DeFi lending agreement bZx suffers a mysterious attack, losing hundreds of thousands of dollars

News on February 15th, bZx, an open financial (DeFi) lending protocol, was attacked, causing some ETH to have been lost.

According to bZx co-founder Kyle Kistner, although the amount of ETH currently lost is unknown, the loss does exist.

Kistner revealed some details in the bZx official telegram group, saying that a contract loophole was exploited by the attacker. The company has currently suspended the contract, while the loan contract and cancellation contract are still running.

As for the details of the vulnerability, bZx is still consulting with security researchers to understand the problem, Kistner added:

"We will publish a deeper profiling report, and the remaining funds are safe."

Due to the impact of the vulnerability, bZx has suspended its Fulcrum trading platform and is currently under maintenance.

3

According to DeFi Pulse data, users have taken 3300 ETH (about $ 932,000) from the bZx protocol in the past 24 hours.

Following the incident, DeFi observer Chris Blec commented:

"Early unproven theory holds that this is not a smart contract hack, but that someone has used oracle (possibly using fast loans) for some kind of radical market manipulation.

Another observer, Paranoid Individual, agrees, saying:

"After a quick investigation, my opinion is that someone attacked bZx through an oracle vulnerability. The news is good or bad, depending on where you are right now."

Analyst Alex gave his specific judgment:

"Recall what the attackers did:

  1. The attacker borrowed 10,000 ETH from dydx using a fast loan;
  2. He put 50% of it in compound and the remaining 50% in bZx (fulcrum uses bZx protocol);
  3. He borrowed 112 WBTC (Bitcoin Anchor Coin from ERC20) from compound;
  4. He shorted WBTC at bZw;
  5. He threw 112 WBTC in uniswap, probably to drive down prices;
  6. Return 10,000 ETH borrowed from dydx;
  7. The original contract had $ 1 million worth of eth in the compound and $ 650,000 of WBTC debt, so the attacker had a profit of about $ 350,000;

" 4

(Figure: Operation records of the attacker )

What do you think?

We will continue to update Blocking; if you have any questions or suggestions, please contact us!

Share:

Was this article helpful?

93 out of 132 found this helpful

Discover more

Blockchain

Long Push Receiving 1 million ARB airdrop, Summary and Reflections on 2 Years in the Circle

Note This article is from @0xfarmer_ on Twitter, summarized by MarsBit as follows Time flies. I have finished my subs...

Blockchain

FTX Bankruptcy Estate Bets Big $150 Million SOL and ETH on the Line as Sam Bankman-Fried's Trial Unfolds

It seems that addresses associated with the insolvent cryptocurrency exchange, which is currently being managed by a ...

Blockchain

Three major domestic virtual currency exchanges focus on compliance business and actively engage with local governments and state-owned enterprises

China Times (www.chinatimes.net.cn) reporter Ran Xuedong trainee reporter An Lingfei Beijing reports The currency cir...

Blockchain

Research Report | Blockchain Economics Panorama and Future: Exchange Compliance

Author: BlockVC industry research team Source: BlockVC Editor's Note: The original title is "Postal Chain E...

Blockchain

Demystify Bybit's new product "black technology", you can open both long and short, insurance contracts!

If you have seen Jobs's Apple conference, Rebus' Xiaomi conference, or Lao Luo's wee phone conference....

Blockchain

Has the long-standing resentment towards VC finally erupted? After falling out with LianGuairadigm, Reflexer bought back tokens and put on a mocking face.

This year, you can earn substantial profits from cryptocurrency, all coming from self-reliant projects without ventur...