Compound's COMP Distribution Bug Leaks $80 Million to Opportunistic Claimants
A community-authored governance proposal, Proposal 62, which had reportedly been reviewed by Compound Labs before deployment, contained a calculation error that let certain users claim COMP rewards they had not actually earned. Compound's own statement on the incident put the excess distribution at roughly $80 million.
The faulty code took effect starting around 22:20 UTC on September 29th, after which some users could withdraw COMP rewards far beyond what they were owed.

Unlike a genuine infinite-mint exploit, no tokens were created out of thin air here — the damage was indirect. The only real losers were existing COMP holders, whose holdings were diluted faster than the protocol's intended emission schedule would have caused.
Even accounting for that extra dilution, calling this a crash overstates it. Compound's standing in the community is strong enough that an $80 million miscalculation barely dented its overall reputation. The Compound team downplayed the severity publicly, and founder Robert Leshner moved quickly to distance himself from the episode — though Compound Labs' credited role in reviewing Proposal 62 means the organization can't fully separate itself from what happened.
Where the bug lived
The error sat inside the comptrollerImplementation contract's reward calculations, specifically affecting long-tenured users who had been supplying or borrowing assets before the compInitialIndex value was ever established.
Developer Kurt Barry identified the flaw on Twitter, noting it came down to a comparison-operator mistake: a "greater than" (>) used where "greater than or equal to" (>=) belonged, repeated in two separate places in the code. Mudit Gupta laid out a fuller technical explanation in a separate thread.
Early claimants versus latecomers
Users who caught the exploit early were able to withdraw heavily inflated rewards. As the Comptroller contract's balance drained, users who arrived later were left with only scraps.
The community pushed through a follow-up governance action, Proposal 63, to disable COMP rewards entirely and stop further bleeding. By the time it could take effect, though, only around $250,000 remained in the Comptroller contract — suggesting the fix arrived too late to matter much.

Aftermath
The full fallout is still unfolding. Researcher 0xngmi noted on Twitter that at least one person who claimed excess rewards doesn't seem overly concerned about covering their tracks: they reportedly converted roughly 10 million dollars' worth of COMP into stablecoins on OKEx and Huobi, then began farming Curve with the proceeds — behavior that implies a KYC-verified account, since both exchanges require identity checks for withdrawals of that size.
In the end, this looks like a story of systemic failure rather than a single villain — a case, as Kurt Barry put it, of two mistyped comparison operators leading to tens of millions of dollars in lost value.
Get new scam files the moment we publish them — usually 2–3 emails a week.