Compound:
the pioneer that stayed conservative, with a real, self-inflicted scar of its own.
We tore apart Compound, one of DeFi lending's founding protocols and the direct architectural ancestor of much of what Aave and others later built on, across the same lending-adapted scorecard we opened this series with. From a genuinely clean record against external, malicious smart-contract hacks across V2 and V3 (Comet), extensive named audits (Trail of Bits, OpenZeppelin, ChainSecurity, and Certora formal verification), and a genuinely conservative, isolated-market design that meant Compound carried almost no exposure to the April 2026 rsETH bridge exploit that hit Aave hard, to a real, well-documented incident worth centering directly: in September 2021, a single-character bug in a governance-approved upgrade (Proposal 062) caused Compound's own Comptroller contract to erroneously distribute its native COMP token, putting as much as $161.7 million at risk at its worst estimate, with no emergency admin mechanism available to pause it, a full 7-day governance vote was required to patch it. We also found a real, notable discrepancy in current TVL figures across our sources; and landed on a score the marketing page won't show you.
Our take, up front: Compound is one of DeFi lending's founding protocols, launched in 2018 and reaching major versions V2 (2019) and V3, branded Comet (2022). Real, genuinely clean record against external, malicious smart-contract hacks: despite dedicated searching, we found no confirmed direct exploit of Compound's own contracts by an outside attacker across either version. Real, genuinely extensive, long-standing named audits: Trail of Bits, OpenZeppelin, and ChainSecurity have all reviewed the protocol, alongside Certora formal verification integrated directly into Compound's continuous integration system. Real, disclosed Immunefi bug bounty offering up to $1 million for critical mainnet vulnerabilities. Real, genuinely conservative, distinctive design in Compound III: each isolated Comet market has a single Base Asset that earns interest, while collateral assets remain idle specifically to reduce protocol-wide contagion risk; this design meant Compound carried almost no exposure to the April 2026 rsETH bridge exploit that hit Aave and other lenders hard. What we can't set aside: a real, well-documented, significant incident of a different character than a hack. In September 2021, a single-character bug (a ">" where a ">=" should have been) in a governance-approved upgrade, Proposal 062, caused Compound's own Comptroller contract to erroneously distribute its native COMP governance token; no supplied or borrowed user funds were ever at risk, but as much as $161.7 million in COMP was estimated at risk at the worst point, and because there was no admin kill-switch by design, a full 7-day governance process was required to patch it. We also found a real, notable discrepancy in current TVL figures across our sources, ranging from roughly $1.2 billion to $3.2 billion depending on the source and date. We weighted all of it below.
Real, genuinely clean record against external, malicious smart-contract hacks across both V2 and V3 (Comet). Real, extensive, named audits (Trail of Bits, OpenZeppelin, ChainSecurity) and Certora formal verification integrated into continuous integration. Real, disclosed Immunefi bug bounty up to $1M. Real, genuinely conservative isolated-market design meant Compound carried almost no exposure to the April 2026 rsETH bridge exploit that hit Aave and other lenders hard. What we can't set aside: a real, well-documented, different-category incident. In September 2021, a single-character bug in a governance-approved upgrade (Proposal 062) caused erroneous COMP distribution, putting as much as $161.7 million in COMP at risk at the worst estimate; no admin kill-switch existed by design, requiring a full 7-day governance vote to patch.
Pros
- No confirmed external hack of Compound's own contracts found in our research, across V2 or V3
- Almost no exposure to the April 2026 rsETH bridge crisis that hit Aave hard
- Extensive named audits plus Certora formal verification in CI; $1M Immunefi bounty
Cons
- Sept 2021: a governance-upgrade bug put up to $161.7M in COMP at risk of erroneous distribution
- No admin kill-switch by design; a full 7-day governance vote was required to patch it
Real, disclosed, but genuinely modest TVL relative to the category leader: sources disagree notably, ranging from roughly $1.2 billion (via DeFiLlama, June 2026) to $3.2 billion (May 2026). Even at the higher figure, this sits well behind Aave's scale. Real, disclosed active borrow demand specifically on USDC and ETH Comet markets.
Pros
- Active, disclosed borrow demand on deep USDC and ETH markets specifically
Cons
- TVL figures range from $1.2B to $3.2B depending on source and date, a real, unresolved discrepancy
- Meaningfully smaller scale than the category leader regardless of which figure is used
Real, disclosed, functioning on-chain governance via the COMP token, one of the pioneering models later echoed elsewhere in this series. Real, disclosed, publicly known founder (Robert Leshner). Real, genuinely strong, disclosed immutability by design: "no admin controls or community tools" existed to unilaterally halt the 2021 COMP distribution, a genuine decentralization credential that also directly extended that incident's duration.
Pros
- Pioneering, functioning on-chain COMP governance; publicly known founder
- Genuinely strong immutability by design; no unilateral admin override capability
Cons
- That same immutability meant a 7-day governance vote was required to patch the 2021 bug
Real, disclosed, genuinely conservative isolated-market (Comet) design: each market has one Base Asset that earns interest, while other assets serve purely as idle collateral, reducing protocol-wide contagion risk by design. Real, disclosed active growth plans: expanding to 4-6 additional chains and 8-15 new asset markets, including more LSTs and LRTs.
