An Ethereum transaction confirmed at 11:13:39 UTC on October 3, 2021 called `drip()` on Compound’s Reservoir contract and transferred exactly 202,472.5 COMP to the protocol’s Comptroller. The transfer materially increased the tokens exposed to an erroneous rewards-distribution state introduced days earlier by Compound governance Proposal 62.

The transaction did not pay the caller 202,472.5 COMP, nor did it prove that the entire amount had been lost. It moved tokens from the Reservoir—the contract holding COMP allocated for future distribution—into the Comptroller, where accounts affected by the accounting bug could potentially claim more COMP than they had legitimately earned.

That distinction was central to the event-day record. The verified development was a successful on-chain transfer into a vulnerable distribution contract. Estimates of the amount ultimately claimable or recoverable remained unsettled on October 3.

A public function released the backlog

The Reservoir’s `drip()` function was callable by any Ethereum address. The October 3 caller paid the transaction fee but received no COMP in that transaction. Etherscan’s decoded record shows the Reservoir sending 202,472.5 COMP to the Comptroller at block 13,345,887.

Compound founder Robert Leshner said on October 3 that the amount represented approximately two months of accumulated COMP since the function had last been called. His statement also characterized the transfer as increasing total exposure. Those exposure figures were contemporaneous estimates based on account states and possible claims, not an audited loss calculation.

The transaction therefore demonstrated a composability risk that was operational rather than hypothetical: a function working as designed at the Reservoir level could worsen the consequences of faulty accounting elsewhere in the protocol.

Proposal 62 created the vulnerable state

Proposal 62 had changed Compound’s COMP distribution logic, including how rewards were divided between suppliers and borrowers. After its execution on September 29, certain accounts began accruing or claiming excessive rewards. Compound community records described the defect as a distribution bug introduced by that proposal; the underlying lending and borrowing positions were not reported as directly drained by the October 3 Reservoir call.

The incident was consequential because COMP was both a transferable token and the voting asset used to govern Compound. An incorrect distribution could create a financial loss for the community treasury while also reallocating governance power. Yet ownership of newly exposed tokens should not be confused with a completed transfer to specific claimants: only subsequent claim transactions could establish that.

Governance could not patch immediately

Compound’s documented governance process imposed a two-day review period, three days of voting and a two-day Timelock before an approved change could execute. The protocol described the minimum path for an upgrade as one week.

That delay was intended to give token holders notice and an opportunity to review or exit before code changed. On October 3, however, it also meant contributors could not immediately replace the faulty Comptroller logic after discovering the error. A proposed temporary response had already prompted concern that simply disabling claims could break applications integrated with Compound.

The episode exposed a structural tradeoff in decentralized protocol administration. Time delays can constrain hostile or rushed upgrades, but the same constraints can slow emergency repairs after a bug is already active. The October 3 transfer made that tension measurable in COMP rather than merely theoretical.

What remained uncertain on October 3

Contemporaneous reporting identified claims from the replenished Comptroller after the `drip()` transaction, but the full population of affected accounts was not yet known. No complete event-day reconciliation established the final quantity claimed, returned or permanently lost.

The defensible conclusion for October 3 was consequently narrow: 202,472.5 additional COMP had entered a contract affected by faulty reward accounting while a governance-delayed repair remained pending. Final losses, recoveries and later corrective proposals were not yet part of the verified event-day outcome.

Primary sourceEtherscan — October 3, 2021 Compound Reservoir drip transaction

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.