HomeCoinsEthereum (ETH)DeFi protocol bZx attacked once again, lost $8 million due to a...

DeFi protocol bZx attacked once again, lost $8 million due to a faulty code

- Advertisement -


Decentralized finance (DeFi) lending protocol bZx was attacked once again last night and lost a little over $8 million due to a faulty code in its smart contracts.

The flawed code allowed an attacker to duplicate assets, or increase their balance of iTokens (interest-bearing tokens of bZx). Hours after noticing the bug, bZx paused minting and burning of iTokens and then unpaused it after a fix that corrected balances for duplications.

The bug allowed the hacker to mint 219,200 LINK tokens (worth about $2.6 million); 4,503 ETH (~$1.6 million); 1,756,351 USDT (~$1.7 million); 1,412,048 USDC (~$1.4 million) and 667,989 DAI (~$680,000). That is $8.1 million in total. bZx said no user funds are at risk as the loss is being covered by its insurance fund. 

Marc Thalen, a lead engineer at Bitcoin.com, claims to have initially identified the bug. He said more than $20 million of bZx funds were at risk. Thalen himself tried the exploit out and created a loan using USDC (100 USD). “From this I retrieved iUSDC. I then sent this to myself practically duplicating the funds. I then created a claim for 200 USD,” said Thalen. 

bZx co-founder Kyle Kistner told The Block that “it’s difficult to say” how this “critical” bug went unidentified by the protocol’s two audit firms Peckshield and Certik. The firms are preparing internal root cause analyses, said Kistner.

Peckshield said, “one audit cannot guarantee to find all potential issues,” while Certik said, “security is a journey.”

Some industry experts want bZx to halt operations and re-audit its protocol. However, Kistner told The Block that bZx security auditors “did not recommend such a course of action.”

Thalen is expecting a bug bounty from bZx. Kistner told The Block that he will be receiving a bounty of $12,500 — the average of what three panelists suggested, as Thalen reported “an ongoing incident that we had already been investigating.”

This is the third time bZx has been attacked this year. In February, the protocol lost about $945,000 in two attacks.

The latest attack has resulted in a sharp 70% decline in bZx’s total value locked (TVL) to just about $6.3 million. Kistner told The Block that “things change very quickly in this [DeFi] space,” referring to a possible upswing.

When asked how bZx plans to strengthen users’ trust amid attacks, Kistner told The Block: “We want to create products and incentive structures so attractive that users are essentially forced to use us regardless of how they feel about our brand.”

© 2020 The Block Crypto, Inc. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.





Source link

- Advertisement -
profile logo 500x500
Mr Bitcointehttps://www.bitcointe.com/
“Fact You Need To Know About Cryptocurrency - The first Bitcoin purchase was for pizza.” ― Mohsin Jameel
462FansLike
76FollowersFollow
4,567FollowersFollow
5,261FollowersFollow
1,496FollowersFollow
2,230SubscribersSubscribe

Most Popular

bitcoin
Bitcoin (BTC) $ 41,893.00
ethereum
Ethereum (ETH) $ 2,907.48
tether
Tether (USDT) $ 1.00
bitcoin-cash
Bitcoin Cash (BCH) $ 488.90
litecoin
Litecoin (LTC) $ 145.89
eos
EOS (EOS) $ 3.82
okb
OKB (OKB) $ 14.30
tezos
Tezos (XTZ) $ 6.05
leo-token
LEO Token (LEO) $ 2.70
cardano
Cardano (ADA) $ 2.12
monero
Monero (XMR) $ 235.48
stellar
Stellar (XLM) $ 0.263842
chainlink
Chainlink (LINK) $ 23.35
huobi-token
Huobi Token (HT) $ 7.74
tron
TRON (TRX) $ 0.085311
usd-coin
USD Coin (USDC) $ 1.00
dash
Dash (DASH) $ 154.39
neo
NEO (NEO) $ 37.36
iota
IOTA (MIOTA) $ 1.12
nem
NEM (XEM) $ 0.140477
zcash
Zcash (ZEC) $ 106.03
maker
Maker (MKR) $ 2,334.90
paxos-standard
Pax Dollar (USDP) $ 0.99547
ethereum-classic
Ethereum Classic (ETC) $ 45.53
vechain
VeChain (VET) $ 0.086792
true-usd
TrueUSD (TUSD) $ 1.00
ftx-token
FTX Token (FTT) $ 51.58
kucoin-shares
KuCoin Token (KCS) $ 10.34
waves
Waves (WAVES) $ 24.24