📈 Get daily crypto insights that make you smarter about your money

bZx Suffers Second Flash Loan Attack in One Week as $630,000 in Ether Drained From DeFi Protocol

February 18, 2020 marked a watershed moment for decentralized finance when bZx, an Ethereum-based lending protocol, was exploited for the second time in a single week. The attacker made off with approximately $630,000 worth of ether, exposing critical vulnerabilities in the nascent DeFi ecosystem and raising urgent questions about the security of flash loan mechanisms, oracle reliability, and the broader robustness of decentralized financial infrastructure.

TL;DR

  • bZx exploited for the second time in one week, losing $630,000 worth of ETH
  • The attacker used flash loans to manipulate price feeds on bZx’s Fulcrum lending platform
  • The first attack, days earlier, netted approximately $350,000 in profit
  • Flash loans from dYdX provided the attacker with 10,000 WETH (roughly $3 million) with zero upfront capital
  • The incidents sparked industry-wide debate about DeFi security standards and oracle design

How Flash Loans Enabled the Attack

The bZx exploits represented the first major real-world demonstration of flash loan attacks in decentralized finance. Flash loans, a feature unique to DeFi, allow users to borrow enormous sums of cryptocurrency with no collateral — provided the loan is repaid within the same transaction. If the loan is not repaid, the entire transaction is reversed as if it never happened.

In the second attack on February 18, the attacker borrowed a massive amount of Wrapped ETH (WETH) through a flash loan from the dYdX lending platform. The borrowed capital — approximately 10,000 WETH, worth around $3 million at the time — was then used to manipulate the price feed on Fulcrum, bZx’s lending portal. By exploiting a vulnerability in the way Fulcrum relied on a single price oracle, the attacker was able to open significantly under-collateralized positions and extract $630,000 in ether before the transaction completed and the flash loan was repaid.

The second attack was technically distinct from the first. While the initial exploit on February 15 involved manipulating Kyber Network’s reserves to profit from price discrepancies, the February 18 attack centered on swapping ethereum for Synthetix USD (sUSD), a synthetic dollar-pegged stablecoin, to further distort price feeds.

bZx’s Response and Industry Fallout

Kyle Kistner, bZx’s chief visionary officer and operations lead, acknowledged the attack on the project’s Telegram channel, describing the flash loan hack as “completely tractable” — suggesting the vulnerability could have been prevented with better oracle design and price feed redundancy.

The back-to-back exploits sent tremors through the broader DeFi community. Total value locked in DeFi protocols at the time was still measured in the hundreds of millions rather than the billions it would later reach, and the bZx incidents demonstrated that even well-audited smart contracts could harbor exploitable design flaws when they interacted with other protocols in unexpected ways.

The attacks also ignited a fierce debate within the Ethereum community about whether flash loans themselves were the problem, or whether the real issue lay in protocols that relied on single-source price oracles and failed to implement adequate safeguards against manipulation.

The Broader DeFi Security Landscape

The bZx incidents were among the earliest examples of what would become a recurring pattern in DeFi: composability — the ability of different protocols to interact with one another — creating emergent vulnerabilities that were difficult to anticipate during individual protocol audits. An attacker could chain together interactions across multiple platforms (dYdX for flash loans, Kyber for swaps, bZx for lending) in a single atomic transaction, exploiting the interconnected nature of the ecosystem.

With Bitcoin trading at approximately $10,142 and Ethereum at $281.94 on the day of the second attack, the broader cryptocurrency market remained relatively stable despite the DeFi-specific disruption. However, the incidents underscored a fundamental tension in the rapidly growing DeFi space: the pursuit of permissionless, composable financial infrastructure was moving faster than the security frameworks needed to protect it.

Why This Matters

The bZx flash loan attacks of February 2020 were a defining moment for decentralized finance. They demonstrated that DeFi’s greatest strength — the ability to compose financial instruments from modular, interoperable protocols — was also its greatest vulnerability. The attacks catalyzed a wave of security improvements across the ecosystem, including the adoption of decentralized oracle networks like Chainlink, the implementation of time-weighted average price (TWAP) feeds, and more sophisticated circuit breakers. The lessons learned from bZx would prove invaluable as DeFi grew from hundreds of millions to hundreds of billions in total value locked. Yet the fundamental tension between innovation speed and security rigor remains at the heart of every DeFi protocol built today.

