Refreshed 32m ago· updates every 6h

bZx Protocol (2021) — Crypto Hack

Laundered
Nov 5, 2021·
EthereumBSCPolygon
Amount Stolen
$55.0M
~$55M in various tokens across three chains
Recovered
$0

bZx Protocol lost $55M when a developer's private keys were compromised via a phishing email containing a malicious macro.

Summary

bZx Protocol lost $55M when a developer's private keys were compromised via a phishing email containing a malicious macro.

How It Was Compromised — DeFi via Private Key Compromise

DeFiPrivate Key Compromise

A bZx developer received a phishing email with a malicious Microsoft Word document. Opening the document executed a macro that exfiltrated the developer's mnemonic seed phrase for their cryptocurrency wallets. The attacker used these keys to drain bZx protocol's BSC and Polygon deployments, plus a portion of Ethereum holdings, across multiple transactions.

Fund Flow & Laundering Analysis

Stolen funds moved across chains via bridges before being deposited into Tornado Cash. bZx team identified the attack vector as a phishing email with malicious macro. The incident highlighted the risk of personal device compromise in DeFi teams. bZx pivoted to community-governed DAO structure post-hack. No recovery of funds.

Related Incidents

For educational and transparency purposes only. Not financial advice. Data compiled from public sources and may contain approximations.