A week ago, Compound founder Robert Leshner called a bug in his lending protocol’s smart contract a “moral dilemma.” Perhaps for some, but for others today the smart contracts became a vending machine full of free cash.
Today, someone exploited a bug in Compound’s Controller contract, which is the part of the protocol that distributes yield farming rewards to users. By calling Compound’s drip() function, they transferred $68 million, or 202,472 COMP, from Compound’s reservoir to its Comptroller.
Since Banteg, a core developer at Yearn.Finance, tweeted about the exploit earlier this afternoon, four major transactions have drained the pool of 64,997 COMP, or $21.4 million. One of those transactions withdrew 37,504 COMP, or $12.3 million. Banteg said that only “addresses with the buggy state can drain” and that there are another five addresses that could claim $45m, „emptying the Comptroller.”
It appears my estimate was low because of stale data in accruedComp. Four users
Źródło: https://decrypt.co/82499/compound-exploit-drains-21m-from-lending-protocol