📈 Get daily crypto insights that make you smarter about your money

bZx Suffers Second Flash Loan Attack in One Week as $630,000 in Ether Drained From DeFi Protocol — A Deeper Look

February 18, 2020 marked a watershed moment for decentralized finance when bZx, an Ethereum-based lending protocol, was exploited for the second time in a single week. The attacker made off with approximately $630,000 worth of ether, exposing critical vulnerabilities in the nascent DeFi ecosystem and raising urgent questions about the security of flash loan mechanisms, oracle reliability, and the broader robustness of decentralized financial infrastructure.

TL;DR

  • bZx exploited for the second time in one week, losing $630,000 worth of ETH
  • The attacker used flash loans to manipulate price feeds on bZx’s Fulcrum lending platform
  • The first attack, days earlier, netted approximately $350,000 in profit
  • Flash loans from dYdX provided the attacker with 10,000 WETH (roughly $3 million) with zero upfront capital
  • The incidents sparked industry-wide debate about DeFi security standards and oracle design

How Flash Loans Enabled the Attack

The bZx exploits represented the first major real-world demonstration of flash loan attacks in decentralized finance. Flash loans, a feature unique to DeFi, allow users to borrow enormous sums of cryptocurrency with no collateral — provided the loan is repaid within the same transaction. If the loan is not repaid, the entire transaction is reversed as if it never happened.

In the second attack on February 18, the attacker borrowed a massive amount of Wrapped ETH (WETH) through a flash loan from the dYdX lending platform. The borrowed capital — approximately 10,000 WETH, worth around $3 million at the time — was then used to manipulate the price feed on Fulcrum, bZx’s lending portal. By exploiting a vulnerability in the way Fulcrum relied on a single price oracle, the attacker was able to open significantly under-collateralized positions and extract $630,000 in ether before the transaction completed and the flash loan was repaid.

The second attack was technically distinct from the first. While the initial exploit on February 15 involved manipulating Kyber Network’s reserves to profit from price discrepancies, the February 18 attack centered on swapping ethereum for Synthetix USD (sUSD), a synthetic dollar-pegged stablecoin, to further distort price feeds.

bZx’s Response and Industry Fallout

Kyle Kistner, bZx’s chief visionary officer and operations lead, acknowledged the attack on the project’s Telegram channel, describing the flash loan hack as “completely tractable” — suggesting the vulnerability could have been prevented with better oracle design and price feed redundancy.

The back-to-back exploits sent tremors through the broader DeFi community. Total value locked in DeFi protocols at the time was still measured in the hundreds of millions rather than the billions it would later reach, and the bZx incidents demonstrated that even well-audited smart contracts could harbor exploitable design flaws when they interacted with other protocols in unexpected ways.

The attacks also ignited a fierce debate within the Ethereum community about whether flash loans themselves were the problem, or whether the real issue lay in protocols that relied on single-source price oracles and failed to implement adequate safeguards against manipulation.

The Broader DeFi Security Landscape

The bZx incidents were among the earliest examples of what would become a recurring pattern in DeFi: composability — the ability of different protocols to interact with one another — creating emergent vulnerabilities that were difficult to anticipate during individual protocol audits. An attacker could chain together interactions across multiple platforms (dYdX for flash loans, Kyber for swaps, bZx for lending) in a single atomic transaction, exploiting the interconnected nature of the ecosystem.

With Bitcoin trading at approximately $10,142 and Ethereum at $281.94 on the day of the second attack, the broader cryptocurrency market remained relatively stable despite the DeFi-specific disruption. However, the incidents underscored a fundamental tension in the rapidly growing DeFi space: the pursuit of permissionless, composable financial infrastructure was moving faster than the security frameworks needed to protect it.

Why This Matters

The bZx flash loan attacks of February 2020 were a defining moment for decentralized finance. They demonstrated that DeFi’s greatest strength — the ability to compose financial instruments from modular, interoperable protocols — was also its greatest vulnerability. The attacks catalyzed a wave of security improvements across the ecosystem, including the adoption of decentralized oracle networks like Chainlink, the implementation of time-weighted average price (TWAP) feeds, and more sophisticated circuit breakers. The lessons learned from bZx would prove invaluable as DeFi grew from hundreds of millions to hundreds of billions in total value locked. Yet the fundamental tension between innovation speed and security rigor remains at the heart of every DeFi protocol built today.

