Defi Protocol Bzx Loses $8.1 Million in Third Hack This Year

Defi Protocol Bzx Loses $8.1 Million in Third Hack This Year

Marc Thalen, lead engineer at Bitcoin.com, first discovered the vulnerability in the smart contracts and reported it to Bzx, warning $20 million was at risk.

In a statement, Bzx co-founder Kyle Kistner said that the defective code permitted an attacker to duplicate assets or even increase the balance of the protocol’s interest-bearing token called iTokens.

Bzx noticed the security breach some hours later and immediately halted minting and burning of iTokens. Trading resumed after a fix that corrected the balances and duplications.

Kistner detailed that investor funds faced no risk as they were promptly compensated. He said:

No funds are at risk. Due to a token duplication incident, the protocol insurance fund has transiently accrued a debt. The insurance fund is backstopped by both the token treasury in addition to protocol cash flows.

Thalen exploited the faulty code himself, generating a loan of 100 USDC. “From this I retrieved iUSDC. I then sent this to myself practically duplicating the funds. I then created a claim for 200 USD,” he tweeted.

Two audit firms, Peckshield and Certik, failed to pick up the flawed smart contracts code. Peckshield responded, saying: “One audit cannot guarantee to find all potential issues, but with continuous work from developers and auditors, we are getting ever closer to the goal of minimizing security risks.”

This is the third time that Bzx has been attacked in 2020. Two separate attacks in February cost the protocol just under $1 million. Founded in 2017, Bzx is a decentralized protocol built on the Ethereum blockchain for lending and trading with margin and leverage.

What do you think about the recurring hacks at Bzx? Let us know in the comments section below.

The post Defi Protocol Bzx Loses $8.1 Million in Third Hack This Year appeared first on Bitcoin News.

 

source: https://news.bitcoin.com/defi-protocol-bzx-loses-8-1-million-in-third-hack-this-year/

TheBitcoinNews.com is here for you 24/7 to keep you informed on everything crypto. Like what we do? Tip us some BATSend Tip now!

Share your thoughts, add a comment!

You must be logged in in order to place a comment.

Article comments

Loading...
No comments yet, be the first to comment this article