DeFi protocol bZx’s booth sits empty at EthDenver (John Biggs/CoinDesk)
Decentralized finance (DeFi) project bZx has suffered an attack in which a hacker successfully gamed multiple DeFi protocols to extract $350,000 from the platform, about 2 percent of the assets under management.
In response, the company took down its lending and trading protocol Fulcrum at 7 AM UTC. The company was presenting at ETHDenver during the hack. The hackers took advantage of the company’s pricing oracle to trick the protocol into giving up the cash. bZx depended on only one oracle for pricing, according to sources.
The firm, which has yet to reappear at EthDenver, later confirmed in a tweet it will compensate lenders for potential losses.
The attack could be symptomatic of a continuing issue in DeFi: how to source price information, said Chainlink CEO Sergey Nazarov at the show. The attack was even more notable because of its timing as the team had to deal with the hack during the ethereum community’s EthDenver hackathon which largely focuses on DeFi.
bZx stickers at EthDenver via John Biggs/CoinDesk
Nazarov said that sourcing price data from one oracle, services that collect and issue on-chain price information, remains a problematic and the issue is one DeFi teams are still working out, although its relation to this issue has yet to be firmly established, he added.
“You can’t rely on [only] one oracle connected with an exchange API,” Nazarov said.
Staked CEO Tim Ogilvie, which operates a working relationship with bZx, said the loss amounts to an expensive bug bounty and highlights the novelty of flash loans, a new DeFi feature which allows traders to borrow and return funds in short windows the hacker leveraged for the attack.
According to Ogilvie, the attacker borrowed 10,000 ETH, worth approximately $2.67 million, in a flash loan.
The attacker then split the borrowed funds, sending 5,000 ETH to DeFi protocol Compound and the other half to bZx. After the deposits, the attacker shorted wrapped bitcoin (WBTC) on bZx quickly followed by borrowing 112 WBTC on Compound, worth about $1.1 million, and selling the borrowed WBTC on UniSwap, another DeFi market, said Ogilvie.
Ogilvie said, which the firm denied on Twitter, that bZx uses UniSwap’s price feed for WBTC. When the attacker dropped the $1.1 million worth of WBTC on UniSwap, their bZx short became extremely profitable, said Ogilvie.
“The question for DeFi is what’s safe? How do you create a safe and secure set of [price] oracles that actually do things. People use different approaches and you can choose the wrong way,” Ogilvie said.
“There are big risks. It’s a new category, it’s moving fast and that means some things are going to break,” Ogilvie said.
Total value locked in bZx via Defi Pulse
The eighth-largest DeFi market according to DeFi Pulse, 16 percent of funds locked in bZx have been withdrawn from the protocol in the past 24 hours.
The leader in blockchain news, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. CoinDesk is an independent operating subsidiary of Digital Currency Group, which invests in cryptocurrencies and blockchain startups.
When most people think of non-fungible tokens (NFTs), they think of their value as lying in their being unique – hence “non-fungible.” As one-off, digital representations of art, they are indivisible and non-replicable, to which people can attach value. But now there is a growing move to make NFTs usable in several different ways. This…
MARKETS Bitcoin’s (BTC) stalled recovery rally could kick off again if prices manage to beat new resistance above $4,600. The leading cryptocurrency by market valuation picked up a bid after hitting 14-month lows near $4,000 on Wednesday, possibly due to record oversold conditions reported by the 14-day relative strength index (RSI). The corrective rally, however,…
NewslettersMarketsBusinessTechPolicyIndexesTV & VideosPodcastsCrypto Explainer+EventsResearchAboutSponsored ContentNewslettersMarketsBusinessTechPolicyIndexesTV & VideosPodcastsCrypto Explainer+EventsResearchAboutSponsored ContentCrypto Prices Top Assets By DISCLOSUREThe leader in news and information on cryptocurrency, digital assets and the future of money, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. CoinDesk is an independent operating subsidiary…
Dec 18, 2019 at 14:00 UTCUpdated Dec 18, 2019 at 14:22 UTCGert Sylvest, co-founder of Tradeshift (center), image via CoinDesk archives Tradeshift Says It’s Slashed Cross-Border Transaction Costs Using EthereumSupply chain fintech startup Tradeshift, which boasts two million firms on its platform, says it's slashed the cost of cross-border transactions between buyers and suppliers using…
People want to use Augur, if only they could figure out how. The decentralized platform for prediction markets based on real-world events launched on the ethereum blockchain in July. Since then, it has generated excitement beyond the usual crypto circles due to its perceived potential as a trustless, un-censorable platform to bet on sports, forecast…
Chainlink, a blockchain data-oracle project, has made their data feeds available to developers using Polygon’s layer 2 zero-knowledge rollup.Data feeds help connect smart contracts to “real-world data such as asset prices, reserve balances, NFT floor prices and L2 sequencer health.”Developers building on Polygon’s zkEVM will be able to incorporate these data feeds into their on-chain
Apr 22, 2020 at 15:15 UTCSolar panels on Australian homes. (Credit: Shutterstock/zstock)Power Ledger will provide the blockchain technology to enable energy trading at new housing developments in Western Australia.Under a deal announced Wednesday the energy-focused startup will install its platform across 10 residential estates being built in the Perth metropolitan area by local property developer…
Featured SpeakerChristy Goldsmith RomeroCommissionerU.S. Commodity Futures Trading CommissionExplore the policy fallout from the 2022 market crash, the advance of CBDCs and more.Cheyenne Ligon is a CoinDesk news reporter with a focus on crypto regulation and policy. She has no significant crypto holdings. Featured SpeakerChristy Goldsmith RomeroCommissionerU.S. Commodity Futures Trading CommissionExplore the policy fallout from the…
news Belarus-based blockchain startup Currency.com has launched a trading platform for tokenized securities. The firm announced Tuesday that the platform would allow investors to directly trade and invest in financial instruments using the cryptocurrencies bitcoin or ethereum, without first converting to fiat. The platform will initially host over 150 tokenized securities, tracking the underlying market…