Pros
- Isolated Comet markets genuinely limit contagion risk by design
- Disclosed, active expansion plans for more chains and asset markets
Cons
- Currently narrower chain and asset footprint than the category leader
Real, disclosed cTokens model (V2) providing a straightforward, block-by-block accruing representation of pool share. Real, disclosed strong developer integration surfaces per a detailed source: Compound.js, subgraphs, and documented Bulker/wrapper patterns for advanced programmatic workflows.
Pros
- Straightforward cToken model; strong disclosed developer tooling (Compound.js, subgraphs)
Cons
- Comet's single-Base-Asset-per-market design may require using multiple markets for multiple needs
Real, disclosed variable rates driven by utilization, with COMP liquidity-mining rewards for both suppliers and borrowers, using governance-set distribution ratios since the 2021 fix. Real, honest, disclosed competitiveness gap per a detailed source: scale and rate competitiveness genuinely lag the largest DeFi lenders.
Pros
- Disclosed COMP liquidity-mining rewards for both suppliers and borrowers
Cons
- Rate competitiveness genuinely lags the largest DeFi lenders, per a detailed source
Real, disclosed developer-friendly Compound.js SDK, subgraphs, and Bulker/wrapper patterns for advanced programmatic workflows. Real, disclosed ongoing Gauntlet risk-management partnership safeguarding up to 50 Comet deployments. Real, distinctive Comet isolated-market architecture itself as a genuine design choice.
Pros
- Solid, disclosed developer tooling and an active Gauntlet risk-management partnership
Cons
- Less extensive advanced-feature stack than the category's most feature-dense competitor
Access only through Compound's official app, and verify current TVL and market conditions directly given the discrepancies we found.
Given the notable spread in TVL figures across our sources, check Compound's own current dashboard or DeFiLlama directly for live numbers before assuming any single figure quoted elsewhere is current, and remember that Comet's single-Base-Asset design means you may need to pick the specific market that matches what you actually want to borrow or earn interest on.
The pioneer that chose caution over scale, and it genuinely paid off in April 2026, even if it didn't in 2021.
Compound deserves real credit for a genuinely different profile than the category leader we reviewed first: a conservative, isolated-market design that isn't just a marketing claim, it demonstrably kept Compound almost entirely out of the April 2026 rsETH crisis that forced Aave into an emergency response at a scale we haven't seen anywhere else in this project. That's a real, substantive vindication of a deliberate design philosophy. But we don't think Compound gets to claim a spotless record either. The September 2021 COMP distribution bug wasn't a hack, and no user deposits were ever at risk, but it was a real, costly, self-inflicted failure that a full week of governance process couldn't quickly contain, precisely because Compound's own decentralization-by-design removed the emergency lever that might have stopped it sooner. Add a meaningfully smaller, somewhat disputed current TVL, and you get a protocol that's earned real trust through caution, but hasn't matched the market leader's scale or rate competitiveness to go with it.
The scorecard above is deliberately general. Whether Compound is right for you depends heavily on which of these you already are.
The user who wants a conservative, risk-isolated design and is comfortable with a narrower set of markets and chains
This is exactly where Compound's deliberate, Comet-driven design philosophy delivers real, demonstrated value.
The developer who wants a well-documented SDK, subgraphs, and Bulker/wrapper patterns to integrate against
Compound's disclosed developer tooling makes this a genuinely solid, practical option.
The user who verifies current TVL and market-specific conditions directly given the discrepancies we found
Given the real, unresolved spread in TVL figures across our sources, this specific habit genuinely matters here.
Anyone who wants the deepest possible liquidity or the most competitive rates in the category
Aave, reviewed earlier in this series, currently offers meaningfully greater scale on both counts.
The scorecard covers the headline judgment calls. These four tables cover the specifics we didn't want to bury in prose; the September 2021 COMP bug timelined precisely, Compound vs. Aave on the April 2026 crisis specifically, the TVL discrepancy explained, and our second lending-protocol comparison entry.
The September 2021 COMP distribution bug, timelined
| Date | Event |
|---|---|
| Sept 29, 2021 | Proposal 062 activates, changing COMP distribution ratios; a single-character bug (">" instead of ">=") in the upgraded Comptroller contract causes erroneous over-distribution |
| Sept 29-30, 2021 | Community members flag suspicious transactions; one address claims 91,000 COMP (~$26.8M) for providing effectively zero liquidity |
| Sept 30, 2021 | Founder Robert Leshner confirms the bug; worst-case exposure estimated at 280,000 COMP (~$80M) |
| Early Oct 2021 | Reports indicate further exploitation moved additional tokens into the vulnerable contract; worst-case exposure revised up to 490,000 COMP (~$161.7M) |
| Oct 7-9, 2021 | Proposal 064 passes and is activated, restoring correct distribution logic for most users; users tied to specific affected markets remain blocked pending further review |
No supplied or borrowed user funds were ever reported at risk; this was specifically an over-distribution of Compound's own native governance/reward token, a materially different category of incident from a hack that drains user deposits.
