A Warning Ignored - How a Known Compound Fork Bug Cost Sonne Finance $20 Million
Sonne Finance, a lending protocol forked from Compound V2, lost roughly $20 million on its Optimism deployment to an exploit that the wider Compound-fork ecosystem had already been warned about following a near-identical incident a year earlier.
The first sign of trouble came late on Tuesday, when the monitoring account Nerv Alert flagged an initial loss of around $3 million. Sonne posted an update in its Discord server shortly afterward, though a public statement on X didn't follow for another couple of hours. By the time the full damage was tallied, the loss had grown to $20 million across WETH, VELO, soVELO and Wrapped USDC.

The root cause was a donation attack — a vulnerability class that had already sunk another Compound V2 fork, Hundred Finance, in a comparable exploit roughly a year prior. Hundred Finance had even gone as far as publicly cautioning other Compound forks to check for the same weakness. Sonne, which had roughly $60 million in TVL before the exploit, appears not to have acted on that warning, despite the fix being well understood elsewhere in DeFi.
According to a breakdown posted by Luke Youngblood, the chain of events started when Sonne's team deployed a new market contract for $VELO and put forward a governance proposal to activate it, subject to a four-day total governance window. Three days in, the proposal passed, and once its 24-hour timelock expired, the activation transaction became executable by anyone on Optimism — not just the team. An attacker, likely running an automated bot to beat any legitimate caller to the punch, made sure they were the one to submit it.
Rather than simply activating the market, the attacker bundled the activation with their own exploit payload in a single transaction. That transaction set the collateral factor for Sonne's $VELO market to 35%, which was the opening needed to immediately begin draining the protocol — pulling out at least seven figures in the process.
On-chain records identify the attacker's wallet as 0xae4a7cde7c99fb98b0d5fa414aa40f0300531f43, operating through an attack contract at 0x02fa2625825917e9b1f8346a465de1bbc150c5b9. The markets targeted were soVELO (0xe3b81318b1b6776f0877c3770afddff97b9f5fe5), SoUSDC (0xec8fea79026ffed168ccf5c627c7f486d77b765f) and soWETH (0xf7b5965f5c117eb1b5450187c9dcfccc3c317e8e). The core exploit transaction is recorded at 0x9312ae377d7ebdf3c7c3a86f80514878deb5df51aad38b6191d55db53e42b7f0. The stolen funds were subsequently spread across several wallets, including 0x5d0d99e9886581ff8fcb01f35804317f5ed80bbb, 0x6277ab36a67cfb5535b02ee95c835a5eec554c07, the attacker's original address, 0x9f09ec563222fe52712dc413d0b7b66cb5c7c795, 0x3b39652151102d19ca41544a635956ef97416598 and 0x9f44c4ec0b34c2dde2268ed3acbf3aba8eacde51.
Researcher Daniel Von Fange later published a closer look at the governance failures behind the incident, along with guidance for protocols relying on multisig-plus-timelock setups. His core point: when a sequence of steps has to execute in a fixed, specific order to remain safe, the governance mechanism must not allow anyone to cherry-pick which parts of that sequence get executed — the whole thing needs to be atomic.
Sonne moved relatively fast on disclosure, publishing a post-mortem about five hours after the attack. In it, the team explained that it had previously sidestepped the classic Compound V2 donation attack by raising collateral factors gradually — but that a new proposal to onboard VELO markets reopened the same exploit window. Once the VELO integration transactions were scheduled through Sonne's permissionless Optimism multisig, the attacker stepped in, executed the changes, and extracted the full $20 million using the long-documented vulnerability. The team says it is now working on recovering the funds and is weighing a bug bounty as an incentive for their return.
Not all of the story was negative: MEV researcher Tony KΞ of fuzzland documented how he intercepted the exploit in real time and saved more than $6.5 million from being stolen, spending only about $100 to do it.
Separately, a user pointed out that Mendi Finance runs on code that is a close, friendly fork of Sonne's, raising the question of whether it might face the same exposure.

Sonne itself had been audited by Yearn Finance's yAudit, and that audit report lists this exact attack surface as a high-severity finding, noting "unclear protection against Hundred Finance attack vector." In the aftermath, speculation has circulated that other forked protocols carry the same unaddressed risk.
Taken together, the incident is a textbook case of a documented, preventable vulnerability being allowed to resurface. Sonne's team pressed ahead with new market integrations without building in adequate protection against the donation attack vector, even though Hundred Finance's exploit a year earlier — and Sonne's own auditors — had flagged exactly this failure mode. Combined with governance permissions that were too loosely configured, that gap gave the attacker an easy path to millions of dollars.
The severity rating attached to this risk by auditors makes the outcome harder to excuse: this wasn't an unknown unknown, it was a documented finding. With chatter continuing about whether other Compound V2 forks share the same exposure, the episode is best read as a reminder that shipping quickly without matching security diligence carries real costs — and that copying code without fully understanding its failure modes is not a sustainable practice for teams aiming to operate at scale. Real progress will likely require rigorous pre-launch review, ongoing monitoring for known attack patterns, and credible recovery plans, rather than repeating the same $20 million lessons across the sector.
Get new scam files the moment we publish them — usually 2–3 emails a week.