Disclaimer: This article is for informational purposes only and does not constitute financial advice. Cryptocurrency and DeFi investments carry significant risk. Always conduct your own research before making investment decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

26 thoughts on “bZx Suffers Second Flash Loan Attack in One Week as $630,000 in Ether Drained From DeFi Protocol”

    1. the real issue was oracle manipulation, not the flash loans themselves. flash loans just made the attack capital-free

    2. dYdX enabling 10k WETH flash loans with zero checks was the real enabler here. the tool wasnt the problem, zero guardrails was

      1. flashloan_skeptic

        dYdX lending 10k WETH with no checks for flash loan attacks was wild. 2020 defi was basically security through obscurity

        1. lawless_defi zero guardrails was the entire 2020 defi ethos though. move fast, get exploited, patch, repeat. brutal learning curve

  1. two attacks in one week using the same flash loan mechanism. bZx should have paused the protocol after the first one instead of waiting to get hit again

    1. dYdX lending 10k WETH with zero collateral and trusting bZx to handle it safely. the entire DeFi security model in 2020 was just hope

      1. Olu A. the real issue was price oracle manipulation. flash loans just made it free to do. every DeFi protocol learned this lesson the hard way in 2020

    1. the first $350k exploit was the warning shot. bzx not pausing after that is the real scandal here. ego over user funds

      1. defi_safety_ $350k was the warning shot and they still didnt hit pause. thats not a bug, thats negligence. pure ego driven decision making

    2. the first attack netted $350k and they still kept everything running. no circuit breakers, no pause. pure hubris

      1. Tomasz W. keeping everything running after the first $350k hit was pure ego. any tradfi exchange would have halted instantly

      2. Tomasz W. not pausing after the first 350k was peak degen hubris. any normal financial system would have circuit breakers. 2020 defi was the wild west

  2. the real innovation from bZx wasnt the protocol it was the attack vectors it accidentally pioneered. every flash loan exploit since then borrows from this playbook

    1. Olu A. bZx basically wrote the flash loan attack textbook. every exploit since then is just a remix of what they accidentally invented

  3. zero capital exploits were wild. you could borrow millions, crash a price feed, and profit in the same tx. 2020 defi had zero guardrails

    1. mev_archaeologist2

      lawless_defi basically describes the entire 2020 defi ethos. move fast get exploited patch repeat. brutal learning curve but at least the space grew from it

  4. flash loans were never the problem. the real issue was bZx using a single oracle with no fallback. dYdX just provided the tool, bZx built the bomb

    1. Hiroshi M. single oracle with no fallback is the exact mistake every defi protocol made in 2020. bZx just happened to be the textbook case because they got hit twice in one week

  5. flashloan_archivist

    630k lost because bZx used a single oracle for price feeds. this was literally the textbook example used in every DeFi security course for the next 3 years

    1. dYdX_nostalgia_

      flashloan_archivist the attacker borrowed 10000 ETH from dYdX for zero collateral. flash loans were brand new and nobody had considered offensive use cases yet. wild time

      1. dYdX_nostalgia_ 10000 WETH with zero collateral and zero checks. flash loans were so new that nobody had even considered them as an attack vector. pure paradigm blindness

  6. Second exploit in one week and bZx kept operating. 2020 DeFi was lawless. nowadays a protocol pauses on a rumor

    1. DeFiGordon not pausing after the first 350K was the real scandal. they had a warning shot and chose ego over user funds. 2020 defi culture in a nutshell

  7. keeping the protocol running after the first 350k hit was pure ego. any real exchange halts trading on a suspected exploit. bzx treated user funds like a beta test

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$77,228.00-1.2%ETH$2,460.26-0.2%SOL$100.03-2.2%BNB$714.55-2.1%XRP$1.35-3.1%ADA$0.2091-2.0%DOGE$0.0842-2.9%DOT$1.11+0.4%AVAX$7.60-3.2%LINK$11.59-1.5%UNI$6.05-4.7%ATOM$1.80-2.8%LTC$52.39-2.0%ARB$0.1481-1.5%NEAR$2.52+1.6%FIL$0.7986-3.8%SUI$0.7409-5.2%BTC$77,228.00-1.2%ETH$2,460.26-0.2%SOL$100.03-2.2%BNB$714.55-2.1%XRP$1.35-3.1%ADA$0.2091-2.0%DOGE$0.0842-2.9%DOT$1.11+0.4%AVAX$7.60-3.2%LINK$11.59-1.5%UNI$6.05-4.7%ATOM$1.80-2.8%LTC$52.39-2.0%ARB$0.1481-1.5%NEAR$2.52+1.6%FIL$0.7986-3.8%SUI$0.7409-5.2%
Scroll to Top