Home » Research

BZx got hacked: What’s the solution?

bZx hack (September 2020): $8M stolen via flash loan attack exposing DeFi smart contract vulnerabilities. How it happened: (1) Attacker borrowed funds via flash loan (uncollateralized), (2) Manipulated oracle price feeds, (3) Profited from price discrepancy, (4) Repaid flash loan in same transaction. Lessons: (1) Oracle manipulation risk – use decentralized price feeds (Chainlink), (2) Flash loan attack vectors – add time delays, (3) Code audits essential – Immunebytes, OpenZeppelin. SmartCredit.io protection: Immunebytes audited smart contracts, Chainlink oracles, 5-year zero-hack record, conservative 90% LTV limits prevent oracle manipulation profitability. Post-bZx: Industry adopted multi-oracle systems, time-weighted average prices (TWAP), circuit breakers. Visit