TL;DR
Compound is one of the oldest over-collateralized lending protocols on Ethereum, and it shows in the track record: the core lending engine has never had user deposits drained. Version 3 (Comet) narrowed the attack surface by moving to isolated single-base-asset markets, so a bad collateral asset in one market cannot cascade into another the way cross-margin v2 could. The contracts are upgradeable, but only through COMP governance behind a timelock that makes any change take about a week. Two real incidents belong in the record and neither cost depositors principal: a September 2021 COMP-rewards over-distribution bug (which DefiLlama does list as a $147M exploit) and a July 2024 governance attack where a whale bloc pushed a proposal to redirect treasury COMP. The things to actually watch are that governance path, the whale-capture risk it exposed, and the Community Multi-Sig that holds the instant Pause Guardian power. No depositor-principal deal-breaker found, so the gate lands on solid.
Checklist
Audits and contracts. Deep audit history. Trail of Bits and OpenZeppelin on the v2 core (Trail of Bits 2019-2020; OpenZeppelin 2019 onward), and for v3 specifically the Comet contracts were audited by OpenZeppelin and ChainSecurity (ChainSecurity report May 2022) plus Certora formal verification wired into CI. Gauntlet runs the economic/market-risk stress testing, and there is a community-run Immunefi bug bounty. Unlike an immutable AMM, Comet markets are upgradeable proxies, so smart-contract risk is not fully off the table. It is gated behind governance instead.
Admin control. All Comet instances are controlled by the same Timelock that administers v2, driven by COMP holders through Governor Bravo (0xc0da...66529) and the Timelock (0x6d90...33925). A proposal runs a 2-day review, a 3-day vote, then a 2-day timelock queue, so any protocol change takes at least a week. That delay is the real backstop and it matters: in the July 2024 governance attack it was the community's window to react. The exception is the Pause Guardian, held by a Community Multi-Sig (0xbbf3...012c), which can pause supply, transfer, withdraw, absorb, and buy operations immediately but cannot seize funds. The multisig signer threshold (N-of-M) was not confirmable this run.
Oracle. Chainlink is the primary price feed on the main markets, with RedStone used on Unichain and Api3 on Mantle per the DefiLlama oracle breakdown (both with GitHub proof links). Chainlink on the majors is the conservative choice.
Liquidity and exit. Around $1.04B is locked in Compound V3 (parent Compound Finance $1.13B), confirmed live this run against the DefiLlama API. Suppliers can withdraw permissionlessly as long as the specific market has un-borrowed base asset available; in a high-utilization spike, exit can queue behind borrowers repaying, which is normal lending-market behavior, not a protocol flaw.
Yield: real vs emission. The base yield is real: it comes from borrower interest, set algorithmically by utilization. COMP token rewards still exist on some markets but are small now and accounted separately, so the headline supply APY is not propped up by emissions.
Holder concentration. COMP trades around $15.71 with a $24M in COMP) into their own vault. It passed by a narrow margin and was resolved by a settlement (a COMP staking product) rather than reverted, and again no user deposits were lost. Market share has been declining as Aave and newer lenders grew, but declining share is not a safety risk.$152M market cap, roughly 9.67M of a 10M fixed supply circulating, and sits about 98% below its all-time high ($854). That is a governance-token signal, not a solvency one, but the July 2024 episode showed the concentration has teeth: a coordinated delegate bloc was able to pass a treasury proposal. Per-market supplier concentration (whether a few whales dominate a single Comet market) was not measured this run.
Track record. Compound has never had user deposits directly drained across multiple market cycles, but the record is not spotless and two incidents belong here honestly. First, September 2021: a bug in the upgraded Comptroller (rewards-distribution) contract from Proposal 62 over-distributed COMP, roughly 490,000 COMP (about $147-160M at the time) up for grabs; DefiLlama lists this as "Compound V2 - Math Mistake Exploit - $147M." It was a rewards-accounting error, not theft of deposited principal, and a large share was voluntarily returned. Second, July 2024: an activist bloc known as the "Golden Boys" (led by Humpy) used governance to push Proposal 289, seeking to move about 5% of the DAO treasury (
Worst case
A malicious or captured governance proposal, or a Pause Guardian action, alters a market's parameters. The timelock gives roughly a week of warning for a hostile proposal, which is enough time to exit; the July 2024 attack is the live proof that this path is not theoretical, and also that it targeted the treasury, not depositor collateral. The Pause Guardian can freeze operations instantly but can only pause, not seize funds. A more mundane worst case is a collateral asset's oracle mispricing or a bad-debt event in one isolated market, which under v3's design is contained to that single market rather than the whole protocol. There is no protocol insurance fund backstopping depositors, so position sizing per market is the mitigation.
Bottom line
Solid. Old, heavily audited, and the isolated-market v3 design plus a ~1-week governance timelock make this one of the more conservative places to lend on-chain. The honest caveats are that markets are upgradeable (so you are trusting COMP governance and the Timelock), COMP governance has already been the target of a real whale-driven attack (July 2024), the Pause Guardian multisig config is unverified this run, and there is no insurance fund. Both notable incidents (2021 rewards bug, 2024 governance attack) left user deposits intact, so the gate holds at solid rather than caution.
Data appendix
- TVL: Compound V3 ~$1.04B; parent Compound Finance ~$1.13B (DefiLlama, get_tvl by protocol, confirmed live 2026-07-01). 90d / ATH series: refresh.
- Deployed chains: Ethereum, Arbitrum, Base, Optimism, Polygon, Scroll, Mantle, Ronin, Unichain (DefiLlama protocol record).
- Audits: v2 core - Trail of Bits (2019-2020), OpenZeppelin (2019 onward). v3 Comet - OpenZeppelin + ChainSecurity (report May 2022) + Certora formal verification (integrated into CI). Gauntlet - economic/market risk. Immunefi community bug bounty. Sources: compound.finance/docs/security and OpenZeppelin/ChainSecurity audit pages.
- Admin / governance: COMP + Governor Bravo (0xc0da02939e1441f497fd74f78ce7decb17b66529) + Timelock (0x6d903f6003cca6255d85cca4d3b5e5146dc33925); 2-day review + 3-day vote + 2-day timelock, ~1 week minimum per change (Compound v2 governance docs, primary; confirmed this run). Pause Guardian = Community Multi-Sig (0xbbf3f1421d886e9b2c5d716b5192ac998af2012c), can pause supply/transfer/withdraw/absorb/buy (Compound v3 governance docs, primary). Multisig N-of-M signer threshold: refresh.
- Oracle: Chainlink primary; RedStone on Unichain, Api3 on Mantle (DefiLlama oraclesBreakdown with GitHub proof links, confirmed this run).
- COMP token: $15.71, market cap ~$152M, circulating ~9.67M of 10M fixed supply,
98.2% below ATH ($854) (CoinGecko, 2026-07-01). - Holder concentration: COMP top-holder distribution and per-Comet-market supplier concentration: refresh.
- Incident record: DefiLlama hacks list DOES include "Compound V2 - Math Mistake Exploit - $147M - 29 Sept 2021" (the rewards over-distribution bug; user deposits not touched, large share returned). July 2024 "Golden Boys" / Humpy governance attack (Proposal 289) sought
5% of treasury ($24M COMP), passed narrowly, resolved by settlement, no deposit loss. No direct Comet v3 exploit found in a 2025-2026 news scan (forks such as Onyx and Hundred Finance were hit, not Compound itself). Maintained monthly. Methodology: DeFi Research Instruction v2.