Compound COMP Distribution Bug hack — September 2021
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | September 30, 2021 |
| Target type | Lending protocol |
| Loss | $80,000,000Published estimates range $80,000,000 to $90,000,000Price at time of incident |
| Method | Contract logic errorReward accounting error in upgraded Comptroller let users over-claim COMP |
| Chains | Ethereum |
| Outcome | Partially recovered |
What happened
On 29 September 2021 Compound's governance executed Proposal 062, an upgrade to the Comptroller contract meant to let governance set separate COMP reward rates for suppliers and borrowers instead of a fixed 50/50 split. The upgraded contract contained an error in the reward accounting that let users in a handful of markets — cTUSD, cMKR, cSUSHI, cYFI, cAAVE and cSAI — accrue and claim far more COMP than they were owed. Compound Labs said publicly that no supplied or borrowed funds were at risk; what left the protocol was COMP held for liquidity mining rewards.
Because the distribution could not be paused without a seven-day governance vote, claims continued for over a week. CoinDesk reported that roughly 280,000 COMP, about $80 million at the time, had been distributed in error by 1 October; The Block put the amount actually claimed at that point at about 168,000 COMP, roughly $50 million, against a maximum exposure of 280,000 COMP; Fortune put the figure above $90 million. On 3 October someone called the public drip() function for the first time in about two months, moving a backlog of 202,472.5 COMP — valued by Decrypt at roughly $68 million — into the vulnerable contract; Decrypt reported four users then claimed 64,997 COMP, about $21.4 million, and put total potential exposure at roughly 490,000 COMP, about $160 million, most of which was never claimed.
Leshner asked recipients to return the tokens, offering a 10% white-hat share, and in one post said the amounts would be reported to the IRS and that most recipients were doxxed; about two hours later he called that a bone-headed tweet and approach. Compound's own newsletter recorded the final position without attaching a dollar value: 163,000 COMP incorrectly claimed and returned to the community Timelock, 130,000 COMP left unclaimed in the Comptroller, and roughly 200,000 misallocated COMP outstanding. Proposal 063 (to disable COMP rewards outright) was cancelled on 6 October after community objections; Proposal 064 patched the bug on 8 October and Proposal 065 added a function to correct bad accruals.
Sources
- Compound LabsPrimary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
- DecryptSecondary · retrieved 2026-08-01
- FortuneSecondary · retrieved 2026-08-01
Official post-mortem: https://compound.substack.com/p/compound-treasury-updates-comp-bug
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Compound COMP Distribution Bug hack — September 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/compound-comp-distribution-bughttps://itokenly.com/hacks/compound-comp-distribution-bugPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.