bZx Hack

TOTAL LOST $666K
Low Flash Loan Attacks ethereum

What happened

On February 18, 2020, bZx's sUSD pricing path was manipulated in a single flash-loan transaction. The attacker inflated sUSD's value in the protocol's oracle path, borrowed against overvalued collateral, and netted 2,378 ETH (about $665,840 at the time).

Technical Root Cause

bZx relied on a manipulable Kyber-routed spot price for sUSD in collateral valuation. A flash loan made it possible to distort that price and borrow more ETH than the collateral was worth at an unmanipulated rate.

Case & protocol details

Classification Oracle Manipulation
Protocol Type Exploit/Flash Loan Attack
Affected asset / contract BZRX
Official Website bzx.network/
Protocol Twitter/X @bZxHQ

Attack Timeline

The attacker borrowed 7,500 ETH through bZx, accumulated sUSD, and used Kyber-routed swaps to raise the sUSD price seen by bZx. With more than one million sUSD valued at the manipulated rate, the attacker posted it as collateral and borrowed 6,796 ETH. The flash loan was repaid in the same transaction, leaving an underwater bZx position and 2,378 ETH in profit.

The issue was not flash loans alone: a manipulable spot price was accepted as a lending valuation input.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.