First Deposit Bug in CompoundV2 and its forks
This article talks about an unpopular vulnerability of a popular DeFi project, i.e. Compound Finance V2. The bug impacts most Compound V2 forks.
I am Akshay, a smart contract auditor and software engineer working in web3 since 2018. Currently I am securing top web3 projects at Spearbit and Cantina. In 2023 I was among the top auditors on Code4rena. In the past I have build DeFi protocols which combinedly held over $200 Millions in value.
This article talks about an unpopular vulnerability of a popular DeFi project, i.e. Compound Finance V2. The bug impacts most Compound V2 forks.
On 1st Feb 2023, an attacker exploited the Bonq protocol and captured profit in millions of dollars. In this article I will explain the root cause behind that attack.