📢 Exclusive on Gate Square — #PROVE Creative Contest# is Now Live!
CandyDrop × Succinct (PROVE) — Trade to share 200,000 PROVE 👉 https://www.gate.com/announcements/article/46469
Futures Lucky Draw Challenge: Guaranteed 1 PROVE Airdrop per User 👉 https://www.gate.com/announcements/article/46491
🎁 Endless creativity · Rewards keep coming — Post to share 300 PROVE!
📅 Event PeriodAugust 12, 2025, 04:00 – August 17, 2025, 16:00 UTC
📌 How to Participate
1.Publish original content on Gate Square related to PROVE or the above activities (minimum 100 words; any format: analysis, tutorial, creativ
BXH protocol suffered a $139 million Hacker attack, Smart Pool security risks raise concerns.
BXH protocol suffers a $139 million asset loss, raising concerns about Smart Pool security
Recently, a decentralized yield protocol experienced a major security incident on the BSC chain, resulting in approximately $139 million worth of crypto assets being stolen. The protocol subsequently closed all on-chain deposit and withdrawal functions to prevent further losses.
According to the analysis of security agencies, the attack began on October 27, when the hackers deployed the attack contract. Two days later, the wallet address of the protocol granted management permissions to the attack contract. In the early hours of the 30th, the attackers used the gained permissions to transfer assets from the protocol treasury. This indicates that the fundamental cause of this incident was the malicious modification of the management permissions of the protocol.
As of November 1, some of the stolen funds have been transferred to Ethereum network and other Bitcoin addresses. This incident has attracted widespread attention, with many questioning why the protocol would hand over funds management authority to external addresses and whether there are insiders involved. Currently, the protocol has issued a $1 million bounty, seeking assistance from white hat hacker teams to recover the assets.
However, the impact of this event goes far beyond a single protocol. Many Smart Pool projects that rely on this protocol for profit have also been forced to suspend their withdrawal functions. Among them, the Smart Pool project ranked second in on-chain locked positions has been severely affected, with an associated amount reaching 150 million USD.
This chain reaction highlights the potential risks present in the current DeFi ecosystem. Many Smart Pools adopt a "Lego-style" strategy, frequently operating between various high-yield lending protocols to earn platform tokens and leveraging to amplify returns. Although this approach can yield considerable returns, it also significantly increases risk, and any issue at any stage could lead to the collapse of the entire structure.
Industry experts point out that the Smart Pool should more transparently disclose its every operation and the flow of funds, allowing investors to make informed choices. Some well-known projects have adopted this practice, but many other projects, especially some domestic ones, still have room for improvement in terms of transparency.
From a broader perspective, this event has also sparked thoughts on the sustainability of DeFi products. Currently, many Smart Pools merely operate by cycling between various lending protocols to amplify returns, a model that is considered unsustainable in traditional finance.
Experts suggest that DeFi projects should evolve towards more complex and sustainable strategies, such as options portfolio-based protocols and synthetic asset arbitrage, which benchmark traditional financial products. These products have been validated as sustainable profit models in traditional sectors, although the participation threshold is relatively high.
Overall, this incident not only exposed the security vulnerabilities of specific projects, but also highlighted the challenges faced by the entire DeFi ecosystem. It reminds us that while pursuing high returns, we must not overlook the importance of risk management and long-term sustainability.