COMING SOON: A New Way to Earn Passive Income with DeFi in 2025 LEARN MORE

bZx protocol loses estimated $8M in another bug exploit

In this post:

bZx protocol has once again been compromised as a supposed bug in the iTokens duplication method was exploited and reportedly resulted in the loss of funds. However, the team behind the decentralized finance (DeFi) lending protocol has patched out the flaw, assuring that users’ funds are not at risk. Notably, this recent incident marks the third time bZx has been hacked this year. 

bZx protocol’s TVL drop

On Sunday, a bug was reported on bZx iToken duplication method, which enabled a hacker to artificially inflate their balance. As the co-founder of 1inch.Exchange, Anton Bukov shared on Twitter a post showing 101778 $iETH tokens (worth ~4.7K ETH) that were duplicated on bZx protocol in about nine different transactions. The tokens were worth $1,724,900 following the current price of ETH at $367. 

The bZx team began investigating the duplication incident as the protocol’s total value locked (TVL) started dropping suddenly. They could learn about the duplication incident with several of the iTokens, and immediately stopped activities on the protocol such as lending and unlending temporarily. After a heavy auditing of bZx protocol by top security firms Peckshield and Certik, the faulty duplication method was patched out of the iToken contract code.

Overall, the total value lost in bZx protocol during the incident is reportedly about $8 million. The team assured that the stolen funds have been debited from the insurance funds, hence, customers need not to close their loans as “no funds are currently at risk.” Meanwhile, the funds added to the insurance fund include 219,199.66 LINK, 4,502.70 ETH, 1,756,351.27 USDT, 1,412,048.48 USDC, 667,988.62 DAI.

See also  US DOJ considers fairer repayment standards for crypto fraud victims

bZx hack could have been prevented

A Twitter user @MarcThalen first discovered the bug and reported it to bZx team; however, they did not respond on time. 

“Last night I found an exploit in BRZX. I noticed that users were capable of duplicating “i tokens”. There was 20+ million $ at risk. I informed the team telling them to stop the protocol and explained the exploit to them. At this point none of the founders were up..”

He added:

“After a while the admin I was talking to told me that he finally got a hold of the team and was passing the info I was giving them through to them. At this point the attacker I noticed had drained substantial amounts of Dai and USDC.”

Cryptopolitan Academy: Tired of market swings? Learn how DeFi can help you build steady passive income. Register Now

Share link:

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Most read

Loading Most Read articles...

Stay on top of crypto news, get daily updates in your inbox

Editor's choice

Loading Editor's Choice articles...

- The Crypto newsletter that keeps you ahead -

Markets move fast.

We move faster.

Subscribe to Cryptopolitan Daily and get timely, sharp, and relevant crypto insights straight to your inbox.

Join now and
never miss a move.

Get in. Get the facts.
Get ahead.

Subscribe to CryptoPolitan