February 18, 2020 marked a watershed moment for decentralized finance when bZx, an Ethereum-based lending protocol, was exploited for the second time in a single week. The attacker made off with approximately $630,000 worth of ether, exposing critical vulnerabilities in the nascent DeFi ecosystem and raising urgent questions about the security of flash loan mechanisms, oracle reliability, and the broader robustness of decentralized financial infrastructure.
TL;DR
- bZx exploited for the second time in one week, losing $630,000 worth of ETH
- The attacker used flash loans to manipulate price feeds on bZx’s Fulcrum lending platform
- The first attack, days earlier, netted approximately $350,000 in profit
- Flash loans from dYdX provided the attacker with 10,000 WETH (roughly $3 million) with zero upfront capital
- The incidents sparked industry-wide debate about DeFi security standards and oracle design
How Flash Loans Enabled the Attack
The bZx exploits represented the first major real-world demonstration of flash loan attacks in decentralized finance. Flash loans, a feature unique to DeFi, allow users to borrow enormous sums of cryptocurrency with no collateral — provided the loan is repaid within the same transaction. If the loan is not repaid, the entire transaction is reversed as if it never happened.
In the second attack on February 18, the attacker borrowed a massive amount of Wrapped ETH (WETH) through a flash loan from the dYdX lending platform. The borrowed capital — approximately 10,000 WETH, worth around $3 million at the time — was then used to manipulate the price feed on Fulcrum, bZx’s lending portal. By exploiting a vulnerability in the way Fulcrum relied on a single price oracle, the attacker was able to open significantly under-collateralized positions and extract $630,000 in ether before the transaction completed and the flash loan was repaid.
The second attack was technically distinct from the first. While the initial exploit on February 15 involved manipulating Kyber Network’s reserves to profit from price discrepancies, the February 18 attack centered on swapping ethereum for Synthetix USD (sUSD), a synthetic dollar-pegged stablecoin, to further distort price feeds.
bZx’s Response and Industry Fallout
Kyle Kistner, bZx’s chief visionary officer and operations lead, acknowledged the attack on the project’s Telegram channel, describing the flash loan hack as “completely tractable” — suggesting the vulnerability could have been prevented with better oracle design and price feed redundancy.
The back-to-back exploits sent tremors through the broader DeFi community. Total value locked in DeFi protocols at the time was still measured in the hundreds of millions rather than the billions it would later reach, and the bZx incidents demonstrated that even well-audited smart contracts could harbor exploitable design flaws when they interacted with other protocols in unexpected ways.
The attacks also ignited a fierce debate within the Ethereum community about whether flash loans themselves were the problem, or whether the real issue lay in protocols that relied on single-source price oracles and failed to implement adequate safeguards against manipulation.
The Broader DeFi Security Landscape
The bZx incidents were among the earliest examples of what would become a recurring pattern in DeFi: composability — the ability of different protocols to interact with one another — creating emergent vulnerabilities that were difficult to anticipate during individual protocol audits. An attacker could chain together interactions across multiple platforms (dYdX for flash loans, Kyber for swaps, bZx for lending) in a single atomic transaction, exploiting the interconnected nature of the ecosystem.
With Bitcoin trading at approximately $10,142 and Ethereum at $281.94 on the day of the second attack, the broader cryptocurrency market remained relatively stable despite the DeFi-specific disruption. However, the incidents underscored a fundamental tension in the rapidly growing DeFi space: the pursuit of permissionless, composable financial infrastructure was moving faster than the security frameworks needed to protect it.
Why This Matters
The bZx flash loan attacks of February 2020 were a defining moment for decentralized finance. They demonstrated that DeFi’s greatest strength — the ability to compose financial instruments from modular, interoperable protocols — was also its greatest vulnerability. The attacks catalyzed a wave of security improvements across the ecosystem, including the adoption of decentralized oracle networks like Chainlink, the implementation of time-weighted average price (TWAP) feeds, and more sophisticated circuit breakers. The lessons learned from bZx would prove invaluable as DeFi grew from hundreds of millions to hundreds of billions in total value locked. Yet the fundamental tension between innovation speed and security rigor remains at the heart of every DeFi protocol built today.
