T
iTokenly

bZx hack — November 2021

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Target typeLending protocol
Loss$55,000,000Price at time of incident
MethodPrivate key compromisephishing macro stole a developer's mnemonic and the Polygon and BNB Chain deployer keys
ChainsPolygon, BNB Chain
Attributed toBlueNoroff (North Korea-linked)Suspected
OutcomeUnresolved

What happened

bZx was a lending and margin-trading protocol deployed on Ethereum, Polygon and BNB Chain, later governed as Ooki DAO; third-party trackers often file this incident under the Ooki name. On 5 November 2021 a bZx developer opened a phishing email attachment, a Word document carrying a malicious macro. The macro ran a script on his personal computer that captured his wallet mnemonic and, with it, the two private keys the project used to operate its Polygon and BNB Chain deployments.

The attacker emptied the developer's own wallet first, then used the deployment keys to take the protocol's funds on both chains, and also drained tokens from a small number of users who had granted unlimited spending approvals. bZx confirmed the keys were compromised and said its smart contracts were not exploited. The Ethereum deployment was unaffected; the later class action alleged that a single passphrase was sufficient to reach client funds on two of the three chains.

The loss has been reported at about $55 million from the first day. That estimate originated in third-party on-chain analysis by SlowMist, which described it as a running total rather than a final accounting, and the same figure appears in the class action complaint. bZx said roughly a quarter of the total consisted of the compromised team member's personal holdings rather than protocol or user funds.

bZx disabled its front end, appealed publicly to the attacker, and asked exchanges to freeze the attacker's addresses. In May 2022 fourteen plaintiffs sued in Sarcuni et al. v. bZx DAO et al. in the Southern District of California, case 3:22-cv-00618, alleging the loss resulted from simple negligence; the named plaintiffs put their own combined losses at about $1.6 million. On 12 November 2021 Kaspersky attributed the intrusion to BlueNoroff.

Sources

  1. The Record (Recorded Future News)Secondary · retrieved 2026-08-01
  2. CoinDeskSecondary · retrieved 2026-08-01
  3. US District Court, Southern District of California (via CourtListener)Primary · retrieved 2026-08-01
  4. ClassAction.orgSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "bZx hack — November 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/bzx
https://itokenly.com/hacks/bzx

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.