Compartilhe este artigo

DeFi Lender bZx Loses $8M in Third Attack This Year

An attacker found a way to mint unbacked iTokens that they could then redeem against other cryptos held in lending pools for DeFi lender bZx.

Atualizado 14 de set. de 2021, 9:55 a.m. Publicado 14 de set. de 2020, 9:58 a.m. 2 min readTraduzido por IA
(Shutterstock)

Decentralized finance (DeFi) protocol bZx has fallen victim to yet another attack after a bug in its code allowed someone to mint tokens they redeemed for cryptocurrencies on the protocol.

  • Co-founder Kyle Kistner told CoinDesk the company noticed something was wrong on Sunday when a single LINK withdrawal led to a $2.6 million drop in the protocol's total value locked (TVL).
  • The attack basically centered around the protocol's interest-earning iToken that users receive and redeem for crypto deposited into lending pools.
  • Kistner said the attacker exploited a bug that tricked bZx into minting unbacked iTokens subsequently exchanged for cryptocurrencies held in the pools.
  • Per an incident report Sunday, the attacker managed to steal just under 220,000 LINK tokens, 4,507 ETH, 1.76 million USDT, 1.4 million USDC and 670,000 DAI.
  • At current spot prices, this works out as a loss of just over $8 million.
  • That's much more than the $630,000 and $350,000 hacks the protocol suffered in February, which both manipulated oracle price feeds in order to pay back bZx loans for far less than the actual amount.
  • bZx paused the protocol in the aftermath of Sunday's attack so the bug could be patched, and resumed operations hours later.
  • Kistner said the decision was taken in consultation with security experts, who had not instructed the company to shut down for any longer.
  • He added the $8 million lost had already been debited by the protocol's insurance fund and will be paid out once the bZx community had ratified it.
  • The bug managed to remain undetected in two extensive code audits from cybersecurity firms Certik and Peckshield.
  • Kistner declined to comment on the identity of the hacker.

See also: DeFi Project dForce Refunds All Affected Users After $25M Hack

More For You

(Anna Webber/Getty Images for Inc. at Inc. Founders House at SXSW)

The billionaire investor said he sold most of his bitcoin after concluding the cryptocurrency failed to act as a hedge during recent geopolitical turmoil and dollar weakness.

What to know:

  • Mark Cuban said he has sold most of his bitcoin holdings after concluding it failed to act as a hedge against a weakening dollar and geopolitical turmoil, particularly during the recent Iran conflict.
  • The billionaire investor, who once described bitcoin as a superior version of gold and held a crypto...