Preliminary Post Mortem
2021-11-05 • b Zx •
https://web.archive.org/web/20220531230042/https://bzx.network/blog/Prelminary-Post-Mortem
The bZx post-mortem describes a phishing-driven compromise in which a developer’s private keys were stolen, giving the attacker access to bZx deployments on BSC and Polygon while leaving the Ethereum deployment unaffected. The attacker changed proxy targets on both chains within seconds, drained protocol and user-approved funds, and used automated steps to move assets from the affected contracts. The source notes that an independent security firm analyzed the spear-phishing trojan and identified the group it believed responsible, but the excerpt does not name or substantiate a DPRK actor. Additional leads included IP addresses tied to VPN/ISP providers, a wallet connection to the Bondly Finance exploit, and FixedFloat funding traces.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | mgnr.io | 2021-11-05 | 2024-04-29 |
| URL | https://fixedfloat.com/ | 2021-11-05 | 2021-11-05 |
| URL | https://bondlyfinance.medium.co… | 2021-11-05 | 2021-11-05 |
| DOMAIN | fixedfloat.com | 2021-11-05 | 2021-11-05 |
| DOMAIN | bondlyfinance.medium.com | 2021-11-05 | 2021-11-05 |
| IPv4 | 91.234.192.52 | 2021-11-05 | 2021-11-05 |