Experts weigh in on bZx attacks: flash loans highlight the need to improve DeFi security models

Quick Take
- The Block asked two DeFi market experts about their views of the recent bZx attacks
- The attacks, enabled by flash loans, may force some protocols to reconsider their security models in order to prepare them for better-capitalized attackers.
We'd love your feedback.
One of the first rules in designing a network security model is, perhaps, this: if a person with near-infinite resources tries to attack your model, then you should probably give in to that attack.
The reason behind such a thesis is simple. If someone – usually the government – is willing to deploy as many resources as required to exploit any potential vulnerability of the system, then there is nothing to stop them from doing so unless the system itself is mathematically proven to be secure.
In today’s Decentralized Finance (DeFi) realm, because of so-called flash loans, this line of reasoning seems to be particularly true.
And the recent attacks on DeFi lending protocol bZx, enabled by flash loans, serve as a wake-up call to other DeFi projects that may have been underestimating their adversaries.
Attackers with more resources
A flash loan allows a person to take out capital without putting down any collateral as long as the borrowed funds are returned within a single transaction.
Put more simply: users can instantly get their hands on millions of dollars to carry out an attack that is traditionally reserved to those with near-infinite resources, like what the attackers did to bZx that resulted in a loss of around $943,000 in ETH.
“As evidenced by these attacks, flash loans mean anyone can immediately have access to millions of dollars of capital to use within one transaction. All protocols must realize and account for this when designing their economic incentives,” Antonio Juliano told The Block, whose DeFi trading platform dYdX was one of the first to provide flash loans.
If developers previously designed their protocols under the assumption that their potential attackers will have at most x multiples of y amount of wealth to fund their attack, that x now needs to be churned up by magnitude due to the existence of flash loans.
“The key is making sure that you understand your threat model very carefully and whether your threat model only works if users have bound wealth… You should design these things assuming that people have higher wealth,” said Tarun Chitra, whose firm Gauntlet works with DeFi projects to stress test their systems.
“Now, of course, you can’t say infinite. So you have to make sure you have the scaling law correct,” he added.
To be sure, as The Block's Matteo Leibowitz pointed out, flash loans themselves are not responsible for the bZx attacks. Both Chitra and Juliano noted that bZx’s protocol has some inherent flaws that are not shared by other DeFi protocols.
bZx uses DeFi liquidity protocol Kyber as its price oracle, while Kyber gets its price feeds from decentralized exchange Uniswap reserves. This arrangement allowed attackers to distort the ETH/BTC ratio on Uniswap to their favor. Meanwhile, all other major DeFi protocols such as MakerDAO, dYdX, and Compound use oracles that include data from off-chain reporters.
“These attacks are specific to protocols that use on-chain decentralized exchanges such as Uniswap V1 & Kyber directly as price oracles. bZx is the only mainstream protocol I know of that uses on-chain DEXs as their direct price oracle,” said Juliano.
Responses to attacks
While some protocols become more vigilant in light of the bZx attacks, others are concerned over the bZx team’s use of their administrator power to pause trading on its platform – an action that some regard as an anti-thesis to the ethos of decentralization.
The bZx team argued in the post-mortem that “using pause buttons can, implemented thoughtfully, be part of the toolkit of a decentralized protocol.” Indeed, Chitra and Juliano are also in favor of utilizing administrator keys, at least for now.
“In my opinion, the purpose of DeFi is to enable products that technologically ‘can’t be evil.’ Using admin powers that are available doesn’t make a protocol any more or less decentralized, it’s what admin powers are available in the first place that matters,” said Juliano.
“The admin key is the hard fork of DeFi. If you're a believer in never hard-forking, then there should have never been an admin key. But if you believe that you need hard work for a certain amount of time, and then eventually, once you believe in the system, you get rid of the admin key. Then that’s totally reasonable,” Chitra said.
© 2026 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

