bZx Hack
Incident Overview
The transaction behind the attack:
https://etherscan.io/tx/0xb5c8bd94β¦219838
The attacker's address:
https://etherscan.io/address/0x148426fdβ¦491ad0
The attacker:
- flash loaned 10,000 ETH from the dYdX exchange
- with the borrowed flash loan, the attacker deposited 5,500 ETH into Compound as collateral to borrow 112 WBTC
- Deposited 1300 ETH and called bZx margin trading function, i.e., mintWithEther (that cascadingly invokes marginTradeFromDeposit). The margin trading function leveraged KyberSwap to swap the borrowed 5637.623762 ETH for 51.345576 WBTC in return. Notice that it is 5x borrow to short ETH. The swap essentially drove up the conversion rate of 1 WBTC to around 109.8 WETH, roughly triple the normal conversion rate (~38.5 WETH/WBTC)
- with the spiked WBTC price on Uniswap, the attacker sold the Compound-borrowed 112 WBTC back for WETH on Uniswap. This dump step leads to the net of 6871.4127388702245 ETH in return with the overall conversation rate of 1WBTC=61.4 WETH
- With the netted 6871.4127388702245 ETH from the dumped 112 WBTC, the attacker repaid the flash loan 10000.000000000011ETH back to dYdX.
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to bZx, these are the critical security checks that could have prevented this incident (February 2020).
- Verify all logic paths related to Flash Loan Attack are guarded by proper access controls and input validation - see the Flash Loans Attacks attack class for patterns
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialRelated Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Sources & References
Learn to Prevent the Next bZx
The bZx hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.