Disclaimer: This article is for informational purposes only and does not constitute financial advice. Cryptocurrency and DeFi investments carry significant risk. Always conduct your own research before making investment decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

26 thoughts on “bZx Suffers Second Flash Loan Attack in One Week as $630,000 in Ether Drained From DeFi Protocol — A Deeper Look”

  1. bZx getting hit twice in one week using the same flash loan vector from dYdX. first was 350K then 630K. they literally did not fix the oracle after the first attack

  2. appreciate the deeper analysis. most coverage just said flash loan bad without explaining the oracle price feed manipulation

    1. the oracle manipulation angle is what made bZx different from a normal hack. it exposed that price feeds were the weakest link in DeFi

      1. defi_lesson_learnt

        the oracle manipulation part still keeps me up at night. price feeds were the blind spot nobody saw coming

        1. two_week_window

          defi_lesson_learnt kyber and uniswap both patched their oracle logic within a month. bZx sat on the same code for two weeks between hits. inexcusable even for 2020

    1. Wei C. dYdX flash loans were designed exactly for this kind of atomic borrowing. blaming them is like blaming a bank for issuing a loan that gets spent at a casino

    2. 10k WETH with zero upfront capital was the degen dream and the degen nightmare simultaneously. DeFi composability cut both ways from day one

    3. DeFi_forensics

      dydx didnt do anything wrong technically. flash loans were a feature. the failure was bZx not having any oracle safeguards against rapid price swings

      1. oracle_skeptic

        DeFi_forensics bZx had every chance to add a delay on their oracle after the FIRST attack. they did nothing and lost another 630k. negligence plain and simple

      2. oracle_veteran

        DeFi_forensics the price feed manipulation is what made bZx fundamentally different. it wasnt a hack it was a design flaw every lending protocol shared

      3. DeFi_forensics price feed manipulation made bZx fundamentally different. it wasnt a hack it was a design flaw every lending protocol shared back then

    4. flash loans were brand new and nobody had thought through the attack vectors yet. dYdX wasnt negligent, the entire space was naive

      1. the entire space was flying blind on composability risks. bZx was just the first to learn the hard way

  3. borrowing 10000 WETH from dYdX with zero collateral and manipulating the price feed on Fulcrum. brilliant and terrifying at the same time. DeFi was truly the wild west in 2020

  4. two attacks in one week and bZx still kept operating. that protocol survived purely on 2020 bull market vibes. any modern project would be dead on arrival after this

  5. flashloan_truther_

    350K first attack then 630K second. the team had days to fix the oracle and still got hit again. textbook example of why security audits matter more than TVL

    1. curve_victim_2

      flashloan_truther_ dYdX actually added post-hoc screening after this. too late for bZx but at least the next wave of lending protocols had some guardrails. barely

  6. two attacks in one week using the same flash loan vector. the bZx team basically watched the first exploit happen and still didnt patch

  7. flash_loan_survivor

    still salty about that bZx hack. lost my entire stack trying to arbitrage the price difference before realizing it was an exploit

    1. flashloan_stu

      flash_loan_survivor trying to arb during an active exploit is peak degen lol. picking up pennies in front of a steamroller is the classic description

  8. defi_time_capsule

    reading this in 2026 and its wild how naive the space was about composability risks in 2020. every protocol was copy paste code with zero defense against cross protocol attacks

  9. reading this in 2026 and its wild how naive the space was about composability risks in 2020. copy paste code everywhere with zero cross protocol defense

  10. flashloan_historian

    bZx getting hit twice in one week was the moment DeFi realized flash loans were a weapon not just a feature. the oracle manipulation playbook was born here

    1. two attacks in one week and bZx kept operating. any modern protocol would be dead on arrival after that. 2020 bull market was forgiving

    2. borrowing 10000 WETH from dYdX with zero collateral was wild. the attacker literally needed nothing but a smart contract to drain $630k

      1. oracle_deficit_

        Pavel S. the real issue was bZx using a single price feed. one manipulated Uniswap pool and the whole protocol imploded. TWAP oracles came directly from this exploit

        1. the real issue was bZx relying on a single Uniswap price feed. one manipulated pool and the whole protocol imploded. TWAP oracles were born from this

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$77,228.00-1.2%ETH$2,460.26-0.2%SOL$100.03-2.2%BNB$714.55-2.1%XRP$1.35-3.1%ADA$0.2091-2.0%DOGE$0.0842-2.9%DOT$1.11+0.4%AVAX$7.60-3.2%LINK$11.59-1.5%UNI$6.05-4.7%ATOM$1.80-2.8%LTC$52.39-2.0%ARB$0.1481-1.5%NEAR$2.52+1.6%FIL$0.7986-3.8%SUI$0.7409-5.2%BTC$77,228.00-1.2%ETH$2,460.26-0.2%SOL$100.03-2.2%BNB$714.55-2.1%XRP$1.35-3.1%ADA$0.2091-2.0%DOGE$0.0842-2.9%DOT$1.11+0.4%AVAX$7.60-3.2%LINK$11.59-1.5%UNI$6.05-4.7%ATOM$1.80-2.8%LTC$52.39-2.0%ARB$0.1481-1.5%NEAR$2.52+1.6%FIL$0.7986-3.8%SUI$0.7409-5.2%
Scroll to Top