Compound V2 Hack
What happened
On September 29, 2021, Compound Governance Proposal 62 introduced a bug in Compound V2's COMP reward-distribution logic. Certain users could claim far more COMP than intended, exposing up to roughly $147 million in erroneous reward distribution at contemporary prices. Compound said supplied and borrowed market assets were not at risk.
This was a reward-accounting incident, not an attacker draining lending pools.
An off-by-one reward-index initialization condition used > instead of >= in the Compound V2 Comptroller. Affected uninitialized accounts retained a zero index and over-accrued COMP when they claimed rewards.
Case & protocol details
Attack Timeline
Proposal 62 split COMP reward speeds for suppliers and borrowers. A one-character boundary error prevented some legacy users' reward indexes from being initialized. Their zero index was then compared against the market's 1e36 initial index, so ordinary claimComp calls calculated a large unearned reward.
Proposal 64 stopped new excess claims, but did not reverse previously distributed COMP.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Post-mortem rekt.news
- transaction Transaction etherscan.io
- analysis Compound Digest: COMP Bug Fix compound.substack.com
- analysis Compound: Analysis of Proposal 64 comp.xyz
- analysis Compound Proposal 65: Correct Over-Accrued COMP comp.xyz
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.