bZx Hack

TOTAL LOST $356K
Low Flash Loan Attacks Ethereum

What happened

On February 15, 2020, an attacker used a 10,000 ETH dYdX flash loan to exploit bZx/Fulcrum's margin-trading execution path. A highly price-impacting Kyber order routed through thin Uniswap liquidity left the resulting WBTC position undercollateralized, allowing the attacker to arbitrage the distorted price and repay the flash loan in one transaction. Contemporary estimates put the attacker's gain near $356,000, while the pool's equity shortfall was reported higher.

This was separate from bZx's later February sUSD oracle attack.

Technical Root Cause

The margin-trade path allowed an extreme price-impacting trade to open an undercollateralized position because a conditional path bypassed the intended `shouldLiquidate` health check.

Case & protocol details

Classification Slippage and position-health validation failure
Protocol Type Exploit/Flash Loan Attack
Affected asset / contract BZRX
Official Website bzx.network/
Protocol Twitter/X @bzxHQ

Attack Timeline

The attacker flash-borrowed 10,000 ETH, used 5,500 ETH as Compound collateral to borrow 112 WBTC, and used 1,300 ETH to open a 5x Fulcrum ETH/WBTC short. Fulcrum routed a 5,637 ETH order through thin Uniswap liquidity and received only about 51 WBTC, making the position severely undercollateralized. The attacker then sold the Compound-borrowed WBTC into that distorted market, repaid the flash loan, and retained the economic benefit.

A healthy-position check that should have rejected the trade did not run on this path. The flash loan supplied temporary capital; ineffective slippage and position-health validation created the loss.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.