Compound V2 Hack

TOTAL LOST $147M
Critical Arithmetic Overflow & Underflow Attacks Ethereum

What happened

On September 29, 2021, Compound Governance Proposal 62 introduced a bug in Compound V2's COMP reward-distribution logic. Certain users could claim far more COMP than intended, exposing up to roughly $147 million in erroneous reward distribution at contemporary prices. Compound said supplied and borrowed market assets were not at risk.

This was a reward-accounting incident, not an attacker draining lending pools.

Technical Root Cause

An off-by-one reward-index initialization condition used > instead of >= in the Compound V2 Comptroller. Affected uninitialized accounts retained a zero index and over-accrued COMP when they claimed rewards.

Case & protocol details

Classification Token reward accounting failure
Protocol Type Lending
Smart Contract Language Solidity
Official Website compound.finance
Protocol Twitter/X @compoundfinance

Attack Timeline

Proposal 62 split COMP reward speeds for suppliers and borrowers. A one-character boundary error prevented some legacy users' reward indexes from being initialized. Their zero index was then compared against the market's 1e36 initial index, so ordinary claimComp calls calculated a large unearned reward.

Proposal 64 stopped new excess claims, but did not reverse previously distributed COMP.

Security review history

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.