LIVE
MARKET CAP$2.43T+2.08%
24H VOL$124.78B+74.70%
EXCHANGES1,478
BTC DOMINANCE56.7%
ETH DOMINANCE10.0%
TOP ALTBNB (3.6%)
HomeProtos

DeFi lending platform Compound Finance hijacked again

Security & IncidentsMarket Events
March 9, 2026
3 min read
DeFi lending platform Compound Finance hijacked again

DeFi users reported suspicious functionality on the website of lending platform Compound Finance on Sunday.

The incident is the latest in a string of website hijackings that have affected Maple Finance, OpenEden and Curvance.

It’s the second time attackers have compromised Compound’s front end in less than two years.

Read more: Compound Finance and Celer Network websites compromised in ‘front-end’ attacks

Compound’s security provider later published an update on the project’s governance forum, reassuring users that the incident had been rectified and “all other credentials on the affected infrastructure account have been rotated.”

The post explains that the project’s website redirected users to “a phishing site hosted on a lookalike domain (‘compOOnd’),” but “no user loss of funds [was] identified.”

Compounding errors

Previously, the Compound front end was hacked in July 2024, along with other Squarespace-based DeFi domains.

There are worries that such attacks may become more common as AI tools lower the bar for would-be phishing scammers.

Read more: AI just bypassed the Cloudflare protection that DeFi needs

Luckily, any users of Compound were better protected yesterday.

According to the forum post, the app.compound.finance subdomain, on which users connect wallets and make transactions, “is served via IPFS, allowing [security providers] to independently verify its integrity.”

Sunday’s incident is the latest in a string of blunders for what was once one of DeFi’s top protocols.

Last year, the Compound DAO came under scrutiny over conflict-of-interest concerns related to service provider Gauntlet.

In 2022, an operational error bricked the cETH market (worth over $800 million at the time) for a week while a fix was implemented. The previous year, almost $150 million of excess rewards were distributed, also by mistake.

Got a tip? Send us an email securely via Protos Leaks. For more informed news and investigations, follow us on XBluesky, and Google News, or subscribe to our YouTube channel.

The post DeFi lending platform Compound Finance hijacked again appeared first on Protos.

RELATED TOPICS

front-end attackcompound financephishingDeFi securitywebsite hijackblockchainsmart contractprotocol risk

Market Overview

BitcoinBitcoin
68,981.374.563%
EthereumEthereum
2,026.184.598%
Binance CoinBinance Coin
638.364.309%
CardanoCardano
0.25873.771%
RippleRipple
1.37312.463%

Subscribe to Updates

Get the latest cryptocurrency news and insights delivered directly to your inbox.