bZx Hack

TOTAL LOST $356K
Low Flash Loan Attack ethereum

Summarize with AI

Affected Chain ethereum Incident surface
Recovered - No recovery reported
All-Time Rank #1098 By amount stolen
Auditors 3 Prior security audits

Incident Overview

The transaction behind the attack:

https://etherscan.io/tx/0xb5c8bd94…219838

The attacker's address:

https://etherscan.io/address/0x148426fd…491ad0

The attacker:

- flash loaned 10,000 ETH from the dYdX exchange

- with the borrowed flash loan, the attacker deposited 5,500 ETH into Compound as collateral to borrow 112 WBTC

- Deposited 1300 ETH and called bZx margin trading function, i.e., mintWithEther (that cascadingly invokes marginTradeFromDeposit). The margin trading function leveraged KyberSwap to swap the borrowed 5637.623762 ETH for 51.345576 WBTC in return. Notice that it is 5x borrow to short ETH. The swap essentially drove up the conversion rate of 1 WBTC to around 109.8 WETH, roughly triple the normal conversion rate (~38.5 WETH/WBTC)

- with the spiked WBTC price on Uniswap, the attacker sold the Compound-borrowed 112 WBTC back for WETH on Uniswap. This dump step leads to the net of 6871.4127388702245 ETH in return with the overall conversation rate of 1WBTC=61.4 WETH

- With the netted 6871.4127388702245 ETH from the dumped 112 WBTC, the attacker repaid the flash loan 10000.000000000011ETH back to dYdX.

Incident Report

Protocol / Project bZx
Date of Incident
Affected Chain(s) ethereum
Attack Technique Flash Loan Attack
Classification Exchange (DEX),Borrowing and Lending

Protocol Information

Protocol Type Exploit/Flash Loan Attack
Affected Token BZRX
Official Website bzx.network/
Protocol Twitter/X @bzxHQ
Team Anonymous
Source Code Unverified

What the Attacker Needed to Succeed

Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.

Technical Knowledge Deep understanding of flash loan attack and Solidity and EVM internals
Capital Required Flash loan capital (borrowed atomically, zero upfront cost)
On-Chain Access Ability to interact with ethereum smart contracts and deploy a custom exploit contract
Protocol Analysis Identification of the exploitable vulnerability in bZx's contract logic - root cause: exchange (dex),borrowing and lending
Execution Speed Precise transaction ordering and timing to exploit the vulnerability within a single atomic block
Obfuscation Plan A strategy to launder and move stolen funds - typically through mixers, cross-chain bridges, or decentralized DEX swaps to resist tracing

What Auditors Should Check

Could this have been caught in audit? Yes β€” skilled auditors routinely flag Flash Loan Attack vulnerabilities in code review
Audited by ZK Labs, Certik, DeFi Safety β€” still lost $356K. Prior audits don't guarantee safety, especially after post-audit code changes.

If you're auditing a protocol with similar architecture to bZx, these are the critical security checks that could have prevented this incident (February 2020).

  • Verify all logic paths related to Flash Loan Attack are guarded by proper access controls and input validation - see the Flash Loans Attacks attack class for patterns
  • Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs

Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.

Free Trial

Security Audit History

Related Attack Classes

The technique used in this hack maps to these vulnerability classes in our security curriculum:

See all Flash Loans Attacks examples β†’

Sources & References

Learn to Prevent the Next bZx

The bZx hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.

Recreate exploit patterns safely Free Trial