Compound vs. Aave, specifically on the April 2026 rsETH crisis
| Aave | Compound | |
|---|---|---|
| rsETH exposure | Significant; among the lenders that had to freeze markets | Almost none, per a detailed August 2026 source |
| Direct consequence | $8.45B panic withdrawal in 48 hours; $300M emergency response | No comparable crisis reported |
| Underlying reason | Broader, more expansive collateral-listing philosophy | Conservative, isolated Comet market design |
We think this is a genuinely fair, direct illustration of the real trade-off between Aave's broader ambition and Compound's narrower caution; neither approach is categorically correct, but the outcomes in this specific case were starkly different.
Why our TVL sources disagree
| Source | Figure | Date |
|---|---|---|
| rfp.wiki (via DeFiLlama) | ~$1.2 billion | June 2026 |
| LedgerMind | ~$3.2 billion | May 2026 |
We couldn't fully reconcile this gap from our sources; it may reflect different snapshot dates, different scopes (V2+V3 combined vs. V3/Comet only), or simply market movement between May and June 2026. We're disclosing the range rather than picking whichever number is more flattering.
Lending protocols, side by side (series continues)
| Aave | Compound | |
|---|---|---|
| Confirmed core-contract exploit | None found in our research | None found in our research (external attackers) |
| Most severe incident type | Third-party bridge exploit ($292M, Apr 2026) | Self-inflicted governance-upgrade bug ($161.7M at risk, Sept 2021) |
| TVL scale | ~$14.49B (May 2026) | $1.2-3.2B (disputed across sources) |
| Distinctive model | Multi-network V3/V4 Hub & Spoke; native GHO stablecoin | Isolated Comet markets; single Base Asset per market |
This table will continue to grow as we review MakerDAO/Sky, Morpho, and others under the same adapted scorecard.
We don't just want to hand you our number; we want to show you how it sits next to what other review desks and comparison sites have published. Compound's long history means genuinely deep, specific independent coverage exists, giving us a solid comparison set here.
Our score lands meaningfully below the aggregated industry average; most general reviews we found treat the 2021 COMP bug as a well-resolved historical footnote and don't weight current, disputed TVL scale or rate competitiveness as heavily as our methodology does.
| Source | Score | Type |
|---|
Scores compiled by our editorial team from publicly available reviews as of August 2026. "Editorial estimate" means the outlet didn't publish a single numeric score, so we converted their published verdict and sentiment into a comparable 100-point figure. Verify current figures directly with each source before citing them elsewhere.
We found no confirmed direct hack of Compound's own smart contracts by an external attacker, across either V2 or V3 (Comet). Compound did experience a significant, self-inflicted incident in September 2021: a governance-upgrade bug that erroneously distributed its native COMP token; no user-supplied or borrowed funds were ever at risk.
A single-character bug (">" where ">=" should have been used) in Proposal 062, a governance-approved upgrade to the Comptroller contract, caused the protocol to over-distribute COMP rewards. At its worst estimate, up to $161.7 million in COMP was at risk. No admin kill-switch existed, so a full 7-day governance vote was required to patch it.
Almost not at all, per a detailed source. Compound carried very little rsETH exposure at the time, unlike Aave and several other lenders that had to freeze markets and manage a major liquidity crisis. This reflects Compound III's more conservative, isolated-market design.
Compound's third major version, launched in 2022. Each Comet market has a single Base Asset that earns interest, while other supported assets serve purely as collateral and remain idle, a deliberate design choice to reduce protocol-wide contagion risk.
Our sources disagree: one cites roughly $1.2 billion (via DeFiLlama, June 2026), another cites roughly $3.2 billion (May 2026). We couldn't fully reconcile the gap and are disclosing both figures rather than picking one.
cTokens, used in Compound V2, represent your proportional share of a lending pool. They accrue interest automatically every block, functioning as a verifiable, real-time proof of deposit.
Aave currently offers meaningfully greater scale, chain coverage, and rate competitiveness. Compound offers a more conservative, isolated-market design that demonstrably avoided the April 2026 rsETH crisis that forced Aave into an emergency response. Neither approach is categorically safer; they represent different trade-offs between ambition and caution.
Yes, COMP, one of the pioneering governance-token models in DeFi. COMP is also distributed as a liquidity-mining reward to suppliers and borrowers, using governance-set ratios since the 2021 fix.
More Reviews
Ledn – Crypto Lending & Borrowing Review
Score: 75/100. Highest CeFi score in this series: 10 straight PoR attestations, explicit no-re-lending pledge, never lost customer funds.
Read MoreAave – Crypto Lending & Borrowing Review
Score: 69.5/100. Category leader hit hardest by the Apr 2026 KelpDAO crisis: $124-230M bad debt, its largest liquidity event yet.
Read MoreCoinRabbit – Crypto Lending & Borrowing Review
Score: 50.5/100. Fast, no-KYC lending with a great product, but no named founder, no PoR, and vague licensing behind it.
Read MoreKamino – Crypto Lending & Borrowing Review
Score: 72.25/100. Survived two 2026 stress events with zero bad debt, per a Q2 investor report, not just its own marketing.
Read More



