Familiar Compound Exploit Costs Onyx Protocol $2.1 Million
Onyx Protocol, a fork of Compound Finance, lost $2.1 million on Tuesday to an exploit technique that had already made the rounds elsewhere in the ecosystem this year.
The same underlying attack had previously struck two other Compound forks, Hundred Finance and Midas Capital — both of which had already appeared more than once on rekt's leaderboard — pushing the cumulative damage attributable to this specific bug past $10 million for the year.

PeckShield flagged the issue to Onyx in advance, urging the team to "take a look," but roughly three hours passed with no official response before a team member finally acknowledged the loss. PeckShield and BlockSec both tracked the exploit as it unfolded. During that gap, Telegram moderators were telling users to "please don't fud," even as the protocol absorbed a second attack — this one netting the attacker a comparatively modest ~$62,000.
This kind of repeat exploitation of a single known bug has been a recurring theme across the year: read-only reentrancy alone has separately claimed Conic, Sturdy, EraLend, and Midas as victims.
The mechanism
The root cause traces back to a previously documented flaw in Compound v2's codebase, where a rounding error lets an attacker manipulate markets with little to no liquidity, draining funds from the rest of the protocol in the process.
For Onyx specifically, governance had recently passed Proposal 22, which added a lending market for the memecoin PEPE. That new, thin market became the entry point.
The attack works by taking out a flash loan, converting it into the target asset (PEPE, in this case), minting a small number of corresponding shares — oPEPE — and then donating a large PEPE balance directly to the pool. That donation artificially inflates the price of oPEPE, since its valuation is derived from pool holdings rather than mint volume. With oPEPE now overvalued, the attacker borrows other assets against it as collateral, draining the protocol's broader liquidity. The rounding error is then used to reclaim the donated PEPE, and the original flash loan is repaid — all within a single transaction.
Addresses and transactions:
- Exploiter address: 0x085bdff2c522e8637d4154039db8746bb8642bff
- Attack transaction: 0xf7c21600…
- Repeat exploiter address: 0x5083956303a145f70ba9f3d80c5e6cb5ac842706
- Repeat attack transaction: 0x27a3788d…
The 1,164 ETH (~$2.1M) in proceeds moved first to an intermediary address, from which 1,140 ETH was subsequently deposited into Tornado Cash. The remaining 24 ETH went out to assorted on-chain beggars, which in turn triggered a wave of input-data messages sent to the exploiter's address, each one asking for a cut of the loot.
Aftermath and accountability
Onyx Protocol had previously been audited by Certik, underscoring that this particular vulnerability's danger depends more on the specific conditions of an individual market than on any flaw baked into the audited codebase itself.

Empty or near-empty markets in Compound v2-based code are a known risk, meaning any new market listing deserves particular caution from a project's team. The forum discussion following the second Hundred Finance incident pointed to guidance from Hexagate on rolling out markets carrying "low total supply and a non-zero collateral factor": specifically, forks are advised to mint a batch of cTokens and burn them immediately upon launching any new market so that total supply never actually hits zero — and, when listing a new collateral asset, to set its collateral factor to zero first, mint and burn the cTokens, and only then raise the collateral factor to its intended level.
Compound's own governance proposals get scrutinized by plenty of outside eyes, though that hasn't stopped the occasional misstep from slipping through in the past. Onyx's Proposal 22, by contrast, drew votes from just 11 wallets, with more than 97% of the voting weight coming from a single address — suggesting its governance process may not carry the same level of community oversight over new lending markets.
Teams running Compound forks need to actively track the broader security landscape if they want to avoid falling to vulnerabilities that have already been exploited elsewhere; attackers, evidently, are staying current on exactly that landscape.
Onyx has since put forward a compensation proposal that would refund affected users by selling native XCN tokens out of the treasury, while pausing DAO contributor salaries indefinitely. Well-intentioned as it may look on the surface, that approach risks setting off a downward spiral in XCN's price, all while further misaligning the team's own incentives.
Get new scam files the moment we publish them — usually 2–3 emails a week.