting a continued effort to operate within regulatory frameworks rather than in opposition to them.+ 

Timeline events

+ added2019-11(no description)
+ added2020(no description)
+ added2022-09(no description)
+ added2023-11(no description)
+ added2025-12(no description)
+ added2026-08(no description)
- removed2017(no description)
- removed2018-09(no description)
- removed2018-09-27(no description)
- removed2019-05(no description)
- removed2019-11-15(no description)
- removed2020-03(no description)
- removed2020-06(no description)
- removed2021-09-29(no description)
- removed2021-09-30(no description)
- removed2021-10-02(no description)
- removed2021-10-03(no description)
- removed2021-10-09(no description)
- removed2021-11(no description)
- removed2023-12-30(no description)
- removed2024-04-29(no description)
- removed2024-05-06(no description)
- removed2024-07-19(no description)
- removed2024-07-28(no description)
- removed2024-07-29(no description)
- removed2024-07-30(no description)
~ changed2018: “” → “
~ changed2021-09: “” → “
~ changed2021-10: “” → “
~ changed2023-12-29: “” → “
~ changed2023-12: “” → “
~ changed2024-07: “” → “
~ changed2024-07-11: “” → “

Accepted submissions

No changes to accepted submissions.

Each version is bound to the decision event that created it. Verify the chain anchor for either via the audit log.

v1 hash: f246e884df8d986eaeb553ff4b8b808ef1f3aa3f8a006c5509fb249c6ab09fbf
v2 hash: dad0b8fa003719a2057ad75e173a5ffa1506c35b95d303420fe9fac856696187