{"id":28612,"date":"2020-09-14T12:40:24","date_gmt":"2020-09-14T09:40:24","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=28612"},"modified":"2025-08-27T12:30:36","modified_gmt":"2025-08-27T09:30:36","slug":"defi-platform-bzx-loses-8-million-in-another-attack","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/defi-platform-bzx-loses-8-million-in-another-attack\/","title":{"rendered":"DeFi platform bZx loses $8 million in another attack"},"content":{"rendered":"<p>The DeFi platform bZx has been hacked for the third time this year. This time an unidentified attacker withdrew around $8 million.<!--more--><\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">\u26a0\ufe0f \ud83d\udce2 UPDATE:<\/p>\n<p>1\/ At 3:28 AM EST we began investigating a drop in the protocol TVL. By 6:18 AM EST we confirmed that a duplication incident had occurred with several of the iTokens.<\/p>\n<p>\u2014 bZx (@bZxHQ) <a href=\"https:\/\/twitter.com\/bZxHQ\/status\/1305189177730891776?ref_src=twsrc%5Etfw\">September 13, 2020<\/a><\/p>\n<\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>The attacker exploited buggy code that allowed him to duplicate assets. The platform suspended deposits and withdrawals a few hours after the attack.<\/p>\n<blockquote>\n<p>&#8220;The duplication method has been fixed in the iToken contract code, and the protocol has resumed normal operation,&#8221; the statement said.<\/p>\n<\/blockquote>\n<p>Representatives of bZx issued a separate <a href=\"https:\/\/bzx.network\/blog\/incident\" target=\"_blank\" rel=\"noopener noreferrer\">report<\/a> with details of the withdrawn amounts: 219 200 LINK (~$2.6 million), 4502 ETH (~$1.64 million), 1.7 million USDT, 1.4 million USDC and 667 989 DAI. The total loss was about $8 million.<\/p>\n<p>Representatives of the project pledged to reimburse users from the insurance fund. They said there is no need to withdraw assets.<\/p>\n<p>The native token of the platform tumbled almost 40% after the hack \u2014 from $0.68 to $0.42. At the time of writing, the token was trading around $0.45 (<a href=\"https:\/\/www.coingecko.com\/en\/coins\/bzx-protocol\" target=\"_blank\" rel=\"noopener noreferrer\">CoinGecko<\/a>).<\/p>\n<div id=\"attachment_109976\" style=\"width: 792px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-109976\" class=\"wp-image-109976 size-full\" src=\"https:\/\/u1f987.com\/wp-content\/uploads\/Untitled-1-19.jpg\" alt=\"The DeFi platform bZx lost $8 million due to another attack\" width=\"782\" height=\"528\" srcset=\"https:\/\/u1f987.com\/wp-content\/uploads\/Untitled-1-19.jpg 782w, https:\/\/u1f987.com\/wp-content\/uploads\/Untitled-1-19-300x203.jpg 300w, https:\/\/u1f987.com\/wp-content\/uploads\/Untitled-1-19-768x519.jpg 768w\" sizes=\"auto, (max-width: 782px) 100vw, 782px\" \/><\/p>\n<p id=\"caption-attachment-109976\" class=\"wp-caption-text\">Source: CoinGecko.<\/p>\n<\/div>\n<p><strong>UPDATE:<\/strong><\/p>\n<p>On Monday, September 14, bZx said they had returned all stolen funds; the team promised to disclose details later.<\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"en\">\n<p dir=\"ltr\" lang=\"en\">\ud83d\udce2 UPDATE:<\/p>\n<p>We are relieved to announce that the missing funds are now restored. More information will follow.<\/p>\n<p>Stay tuned!<\/p>\n<p>\u2014 bZx (@bZxHQ) <a href=\"https:\/\/twitter.com\/bZxHQ\/status\/1305496675474006017?ref_src=twsrc%5Etfw\">September 14, 2020<\/a><\/p>\n<\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>According to <a href=\"https:\/\/twitter.com\/CoinDesk\/status\/1305537078348918786\" target=\"_blank\" rel=\"noopener noreferrer\">CoinDesk<\/a>, the attacker returned the assets worth $8 million after DeFi platform specialists traced them with on-chain analytics.<\/p>\n<p>Earlier, the first attack on the DeFi platform occurred in mid-February, when the bZx team participated in the ETHDenver hackathon. The attacker withdrew 1,193 ETH ($350,000), or roughly 2% of the total asset base.<\/p>\n<p>Two days later, unknown parties attacked the platform again. The losses were estimated at 2,388 ETH ($645,000).<\/p>\n<p>Follow ForkLog news on VK!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The DeFi platform bZx has been hacked for the third time this year. This time an unknown attacker withdrew around $8 million.<\/p>\n","protected":false},"author":1,"featured_media":28613,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1935,1154,1093],"class_list":["post-28612","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-bzx","tag-crimes","tag-defi"],"aioseo_notices":[],"amp_enabled":true,"views":"25","promo_type":"1","layout_type":"","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/28612","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=28612"}],"version-history":[{"count":1,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/28612\/revisions"}],"predecessor-version":[{"id":28614,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/28612\/revisions\/28614"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/28613"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=28612"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=28612"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=28612"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}