For the second time in a week, bZx's Ethereum DeFi protocol is attacked
The Decentralized Finance (DeFi) space took a serious hit last week when the decentralized lending protocol suffered two subsequent attacks. Committed funds amount to just under $ 1 million. The first attack occurred on the block 9.484.588, with when and where and time of February 15, according to report bZx official. According to the document, the attack was launched on Valentine's Day on February 14 during ETHDenver.
At the time, the bZx team had been out attending the event. The attacker took advantage of some protocols of DeFi to lend and exchange a substantial amount of ETH and wBTC. The latter represents a token launched on the Ethereum network, which tracks the price of Bitcoin. This allowed the author to manipulate prices and take advantage of decentralized leveraged trading.
[amazon box="B07FY5R77T"]DeFi Low Attack
First, the attacker borrowed 10.000 ETH from dYdX, a decentralized lending protocol. He then used 5.500 ETH to secure a 112 wBTC loan on Compound, another loan protocol. After that, he spent 1.300 ETH to open a 5x leveraged ETH / BTC short position on bZx's Fulcrum trading platform, while also borrowing 5.637 ETH through Kyber's. This amount changed for 51 wBTC, causing a serious slippage.
This allowed the perpetrator to profit by changing Compound's 112 wBTC to 6.671 ETH and generating an income of 1.193 ETH. That is roughly around $ 318.000. At the end of it all, the attacker repaid the loan of 10.00 ETH in the dYdX protocol that he had taken earlier.
The second attack was today February 18, the bZx team also officially confirmed the second attack.
According to the official disclosure, the attacker managed to extract a net profit from the system of around $ 600.000, raising the losses to more than $ 900.000 in ETH. However, the mechanism of the second attack was completely different from the first. The problem in question had a lot to do with manipulation of the oracle. Oracles generally represent centralized components that provide external information to chain applications.
In light of the above, the bZx team has also stated that they are working closely with Chainlink, as well as other oracle providers to “create a more robust oracle and reduce the surface area of attacks against our protocol”The team allegedly managed to delay realizing the gains from the second attack and stated that they “believe the system can recover from this.”