Fun

DEX Volume Soars But Bzx Exploit Raises Questions About ‘Decentralization Theatre’

News Feed - 2020-02-18 08:02:00

DEX Volume Soars But Bzx Exploit Raises Questions About ‘Decentralization Theatre’


As the decentralized finance juggernaut rolls inexorably forward, the exploitation of defi project Bzx – in which $350K, or around 2% of total assets was taken – has called the decentralization of the industry into doubt. The attack forced an admin key reset to redeem lost funds and sparked a surge in defi insurance, with major players hastily taking out cover to immunize themselves from financial loss. Exactly how decentralized is decentralized finance, critics are wondering.


Also read: 50 Cent, Talib Kweli, Snoop Dogg and Nas: Celebrities Who Could Be Bitcoin Millionaires DEX Volume Swells 71% in a Week


Decentralized exchanges, around which the defi movement revolves, are going strong. More than $2.3B was traded on Ethereum-based DEXs last year, and 2020 is on course to comfortably surpass that. $119M was traded in the last seven days, according to Dune Analytics, marking a 71% increase. Meanwhile, new DEXs are springing up regularly to meet growing demand. The latest, Dexive, will operate as a dual Ethereum and Neo decentralized exchange, with integrated trading features such as asset details, news portal, discussion forum and microblog. There are plans to ultimately integrate other blockchains such as Eos and Zilliqa to create a universal DEX. Latest DEX volume according to Dune Analytics


While demand for decentralized token trading, and the defi primitives it supports, ramps up, the industry has looked shaky of late. The Bzx exploit that occurred on February 15 has sparked intense debate as to whether decentralized trading protocols are truly decentralized, or whether the presence of a “kill switch” nullifies all such claims. Bzx is the seventh largest defi protocol, with over $18 million worth of funds locked. A Complex Transaction


The exploitation of Bzx occurred on February 15, with project co-founder Kyle Kistner providing details via the platform’s official Telegram channeland temporarily pausing all trading on the exchange. “Exploit” is probably the most apposite term, although arbitraging, attacking, hacking, and thieving have all been liberally used. The net result is the same: Bzx’s balance wound up $350K worth of ETH lighter, though the damage was far worse given the consequent loss of equity. So, how did it happen?


Essentially an exploit was executed against a contract on the project’s Fulcrum trading platform. The perpetrator took out a 10,000 ETH flash loan from non-custodial exchange Dydx before dispatching 5,000 ETH to Compound and borrowing 112 wrapped bitcoins (WBTC).


Thereafter, the attacker sent 5,000 ETH to Bzx, opening a 5x short position for WBTC. After the exchange had converted 5,637 ETH to 51 WBTC via Uniswap, the attacker then converted the 112 WBTC to 6,871 ETH on Uniswap before paying Dydx their original 10,000 ETH. The total transaction cost incurred by the multi-part smart contract was $8. Confused? You’re not alone; the sophistication of the exploit has had commenters applauding and head-scratching in equal measure. Tweets like "DeFi apps are no different than centralized exchanges because all the contracts have admin keys" is the cheap, boring fast-track to "CT wokeness" these days, forcing me to take the devil"s advocate and point out why that"s sometimes wrong. Warranted retort:


— Eric Wall IS RIGHT (@ercwl) February 17, 2020


An Oracle Problem


In the end, the perpetrator exploited a Bzx flaw that enabled them to trade an inordinate amount on Uniswap at an inflated price of 3x. In other words, it wasn’t an oracle bug per se, but a fundamental vulnerability in the design of the defi stack that facilitated its execution. Opening such a huge position caused a drain of funds from Bzx to Uniswap, enriching the rogue actor to the tune of $350K and resulting in a $620,000 loss of equity for Bzx. Market manipulation at its finest. Our first claims assessment has finalised with the 30,000 DAI claim on @bzxHQ being declined.


7 out of 8 members voted No, with over 76,000 NXM being staked in the process (over $300,000 worth of stake).


The claimant can resubmit a claim one more time if they wish. https://t.co/ffAvyKZlt0


— Nexus Mutual 🐢 (@NexusMutual) February 16, 2020



As well as temporarily taking Fulcrum down for maintenance, Bzx deployed a contract upgradethey said would make their system more robust against similar attacks and statedthat they would cover the attacker’s loan repayment by streaming “interest and exit liquidity to existing iETH holders” from the 600k of WBTC left behind. Amid the post-mortem of the attack, insurance for DeFi lending has experienced a serious uptick, with hundreds of thousands of dollars’ worth of cover taken out across protocols such as Maker, Compound, Dydx and Bzx. The largest defi protocols according to Defi.Pulse How Decentralized Is Decentralized?


Perhaps the most relevant question to emerge from this fiasco was posed by Twitter user @SupraBo_ in responseto Bzx’s update on the transaction: “Decentralized finance is so efficiently decentralized that it can be paused.” The bZx attack occurs regularly in traditional markets in the form of derivative manipulation, which tends to result in harsh regulatory punishments.


The real conundrum with DeFi is not flash loans or oracles, but that "attackers" merely play a permissionless game by the rules.


