DeFi

bZx looks to rebound after attacks serve as a wake-up call for DeFi

This report is part of a weekly series where we will explore the mechanics behind major Open Finance protocols and evaluate them on a fundamental basis. You can view prior reports here.

Last month there were two consecutive attacks on the bZx protocol. There have been many detailed reports written on the attacks, but in short, the first exploited a bug in the system to profitably arbitrage across various DeFi protocols while the second manipulated the oracle to allow the attacker to drain ETH from the loan pool. When it was all said and done, the attackers made off with a combined ~3,500 ETH, worth around $1 million at the time as the company and its stakeholders were left footing the bill. Now that the dust has settled its time to take a step back and look at how the system was affected and what it means for the future of bZx.

Crypto users tend to be particularly sensitive when it comes to control of their funds. Not your key not your coins, right? But even when you hold your private keys, if you deposit collateral into a smart contract you are trusting that you will be able to retrieve it at any time. So when news breaks of an attack that jeopardizes this safety, you naturally look to do everything you can to keep your money safe. After the bZx attacks, that’s exactly what happened as users went running for the exits.

Ignoring the first spike which was a result of two platforms, Staked and Idle, rebalancing their money there are two distinct periods that stand out. As you can imagine they are the days the hacks occurred that shook user confidence and led to massive withdrawals. In the aftermath, the total value locked in bZx has dropped precipitously. Even though the iETH pool was the only one affected, the spillover impacted every loan pool.

The team reacted swiftly pausing the protocol to prevent any new borrowing and trading. To make up for the losses, cash flows of the company from its capacity as a Kyber affiliate and from the protocol as arbitrage opportunities are being directed to the insurance fund so that users do not lose money.

In hindsight, there were steps that could have been made to prevent these attacks. Now that they’ve occurred, the team is taking the necessary steps to make bZx more robust including a multi-phase process integrating Chainlink, Band, and Uniswap v2.0. To alleviate concerns around centralization, administrative privileges will be handed off the bZxDAO in the future which will operate using a unique form of liquid democracy. Finally, to address any code issues bZx will be formally verifying the code and undergoing a security and economic audit before it relaunches.

These attacks highlight the risks involved that are inherent in any DeFi protocol that manages millions of dollars in user funds. It’s easy to see an attack like this and conclude bZx was broken, however, a deeper look under the hood reveals a series of isolated mistakes that are being worked on. To conclude, the subsequent attacks amounted to an expensive bug bounty for bZx and a wake-up call to whole DeFi space about the necessary precautions to take. As the space moves forward these steps will be demanded of major protocols that hold user funds in an effort to instill the necessary faith in DeFi for it to one day reach the mainstream.

Let us know what you loved about the report, what may be missing, or share any other feedback by filling out this short form. All responses are subject to our Privacy Policy and Terms of Service.

Suggested Research Based on your Watchlists

Create a new watchlist
Mentioned Assets