BXH protocol suffered a $139 million Hacker attack, Smart Pool security risks raise concerns.

robot
Abstract generation in progress

BXH protocol suffers a $139 million asset loss, raising concerns about Smart Pool security

Recently, a decentralized yield protocol experienced a major security incident on the BSC chain, resulting in approximately $139 million worth of crypto assets being stolen. The protocol subsequently closed all on-chain deposit and withdrawal functions to prevent further losses.

According to the analysis of security agencies, the attack began on October 27, when the hackers deployed the attack contract. Two days later, the wallet address of the protocol granted management permissions to the attack contract. In the early hours of the 30th, the attackers used the gained permissions to transfer assets from the protocol treasury. This indicates that the fundamental cause of this incident was the malicious modification of the management permissions of the protocol.

As of November 1, some of the stolen funds have been transferred to Ethereum network and other Bitcoin addresses. This incident has attracted widespread attention, with many questioning why the protocol would hand over funds management authority to external addresses and whether there are insiders involved. Currently, the protocol has issued a $1 million bounty, seeking assistance from white hat hacker teams to recover the assets.

However, the impact of this event goes far beyond a single protocol. Many Smart Pool projects that rely on this protocol for profit have also been forced to suspend their withdrawal functions. Among them, the Smart Pool project ranked second in on-chain locked positions has been severely affected, with an associated amount reaching 150 million USD.

This chain reaction highlights the potential risks present in the current DeFi ecosystem. Many Smart Pools adopt a "Lego-style" strategy, frequently operating between various high-yield lending protocols to earn platform tokens and leveraging to amplify returns. Although this approach can yield considerable returns, it also significantly increases risk, and any issue at any stage could lead to the collapse of the entire structure.

Industry experts point out that the Smart Pool should more transparently disclose its every operation and the flow of funds, allowing investors to make informed choices. Some well-known projects have adopted this practice, but many other projects, especially some domestic ones, still have room for improvement in terms of transparency.

From a broader perspective, this event has also sparked thoughts on the sustainability of DeFi products. Currently, many Smart Pools merely operate by cycling between various lending protocols to amplify returns, a model that is considered unsustainable in traditional finance.

Experts suggest that DeFi projects should evolve towards more complex and sustainable strategies, such as options portfolio-based protocols and synthetic asset arbitrage, which benchmark traditional financial products. These products have been validated as sustainable profit models in traditional sectors, although the participation threshold is relatively high.

Overall, this incident not only exposed the security vulnerabilities of specific projects, but also highlighted the challenges faced by the entire DeFi ecosystem. It reminds us that while pursuing high returns, we must not overlook the importance of risk management and long-term sustainability.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 9
  • Repost
  • Share
Comment
0/400
SchrodingerAirdropvip
· 08-11 07:47
Another round of operations as fierce as a tiger.
View OriginalReply0
MetaNeighborvip
· 08-10 11:08
Goodness, I've been drained again.
View OriginalReply0
ZKProofstervip
· 08-09 15:03
technically speaking, another protocol with amateur-level key management smh... did they even audit?
Reply0
ChainSherlockGirlvip
· 08-09 14:58
According to my analysis, this operation is definitely an insider job. The fund transfer trail is incredibly skillful.
View OriginalReply0
StakeOrRegretvip
· 08-09 14:56
Locking your coin has risks, it's too hasty now.
View OriginalReply0
CascadingDipBuyervip
· 08-09 14:55
Have you been clipped coupons again? Tsk tsk.
View OriginalReply0
CoconutWaterBoyvip
· 08-09 14:40
Wow, another internal thief?
View OriginalReply0
MetaverseVagrantvip
· 08-09 14:39
Are you putting on a makeshift performance here?
View OriginalReply0
SingleForYearsvip
· 08-09 14:37
Did you give money to the Hacker again?
View OriginalReply0
View More
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)