— Qiao Wang (@QWQiao) February 16, 2020



Another tweetsuggested the attack exposed the wider danger posed to the Ethereum network of fast-growing finance initiatives: “DeFi = how to increase systemic risk on Ethereum.” Litecoin creator Charlie Lee, meanwhile, sounded offby calling defi “the worst of both worlds,” noting that it “can be shut down by a centralized party, so it’s just decentralization theatre. And yet no one can undo a hack or exploit unless we add more centralization. So how is this better than what we have now?” Research by Chris Blec, who bills himself as “defi’s best friend and toughest critic,” has shown that most defi protocols have an admin key that can override the system in emergencies.



While it is easy to see why faith in defi has been knocked by this ingenious heist of sorts, another perspective is that the event represents a bump in the road for the movement, which remains at an early, experimental stage despite over $1 billion worth of value being locked in, mostly in lending solutions. The exposure of vulnerabilities, and consequent beefing up of procedures, is necessary for maturation of an industry in which innovation continues to play out.


What are your thoughts on the Bzx exploit? Do you think defi protocols are truly decentralized? Let us know in the comments section below.


Images courtesy of Shutterstock.


Did you know you can verify any unconfirmed Bitcoin transaction with our Bitcoin Block Explorer tool? Simply complete a Bitcoin address search to view it on the blockchain. Plus, visit our Bitcoin Chartsto see what’s happening in the industry. Share this story: Tags in this story Decentralized, defi, DEX, Ethereum, trading Related Tax Rules Hit Brazilian Crypto Exchanges, Forcing Trading Platforms Out of Business EXCHANGES | Lubomir Tassev


Tax regulations implemented even before dedicated legislation has been adopted have hit Brazilian cryptocurrency exchanges. Digital asset brokers failing to… read more. Russians Can Use Qiwi, Sberbank, Yandex Money and Now Binance P2P Exchange to Buy Bitcoin With Rubles EXCHANGES | Lubomir Tassev


A growing number of platforms allow Russian residents to purchase cryptocurrencies with local fiat money. Established cryptocurrency exchanges are not… read more. Kai Sedgwick


Kai"s been manipulating words for a living since 2009 and bought his first bitcoin at $12. It"s long gone. He"s previously written whitepapers for blockchain startups and is especially interested in P2P exchanges and DNMs. Please enable JavaScript to view the comments powered by Disqus.

News Feed

A New Super PAC Aims to Elect BTC Advocates and ‘Vote out Anti-Bitcoin Politicians Like Brad Sherman, Elizabeth Warren’
A New Super PAC Aims to Elect BTC Advocates and "Vote out Anti-Bitcoin Politicians Like Brad Sherman, Elizabeth Warren" On Friday, Grant McCarty, the director of policy and public
Bitcoin, Ethereum Technical Analysis: ETH Rebounds on Friday, Climbing Above $1,700
Bitcoin, Ethereum Technical Analysis: ETH Rebounds on Friday, Climbing Above $1,700 Ethereum rose above $1,700, while bitcoin snapped a seven-day losing streak on Friday, with pric
US Bank Launches Cryptocurrency Custody Services Amid Strong Demand From Institutional Clients
US Bank Launches Cryptocurrency Custody Services Amid Strong Demand From Institutional Clients US Bank has launched its cryptocurrency custody services. “Investor interest i
Ana Paula Pereira7 hours agoCore Scientific appoints Adam Sullivan as CEO amid restructuring processThe company claims to have seen a boost in liquidity in recent months and is expected to emerge from bankruptcy proceedi
Kenya Central Bank Governor: Low Smartphone Penetration Working Against Plan to Launch CBDC
Kenya Central Bank Governor: Low Smartphone Penetration Working Against Plan to Launch CBDC According to Patrick Njoroge, the governor of the Kenyan central bank, the significant n
Pepe Battles Price Decline, But Analysts Signal A Potential Rally Ahead
Este artículo también está disponible en español. Pepe [PEPE] is currently trading at approximately $0.000000900 and is undergoing a challenging period. The Relative Stre
US Bitcoin Reserve Will Push Price Above $1 Million, Expert Predicts
Este artículo también está disponible en español. In a series of exchanges on X, Adam Back, CEO of blockchain technology firm Blockstream, projected that Bitcoin could su
Huobi Global Rebrands as Huobi, Introduces New Strategy
Huobi Global Rebrands as Huobi, Introduces New Strategy sponsored Huobi will endeavour to bring value to its business and provide secure and professional services to its users as it
Derek Andersen18 hours agoBasel Committee to consider disclosure requirements for banks’ crypto assetsThe committee already imposes a limit on crypto holdings in bank reserves, but the concentration of crypto in a smal
Study: Over 13% of All Proceeds of Crimes in Bitcoin Passed Through Privacy Wallets in 2020
Study: Over 13% of All Proceeds of Crimes in Bitcoin Passed Through Privacy Wallets in 2020 According to a study published by the blockchain analysis firm Ellipt
Mastercard to Help Banks Offer Crypto Trading — Executive Says Crypto Is on the ‘Cusp of Really Going Mainstream’
Mastercard to Help Banks Offer Crypto Trading — Executive Says Crypto Is on the "Cusp of Really Going Mainstream" Payments giant Mastercard has introduced a new program called Cr
If Solana Reclaims $210 ‘New Highs Are Next’ – Price Analysis
Este artículo también está disponible en español. The crypto market showed signs of life yesterday after enduring weeks of persistent selling pressure, with many assets s