bZx hack — November 2021
Incident facts
| Date of incident | |
|---|---|
| Target type | Lending protocol |
| Loss | $55,000,000Price at time of incident |
| Method | Private key compromisephishing macro stole a developer's mnemonic and the Polygon and BNB Chain deployer keys |
| Chains | Polygon, BNB Chain |
| Attributed to | BlueNoroff (North Korea-linked)Suspected |
| Outcome | Unresolved |
What happened
bZx was a lending and margin-trading protocol deployed on Ethereum, Polygon and BNB Chain, later governed as Ooki DAO; third-party trackers often file this incident under the Ooki name. On 5 November 2021 a bZx developer opened a phishing email attachment, a Word document carrying a malicious macro. The macro ran a script on his personal computer that captured his wallet mnemonic and, with it, the two private keys the project used to operate its Polygon and BNB Chain deployments.
The attacker emptied the developer's own wallet first, then used the deployment keys to take the protocol's funds on both chains, and also drained tokens from a small number of users who had granted unlimited spending approvals. bZx confirmed the keys were compromised and said its smart contracts were not exploited. The Ethereum deployment was unaffected; the later class action alleged that a single passphrase was sufficient to reach client funds on two of the three chains.
The loss has been reported at about $55 million from the first day. That estimate originated in third-party on-chain analysis by SlowMist, which described it as a running total rather than a final accounting, and the same figure appears in the class action complaint. bZx said roughly a quarter of the total consisted of the compromised team member's personal holdings rather than protocol or user funds.
bZx disabled its front end, appealed publicly to the attacker, and asked exchanges to freeze the attacker's addresses. In May 2022 fourteen plaintiffs sued in Sarcuni et al. v. bZx DAO et al. in the Southern District of California, case 3:22-cv-00618, alleging the loss resulted from simple negligence; the named plaintiffs put their own combined losses at about $1.6 million. On 12 November 2021 Kaspersky attributed the intrusion to BlueNoroff.
Sources
- The Record (Recorded Future News)Secondary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- US District Court, Southern District of California (via CourtListener)Primary · retrieved 2026-08-01
- ClassAction.orgSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "bZx hack — November 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/bzxhttps://itokenly.com/hacks/bzxPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.