Disclaimer: This article is for informational purposes only and does not constitute financial advice. Cryptocurrency and DeFi investments carry significant risk. Always conduct your own research before making investment decisions.
bZx getting hit twice in one week using the same flash loan vector from dYdX. first was 350K then 630K. they literally did not fix the oracle after the first attack
appreciate the deeper analysis. most coverage just said flash loan bad without explaining the oracle price feed manipulation
this was the template for every DeFi exploit that followed. manipulate oracle, profit, repeat
the oracle manipulation angle is what made bZx different from a normal hack. it exposed that price feeds were the weakest link in DeFi
the oracle manipulation part still keeps me up at night. price feeds were the blind spot nobody saw coming
defi_lesson_learnt kyber and uniswap both patched their oracle logic within a month. bZx sat on the same code for two weeks between hits. inexcusable even for 2020
dYdX providing 10,000 WETH for the attack is wild. Lending protocols enabling attacks on other lending protocols.
Wei C. dYdX flash loans were designed exactly for this kind of atomic borrowing. blaming them is like blaming a bank for issuing a loan that gets spent at a casino
10k WETH with zero upfront capital was the degen dream and the degen nightmare simultaneously. DeFi composability cut both ways from day one
dydx didnt do anything wrong technically. flash loans were a feature. the failure was bZx not having any oracle safeguards against rapid price swings
DeFi_forensics bZx had every chance to add a delay on their oracle after the FIRST attack. they did nothing and lost another 630k. negligence plain and simple
DeFi_forensics the price feed manipulation is what made bZx fundamentally different. it wasnt a hack it was a design flaw every lending protocol shared
DeFi_forensics price feed manipulation made bZx fundamentally different. it wasnt a hack it was a design flaw every lending protocol shared back then
flash loans were brand new and nobody had thought through the attack vectors yet. dYdX wasnt negligent, the entire space was naive
the entire space was flying blind on composability risks. bZx was just the first to learn the hard way
borrowing 10000 WETH from dYdX with zero collateral and manipulating the price feed on Fulcrum. brilliant and terrifying at the same time. DeFi was truly the wild west in 2020
two attacks in one week and bZx still kept operating. that protocol survived purely on 2020 bull market vibes. any modern project would be dead on arrival after this
350K first attack then 630K second. the team had days to fix the oracle and still got hit again. textbook example of why security audits matter more than TVL
flashloan_truther_ dYdX actually added post-hoc screening after this. too late for bZx but at least the next wave of lending protocols had some guardrails. barely
two attacks in one week using the same flash loan vector. the bZx team basically watched the first exploit happen and still didnt patch
still salty about that bZx hack. lost my entire stack trying to arbitrage the price difference before realizing it was an exploit
^ this is exactly why i never trust lending protocols that dont have circuit breakers
flash_loan_survivor trying to arb during an active exploit is peak degen lol. picking up pennies in front of a steamroller is the classic description
reading this in 2026 and its wild how naive the space was about composability risks in 2020. every protocol was copy paste code with zero defense against cross protocol attacks
reading this in 2026 and its wild how naive the space was about composability risks in 2020. copy paste code everywhere with zero cross protocol defense
bZx getting hit twice in one week was the moment DeFi realized flash loans were a weapon not just a feature. the oracle manipulation playbook was born here
two attacks in one week and bZx kept operating. any modern protocol would be dead on arrival after that. 2020 bull market was forgiving
borrowing 10000 WETH from dYdX with zero collateral was wild. the attacker literally needed nothing but a smart contract to drain $630k
Pavel S. the real issue was bZx using a single price feed. one manipulated Uniswap pool and the whole protocol imploded. TWAP oracles came directly from this exploit
the real issue was bZx relying on a single Uniswap price feed. one manipulated pool and the whole protocol imploded. TWAP oracles were born from this