·

DeFi lending protocol bZx exploit leads to a $1 million loss

DeFi lending protocol bZx exploit leads to a $1 million loss

bZx, a DeFi lending protocol, was hit with a series of exploits. The attacks resulted in the loss of 3,581 ETH worth nearly $1 million.

A series of unfortunate events

On Feb. 14, the bZx team was alerted about a suspicious transaction that allowed the perpetrator to net a whopping $300,000 in profits.

Julien Bouteloup, founder of DeFi investment firm Stake Capital, explained that a smart trader under the pseudonym dYdX took a 10,000 ETH flash loan to borrow 112 wrapped BTC (wBTC) from Compound. Witht the rest of the loan he was able to open a 5x short position against the “ETHBTC ratio” on Fulcrum.

Then, the individual went into Uniswap to swap 51 wBTC. These series of events caused a “large slippage” allowing the trader to exit his short position at profit and pay back the initial loan with the proceeds.

Julien Bouteloup explains bZx exploit
Source: Twitter

Following the exploit, bZx issued a statement claiming that users funds were not affected. The team also vowed to implement multiple upgrades to ensure that this type of incidents do not happen again.

bZx stated:

“We have made the following upgrades using the administrator key to prevent this attack from occurring again. First, we addressed the condition that prevented the check from firing in the first place by requiring the check to take place even in the case of overcollateralized loans. Second, the ETHBTC margin tokens were delisted from the oracle token registry. Third, we implemented maximum trade sizes to limit the possible scope of any attack.”

The different upgrades were targeting multiple vulnerabilities on the DeFi lending protocol. However, a second attack took place shortly after the system update. This time the trader took advantage of the protocol’s own flash loans. He was able to walk away with 2,388 ETH.

Larry Cermak, director of research at The Block, said that the attacker took out a flash loan of 7,500 ETH to buy sUSD at a price close to $1 and deposited the funds on bZx to use as collateral. Then, the individual used 900 ETH to market buy sUSD on Kyber and Uniswap pushing the price to over $2.

Once sUSD went up, the trader borrowed nearly 6,800 ETH against sUSD on bZx and repaid the flash loan. In the end, the anonymous attacker was able to profit approximately $645,000.

Larry Cermak explains bZx exploit
Source: Twitter

bZx maintains that the second exploit is the result of an “oracle manipulation attack”. Nonetheless, the team was able to “delay the realization of the loss”. This could allow the system to recover from this incident.

These series of unfortunate events have opened up discussion in the crypto community regarding the high levels of centralization in DeFi applications and the danger of flash loans.

Posted In: , Hacks, Lending & Borrowing

The above advertisement is an referral link.

Invest with AMFEIX

Like what you see? Subscribe to CryptoSlate

Get our daily newsletter containing the top blockchain stories and crypto analysis straight to your inbox.

Sign up to stay informed
Ali Martinez
Author

Ali Martinez

Technical Analyst @ CryptoSlate

After Ali began forex trading in 2012 In 2014, he came across Bitcoin’s whitepaper and was so fascinated by the idea of a decentralized, borderless, and censorship-resistant currency that he started buying Bitcoin. By 2015, he started traveling to spread the word about Bitcoin.

View author profile

Commitment to Transparency: The author of this article is invested and/or has an interest in one or more assets discussed in this post. CryptoSlate does not endorse any project or asset that may be mentioned or linked to in this article. Please take that into consideration when evaluating the content within this article.

Disclaimer: Our writers' opinions are solely their own and do not reflect the opinion of CryptoSlate. None of the information you read on CryptoSlate should be taken as investment advice, nor does CryptoSlate endorse any project that may be mentioned or linked to in this article. Buying and trading cryptocurrencies should be considered a high-risk activity. Please do your own due diligence before taking any action related to content within this article. Finally, CryptoSlate takes no responsibility should you lose money trading cryptocurrencies.