Compounding problems: $65M more COMP at risk as devs wait for time-locked bug fix

Published at: Oct. 4, 2021

Major decentralized finance (DeFi) money market Compound’s woes are worsening, with nearly $150 million worth of COMP now at risk due to a buggy upgrade to the protocol that went live last week.

On Thursday, Cointelegraph reported that a bug had resulted in between $70 million and $85 million worth of COMP tokens being mistakenly offered to users as rewards after an update intended to fix bugs and “split COMP rewards distribution” went awry.

Despite the reward distribution error being identified quickly, Compound’s week-long delay in enacting new governance measures meant that the error will not be fixed until Thursda.

On Sunday, Compound founder Robert Leshner tweeted that 202,472.5 COMP (worth approximately $65 million) had been placed at risk after the protocol’s drip function was called for the first time in roughly two months.

The drip function makes tokens held in Compound’s Reservoir available to users, with 0.5 COMP being accumulated by the Reservoir per block. Leshner noted that “the majority of COMP reserved for users” is held in the Reservoir.

This brings the total COMP at risk to approximately 490k, of which 136k is still in the Comptroller, and 117k has been returned to the community so far (THANK YOU ).

— Robert Leshner (@rleshner) October 3, 2021

SushiSwap developer Mudit Gupta took to social media to criticize the use of time-locks on governance, asserting that roughly 100 people were aware of the threat posed by the drip function since the bug was discovered on Thursday, but they were unable to act due to the time-delay on updating the protocol.

Gupta also warned of the risks associated with upgradable smart contracts, asserting they are inappropriate for “large [DeFi] primitives.”

This is why timelocks on everything are not always the best option. About a hundred people knew about this possibility since day 1 but their hands were tied due to the timelock.All of this 68.8m can be drained, not just a quarter if there are malicious actors involved. https://t.co/xB5T1sjUQ8

— Mudit Gupta (@Mudit__Gupta) October 3, 2021

“I’ve come to see upgradability as more of a bug than a feature,” he added.

While Leshner’s tweet revealed that roughly 117,000 COMP worth $37.6 million had been returned to the protocol following the initial incident, Yearn.finance developer Banteg estimated that one-third of the funds that were placed at risk by the drip function had already been claimed by users at roughly 3:30 pm UTC on Sunday.

Banteg tallied the total value of COMP tokens placed at risk by the protocol’s bug to now be $147 million.

Related: Hackers exploit MFA flaw to steal from 6,000 Coinbase customers — Report

Despite the bug’s initial identification causing the price of COMP to quickly crash 3% from $330 to $286 on Thursday, the token quickly recovered and traded above $340 on Saturday, according to CoinGecko.

COMP has shed 7% of its value since tagging a local high of $347.5 on Sunday, last changing hands for $322 at the time of writing.

Tags
Related Posts
MDT introduces blockchain oracle to accelerate DeFi adoption
Measurable Data Token (MDT) has announced the launch of a blockchain-based oracle service, Measurable Finance (MeFi), which has been designed to connect traditional financial data markets to the decentralized finance (DeFi) sector. In its primary showcase of utility, the project constructed a decentralized application (DApp) —accessible on both the Ethereum and testnet blockchains — which enables DeFi participants to access stock trading data from some of the world’s largest financial marketplaces, including the Nasdaq, New York Stock Exchange (NY and Hong Kong Stock Exchange (HKEX). With the introduction of these services, decentralized data sharing network Measurable aims to advance the …
Adoption / Oct. 20, 2021
Gelato raises $11M from heavyweight backers for Web 3.0 automation
Smart contract automation network Gelato has become the latest to receive big backing from crypto venture capital giants. Gelato has raised $11 million in a Series A funding round led by Dragonfly Capital and with participation from ParaFi Capital, Nascent, IDEO CoLab Ventures and Aave founder Stani Kulechov. The funds were raised through a closed-door token sale and will go toward onboarding more blockchains to the network and increasing its staff from the current team of 15. Gelato automates Ethereum smart contract operations by using what it calls “arbitrary logic” and bots. Its most prominent use case is addressing liquidity …
Blockchain / Oct. 8, 2021
Binance Smart Chain Adds Chainlink Oracles for Better DeFi
Binance Smart Chain — a dual-chain architecture from major crypto exchange Binance — is now integrating Chainlink (LINK) data oracles. Binance Smart Chain adds smart contracts to the exchange's original chain, Binance Chain, and is currently in testnet. Chainlink co-founder Sergey Nazarov told Cointelegraph that in his opinion, this integration will save time and effort for developers who are building decentralized apps on the blockchain: “With the Chainlink integration, Binance Smart Chain developers no longer need to dedicate months of engineering time to set up their own oracle infrastructure. Now, they can simply use Chainlink as an abstraction layer to …
Technology / July 23, 2020
DAOs need checks and balances to have better governance
Over the past few years, decentralized autonomous organizations (DAOs) have introduced a clear paradigm shift in blockchain governance. With their community decision-making and adherence to hardcoded rules, they have challenged the role of hierarchy and central authority that are present in modern organizations, especially as it pertains to business. Ideologically, DAOs have a lot in common with democracies: individuals holding an amount of a DAO’s specific token can allocate those tokens as votes on governance proposals. Once voting has concluded, the final outcome is executed autonomously by smart contracts. In functional democracies, however, citizens elect representatives to legislate laws and …
Decentralization / Oct. 18, 2022
Number of devs increased during crypto winter: Electric Capital report
The notion that bear markets are good for builders appears to be true with the total number of monthly active Web3 developers increasing 5.4% to more than 23,300 over the last 12 months despite a near 70% drop in crypto prices. According to a Jan. 16 report from Electric Capital, “full-time” developers — categorized as those who contribute to 76% of Github commits — also increased 15.2% to over 7000, while “one-time” builders fell 6.2% to over 3,500 during the same time period between December 2021 and December 2022 Despite the crypto market capitalization beginning its long plunge from from …
Adoption / Jan. 18, 2023