bZx

#bZx • 2021-11

🇺🇸 United States

bZx suffered a phishing-driven compromise after a developer received a malicious Word document, leading to theft of the developer private key and unauthorized ownership changes on affected smart contracts. The attacker used the new contract owner to drain approved tokens from bZx deployments on BSC and Polygon while the Ethereum deployment was reported unaffected, and later blockchain investigations tied the incident into a Lazarus/Bluenoroff-linked cryptocurrency laundering cluster.

Related Actors

Related Reports

« Back