Share this article

Exploit During ETHDenver Reveals Experimental Nature of Decentralized Finance

A $350,000 hack casts light on the problem of depending on single price oracles.

Updated Sep 13, 2021, 12:18 p.m. Published Feb 15, 2020, 9:00 p.m.
AFTER THE HACK: DeFi protocol bZx's booth sits empty at ETHDenver. (Photo by John Biggs for CoinDesk)
AFTER THE HACK: DeFi protocol bZx's booth sits empty at ETHDenver. (Photo by John Biggs for CoinDesk)

DENVER – Decentralized finance (DeFi) project bZx has suffered an attack in which a hacker successfully gamed multiple DeFi protocols to extract $350,000 from the platform, about 2 percent of the assets under management.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters

In response, the company took down its lending and trading protocol Fulcrum at 7:00 UTC. The company was presenting at ETHDenver during the hack. The hackers took advantage of the company's pricing oracle to trick the protocol into giving up the cash. bZx depended on only one oracle for pricing, according to sources.

The firm, which has yet to reappear at EthDenver, later confirmed in a tweet it will compensate lenders for potential losses.

The attack could be symptomatic of a continuing issue in DeFi, said Chainlink CEO Sergey Nazarov at the event: how to source price information.

The attack was even more notable because of its timing as the team had to deal with the hack during the ethereum community’s EthDenver hackathon, which largely focuses on DeFi.

bZx stickers at ETHDenver. (Photo by John Biggs for CoinDesk)
bZx stickers at ETHDenver. (Photo by John Biggs for CoinDesk)

Nazarov said sourcing price data from one oracle – services that collect and issue on-chain price information – remains problematic and one DeFi teams are still working out, although its relation to this issue has yet to be firmly established, he added.

“You can’t rely on [only] one oracle connected with an exchange API,” Nazarov said.

Staked CEO Tim Ogilvie, which operates a working relationship with bZx, said the loss amounts to an expensive bug bounty and highlights the novelty of flash loans, a new DeFi feature that allows traders to borrow and return funds in short windows the hacker leveraged for the attack.

According to Ogilvie, the attacker borrowed 10,000 ETH, worth approximately $2.67 million, in a flash loan.

The attacker then split the borrowed funds, sending 5,000 ETH to DeFi protocol Compound and the other half to bZx. After the deposits, the attacker shorted wrapped bitcoin (WBTC) on bZx quickly followed by borrowing 112 WBTC on Compound, worth about $1.1 million, and selling the borrowed WBTC on UniSwap, another DeFi market, said Ogilvie.

Ogilvie said, which the firm denied on Twitter, that bZx uses UniSwap’s price feed for WBTC. When the attacker dropped the $1.1 million worth of WBTC on UniSwap, the bZx short became extremely profitable, said Ogilvie.

“The question for DeFi is, what's safe? How do you create a safe and secure set of [price] oracles that actually do things? People use different approaches and you can choose the wrong way,” Ogilvie said.

“There are big risks. It's a new category, it's moving fast and that means some things are going to break,” Ogilvie said.

Total value locked in bZx. (Image via DeFi Pulse)
Total value locked in bZx. (Image via DeFi Pulse)

The eighth-largest DeFi market according to DeFi Pulse, 16 percent of funds locked in bZx have been withdrawn from the protocol in the past 24 hours.

More For You

Pudgy Penguins: A New Blueprint for Tokenized Culture

Pudgy Title Image

Pudgy Penguins is building a multi-vertical consumer IP platform — combining phygital products, games, NFTs and PENGU to monetize culture at scale.

What to know:

Pudgy Penguins is emerging as one of the strongest NFT-native brands of this cycle, shifting from speculative “digital luxury goods” into a multi-vertical consumer IP platform. Its strategy is to acquire users through mainstream channels first; toys, retail partnerships and viral media, then onboard them into Web3 through games, NFTs and the PENGU token.

The ecosystem now spans phygital products (> $13M retail sales and >1M units sold), games and experiences (Pudgy Party surpassed 500k downloads in two weeks), and a widely distributed token (airdropped to 6M+ wallets). While the market is currently pricing Pudgy at a premium relative to traditional IP peers, sustained success depends on execution across retail expansion, gaming adoption and deeper token utility.

More For You

Peter Thiel and Galaxy-backed Citrea wants to turn idle bitcoin into a high-speed bank account

A photo of Citrea's four co-creators (Citrea)

Founders Fund and Galaxy-backed Citrea is aiming to unlock Bitcoin-denominated credit markets with a new mainnet and a Treasury-backed stablecoin designed for USD settlement.

What to know:

  • Citrea has debuted its mainnet, enabling Bitcoin-backed lending, trading and structured products directly tied to the Bitcoin network.
  • The platform introduced ctUSD, a Treasury-backed stablecoin issued by MoonPay and designed to align with forthcoming U.S. stablecoin rules.
  • Citrea says the rollout aims to mobilize idle BTC and provide an institutional-grade settlement layer for Bitcoin-based capital markets.