Leading DeFi Protocol Compound Leaked Over $100 Million in Rewards

The Compound money-market protocol is recovering from a bug that caused it to distribute too much of its governance token COMP to some users, though no deposited funds were at risk.

article-image
share
  • Over $51 million of the erroneously distributed COMP has been returned to the Compound treasury
  • The mishap points to decentralized governance as a double-edged sword

It started as a technocratic tweak to a long-running DeFi blue chip. “Proposal 62” voted on by holders of the Compound protocol’s governance token, COMP, was meant to give governance wider latitude in distributing incentives to lenders and borrowers.

Compound kicked off the 2020 “DeFi summer” with its then-novel use of liquidity mining following the debut of its COMP governance token in June of last year. With it, anyone providing or using liquidity in the money market protocol would earn COMP — lenders and borrows benefitted equally — rewards were split 50/50.

After a year of real-world testing, it became clear there were some unintended and deleterious side effects, particularly in non-stablecoin markets: WBTC (wrapped bitcoin), for example, could be borrowed at effectively a negative interest rate.

To address this problem, Proposal 62, enabled COMP rewards to be set heterogeneously across markets. It passed unanimously and went into effect on September 29.

Then, trouble:

Loading Tweet..

The protocol was paying out too much in COMP rewards to a subset of its users. It needed an immediate patch, first to pause all COMP distribution and then to repair the design flaw in Prop 62.

Compound Labs Inc., a Delaware corporation headquartered in San Francisco, originally developed the protocol, but in a move to decentralize control over its future evolution, they implemented a governance process of reviews, voting, and finally what’s known as a “timelock” on all changes approved by COMP token holders. The mechanism was aimed to prevent malicious code from being quickly rammed through and to move the company out of a primary decision-making role, but in this case, it also meant that any attempt to fix the bug would take at least seven days.

So, is decentralization partly to blame? The founder of Compound, Robert Leshner, doesn’t think so:

“This is not an event that calls into question whether DeFi can be operated safely. It’s a wake-up call for decentralized, community-run protocols to improve the processes by which changes are introduced,” Leshner told Bloomberg.

Leshner was quick to downplay the consequences of the bug on Twitter:

Loading Tweet..

A fix was passed through governance on October 7, and was executed on Saturday, stopping the COMP bleed.

In a typically DeFi twist, Leshner announced that 163,000 COMP tokens that were incorrectly claimed had been returned to the Compound community. That’s about $50 million worth of windfall tokens not taken. A further 130,000 — or roughly $40 million — that could have been expropriated, were left untouched. It’s as though the code to your front door security system was sent to everyone in your address book, along with a picture of the suitcase full of cash just inside, but no one wanted to turn the handle.

For now, there remain 200,000 COMP tokens that were in fact claimed and which have not been returned. That has the effect of diluting all holders of COMP.

Despite the slip-up, the COMP price has remained around $300 per token, without seeing a marked adverse reaction to its price.

Tags

Decoding crypto and the markets. Daily, with Byron Gilliam.

Upcoming Events

Javits Center North | 445 11th Ave

Tues - Thurs, March 24 - 26, 2026

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

Research Report Templates (8).png

Research

Kinetiq has established itself as Hyperliquid's dominant liquid staking protocol, holding 82.5% of LST market share with $610M in TVL. The protocol is now expanding beyond its kHYPE staking core into higher take-rate verticals: iHYPE for institutional custody rails, Launch for HIP-3 capital formation, and Markets for builder-deployed perpetuals. We view Markets, launching Jan. 12, as the highest-potential product line given its mechanically scalable, activity-linked unit economics. Near-term revenue remains anchored by kHYPE's KIP-2 fee schedule (~$1.6M annualized), while Markets provides embedded optionality if HIP-3 economics normalize post-Growth Mode. KNTQ's setup is relatively clean: zero insider unlocks until November 2026, 6.2% buyback yield from staking revenue, and cleared airdrop overhang. Risks center on unproven Markets execution, declining kHYPE TVL despite ongoing incentives, and competition from Hyperliquid's native initiatives.

article-image

BTC finished the week up 1.6%, while L2s, RWAs and the treasury trade continued to grind lower

article-image

DTCC moves DTC-custodied Treasuries onchain via Canton, while Lighter’s LIT launches trading at a fees multiple in Hyperliquid territory

article-image

In the 90s, rapt audiences worldwide watched a coffee pot — will that fascination ever turn to crypto?

article-image

Some systems improve by failing — and crypto has no choice

article-image

Yield Basis introduces an IL-free AMM design that already dominates BTC DEX liquidity

article-image

Maybe tokenholders don’t need the rights that corporate shareholders have come to expect

Newsletter

The Breakdown

Decoding crypto and the markets. Daily, with Byron Gilliam.

Blockworks Research

Unlock crypto's most powerful research platform.

Our research packs a punch and gives you actionable takeaways for each topic.

SubscribeGet in touch

Blockworks Inc.

133 W 19th St., New York, NY 10011

Blockworks Network

NewsPodcastsNewslettersEventsRoundtablesAnalytics