Skip to main content

Compound Finance Suffers Bug Leading To ~$50M Token Distribution

Compound Finance (COMP) has seemingly suffered a token distribution bug after introducing and passing a recent governance vote that addressed rewards distribution, Proposal 62. Shortly thereafter, Compound reported in a tweet that there was unusual behavior regarding COMP distribution following the vote, but that “no supplied/borrowed funds are at risk.”

The funds that are in jeopardy due to the bug sit only in the Comptroller contract, which means that there is a total cap of 280,000 COMP tokens that are at risk. However, that’s still a hefty number, worth over $80M USD at the time of publishing. One transaction was reportedly as high as nearly $30M alone.

Let’s Get Movin’

With governance often comes the lack of immediate action. As Compound Finance CEO and Founder Robert Leshner noted in a tweet discussing the events at hand, “there are no admin controls or community tools to disable the COMP distribution; any changes to the protocol require a 7-day governance process.”

The Compound team quickly rolled out the initial governance process with Proposal 63 up for review, which temporarily disables COMP distribution rewards while the team and community address the fix for the protocol.

Leshner adds that while Proposal 63 is up for review, “a patch to restart the distribution is in development.” While this gives the team time to address the issue, Proposal 63 does note that all ~280,000 tokens will be at risk.

While the recent Compound bug showed immediate price impact, buyers quickly came back to market and the COMP token has still showed long-term resiliency. | Source: COMP-USD on TradingView.com

Related Reading | TA: Ethereum Consolidates, Why Bulls Could Aim Fresh Rally

Take 10%

Leshner has since gone on Twitter asking recipients of mistaken distributed COMP to return it, with the below tweet:

If you received a large, incorrect amount of COMP from the Compound protocol error:

Please return it to the Compound Timelock (0x6d903f6003cca6255D85CcA4D3B5E5146dC33925). Keep 10% as a white-hat.

Otherwise, it's being reported as income to the IRS, and most of you are doxxed.

— Robert Leshner (@rleshner) October 1, 2021

He took a bit of heat for the tweet, and followed up by stating that it was a “bone-headed tweet / approach” and that his intentions lie in “trying to do anything I can do to help the community get some of its COMP back.”

Smart contract specialist Kurt Barry noted just how costly small errors in code can impact blockchain projects:

Smart contracts are unforgiving of the tiniest errors…COMP bug is a tragic case of ">" instead of ">=" (in two code locations). Two characters, tens of millions of value lost.

— Kurt Barry (@Kurt_M_Barry) September 30, 2021

Truly a tough set of circumstances for the Compound Finance community, however many have shown approval of Leshner’s response.

The move is not the first mishap in the rapidly growing world of DeFi. Last month, the Poly Network suffered a hack that cost over $600M USD. In a bit of a bizarre set of circumstances, the Poly hacker returned most of the stolen crypto back to the network. And in the last week, cross-chain DeFi protocol pNetwork lost over $12M USD in tokenized Bitcoin to attackers.

Related Reading | Visa Is Building A Payment Channel Network On Ethereum

Featured image from Pexels, Charts from TradingView.com

from NewsBTC https://ift.tt/3utvXEC
via IFTTT

Comments

Popular posts from this blog

DeFi isn’t dead, it just needs to fix these 3 critical problems

It’s been a rough year for DeFi, and it may not get any better until projects focus more on security, regulation and usability. The persistent challenges  decentralized finance  face have been well documented by a handful of analysts and the recent collapse of the Terra ecosystem re-enforced the fact that something is critically wrong with DeFi. I think DeFi today is completely broken for 99% of the population. The promise of a more transparent financial system has been overtaken by greed. UST/LUNA is just the latest in a string of bad developments: — Peter Yang (@petergyang) May 11, 2022 Let's take a look at what experts say DeFi needs to do in order to have another revival.  Improved usability To date, the promise of open and uncensored access to a global decentralized financial system has been largely hampered by the complicated interface, confusing multi-step staking processes and lack of clarity surrounding the yields on various tokens. What do you thi...

ENS DAO delegates offer perspective on DAO governance and decentralized identity

AlphaWallet CEO and Spruce co-founder talk about their roles as contributors to the Ethereum Name Service following the project's recent airdrop. Earlier this month, the Ethereum Name Service, or ENS, formed a decentralized autonomous organization, or DAO, for the ENS community.  Cointelegraph spoke to two ENS DAO delegates who applied for the opportunity to represent the community and stay involved in the decision making process: Victor Zhang, CEO of AlphaWallet, an open source Ethereum wallet, and Gregory Rocco, co-founder of Spruce, a decentralized ID and data toolkit for developers. Zhang spoke about his experience as an external contributor to ENS and an early supporter since 2018. Zhang initially sought to help ENS by offering Alpha Wallet as a user-friendly tool for  resolving .eth names and cryptocurrency wallet addresses. Essentially, if a user inputs an .eth name in the AlphaWallet, it will show the wallet address, and vice versa using reverse resolution. Alpha...

National Futures Association adds rules for members handling digital assets

The CFTC-linked self-regulatory organization (SRO) has disclosure rules for members engaging in activities with BTC and ETH; now, standards of conduct are being added. The National Futures Association (NFA), the United States self-regulatory organization for derivatives markets, has issued a new compliance rule addressing members’ conduct. The new rule complements requirements issued in 2018. The NFA has “well over 100” members that engage in activities with digital asset commodities, but no way to address fraud or misconduct committed by those members, the organization explained to secretary of the Commodity Futures Trading Commission (CFTC) Christopher Kirkpatrick in a Feb. 28 letter as it submitted the proposed new rule for approval. The new rule is modelled on the NFA’s antifraud rules for exchange traded futures and swaps transaction and retail foreign exchange. The NFA is the only registered self-regulatory organization that has delegated authority from the CFTC, giving it a...