bZx Hack

REPORTED LOSS $47.6M
High Compromised administrative key bsc polygon

What happened

On November 5, 2021, a phishing email with a malicious Word macro compromised a bZx developer’s mnemonic and the administrative keys for bZx’s Polygon and BSC deployments. The attacker used that authority to take over the deployments and drain protocol assets and token balances protected only by unlimited approvals. Ethereum’s DAO-controlled deployment was unaffected.

Technical Root Cause

A single developer credential controlled upgrade and withdrawal authority for deployed contracts. Once compromised, that credential authorized administrative actions; broad unlimited token approvals expanded the loss surface.

Case & protocol details

Classification Borrowing and Lending
Protocol Type Exploit/Access control
Affected asset / contract BZRX
Official Website bzx.network/
Protocol Twitter/X @bzxHQ

How it happened

The malicious attachment compromised the developer’s mnemonic and exposed BSC and Polygon deployment keys. The attacker then used privileged ownership-transfer and upgrade paths to control the affected deployments, drain their assets, and transfer tokens from users who had granted unlimited allowance. This was a key-compromise incident, not a defect in the Ethereum protocol deployment.

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.