Compound DeFi Bug Leads to $90M Incorrect COMP Coin Distribution

Around $90 million has been mistakenly sent to users of popular DeFi staking protocol Compound following a bug in a recent upgrade.
The company's founder took to Twitter to plead with users to return the platform's crypto tokens, while also threatening those refusing to do so.
"If you received a large, incorrect amount of COMP from the Compound protocol error: Please return it," Robert Leshner, founder of Compound Labs, tweeted on Thursday. "Keep 10% as a white-hat. Otherwise, it's being reported as income to the IRS, and most of you are doxxed."
Compound is a decentralised finance (DeFi) platform with a liquidity mining program that rewards depositors and borrowers, but usually at a rate of a single-digit for annual percentage yield (APY).
A user known as 'napgener' first noticed an issue with Compound payouts, flagging three Ethereum transactions where users received around $15 million in COMP tokens in exchange for borrowing and supplying small token quantities for the likes of USDC, ETH and DAI.
DeFi protocols like Compound are designed to recreate traditional financial systems, such as banks and exchanges, but with blockchain powered by automated smart contracts. On Wednesday Compound attempted to roll out an upgrade, but it appears to have included an error.
"The new Comptroller contract contains a bug, causing some users to receive far too much COMP," Leshner said. "There are no admin controls or community tools to disable the COMP distribution; any changes to the protocol require a 7-day governance process to make their way into production."
More and more users began reporting over payments after Leshner tweeted about the bug: $29 million worth of COMP has been claimed in one transaction, while another has said they received 70 million COMP tokens (thought to be worth about $28m).
Leshner didn't specify the issue with the update, however a developer from another DeFi crypto exchange, SushiSwap, tweeted that the fault could be blamed on a "one-letter bug" in the code.
Blockchain
- Coinbase vs. Coinbase Pro: Which Exchange is Right for You in 2024?
- Compound (COMP): Decentralized Lending Explained
- NFTs & DeFi: Exploring the Convergence of Digital Collectibles and Decentralized Finance
- Compound (COMP): Earn & Borrow Crypto - A Comprehensive Guide
- Understanding the Blockchain Trilemma: Challenges & Ethereum 2.0
- DeFi Explained: A Beginner's Guide to Decentralized Finance
- Bitcoin Mining vs. HODLing: Which Crypto Strategy Pays Off in 2024?
- DeFi vs. CeFi: Understanding Decentralized & Centralized Finance
- Unclaimed Stimulus Checks: Over $2 Billion Still Available - CARES Act
-
Coinbase Expands Cryptocurrency Listings: What It Means for InvestorsMany or all of the products here are from our partners that pay us a commission. It’s how we make money. But our editorial integrity ensures our experts’ opi...
-
Pet Coins: Understanding the Hype & Risks - Expert AnalysisMany or all of the products here are from our partners that pay us a commission. It’s how we make money. But our editorial integrity ensures our experts’ opi...
