bZx Hack
What happened
On November 5, 2021, a phishing email with a malicious Word macro compromised a bZx developer’s mnemonic and the administrative keys for bZx’s Polygon and BSC deployments. The attacker used that authority to take over the deployments and drain protocol assets and token balances protected only by unlimited approvals. Ethereum’s DAO-controlled deployment was unaffected.
A single developer credential controlled upgrade and withdrawal authority for deployed contracts. Once compromised, that credential authorized administrative actions; broad unlimited token approvals expanded the loss surface.
Case & protocol details
How it happened
The malicious attachment compromised the developer’s mnemonic and exposed BSC and Polygon deployment keys. The attacker then used privileged ownership-transfer and upgrade paths to control the affected deployments, drain their assets, and transfer tokens from users who had granted unlimited allowance. This was a key-compromise incident, not a defect in the Ethereum protocol deployment.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.