Compounder Finance Hack

TOTAL LOST $12.5M
High Drained Contracts ethereum

What happened

Contract deployer exploited StrategyController smart contract, transferring funds to his wallet and hiding traces using Tornado Cash mixer.

The contract deployer exploited the StrategyController smart contract by invoking the inCaseTokensGetStuck() function. This allowed him to transfer funds directly into his wallet. The exploit was carried out in several transactions.

After acquiring the funds, the attacker used the Tornado Cash mixer to hide the traces of the stolen funds. This method of obscuring the origin of funds makes it difficult to track the attacker.

Malicious Transactions:

https://etherscan.io/tx/0x57c61df9…3fc7fe

https://etherscan.io/tx/0x10d245e6…113d77

https://etherscan.io/tx/0x0763afe2…901822

https://etherscan.io/tx/0xf94de5a0…f033e6

https://etherscan.io/tx/0x18e0efca…0cacfa

https://etherscan.io/tx/0x744c51b4…d852e5

https://etherscan.io/tx/0x9c75f706…809056

Tornado Cash Mixer Transaction:

https://bloxy.info/txs/calls_from/0x079667f4…1f0758?signature_id=11062&smart_contract_address_bin=0xa160cdab…53f291

Case & protocol details

Classification Rugpull / Borrowing and Lending
Protocol Type Exit Scam/Rugpull
Affected asset / contract CP3R
Smart Contract Language Solidity
Official Website compounder.finance/
Protocol Twitter/X @gocompounder

Evidence & learning

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.