Ethereum recorded a complex transaction on February 15, 2020 that used a 10,000-ETH flash loan and several decentralized-finance applications to leave an undercollateralized position at bZx. The protocol responded by pausing trading and borrowing through its Fulcrum platform while keeping lending and withdrawals available.
The episode mattered because it demonstrated that a vulnerability in one application could be amplified by liquidity and pricing conditions across several others. No lender supplied the attacker with unsecured capital for days or months. Instead, the flash loan, trades, collateral movements and repayment completed atomically in one Ethereum transaction.
What was known on February 15
Ethereum transaction `0xb5c8bd9430b6cc87a0e2fe110ece6bf527fa4f170a4bc8cd032f768fc5219838` was mined in block 9,484,688 at 01:38:57 UTC on February 15. The transaction borrowed 10,000 ETH through dYdX and interacted with Compound, bZx, Kyber and Uniswap before repaying the flash liquidity.
Contemporaneous reports described the transaction as producing approximately $350,000 of benefit for its operator, but that was an early estimate rather than an audited loss calculation. The reports did not identify a common price benchmark, valuation timestamp or realized-dollar conversion for every position. Coinburn therefore does not treat the dollar figure as exact.
bZx said on February 15 that a comprehensive accounting would require more time because of the transaction’s complexity. It disputed the initial characterization of the event as a simple Uniswap-oracle attack and said it did not use Uniswap as an oracle. The team also announced a contract upgrade and represented that lenders would not bear losses. Those were event-day statements from the protocol, not independently audited guarantees.
The Block and Decrypt reported that bZx co-founder Kyle Kistner acknowledged an exploit, an unspecified loss of ETH and a pause covering the affected contract except for lending and withdrawing. Fulcrum was placed into maintenance. The precise economic loss, the responsible contract condition and the treatment of the resulting position remained unsettled on February 15.
Why composability increased the impact
A flash loan permits assets to be borrowed without conventional collateral when the principal is returned before the enclosing transaction finishes. If repayment fails, the entire transaction reverts. That design can support arbitrage and collateral management, but it also gives a caller substantial temporary capital with which to probe interconnected contracts.
In this case, the same transaction could borrow ETH, establish collateral elsewhere, open a leveraged bZx position, trade wrapped bitcoin through decentralized liquidity and repay the original loan. Each component performed its assigned function, yet their combination allowed an economic state that bZx had not intended to accept.
The response also exposed an institutional trade-off. bZx’s ability to pause functions and deploy an upgrade helped contain immediate risk, but it showed that administrators retained emergency influence over a system marketed as decentralized. On February 15, the defensible conclusion was limited: the transaction succeeded, Fulcrum was curtailed, and the final allocation of losses remained uncertain.
Evidence published after February 15
On February 17, PeckShield reconstructed the transaction. It found that 5,500 ETH was deposited at Compound to borrow 112 WBTC, while 1,300 ETH supported a leveraged bZx trade that routed 5,637.623762 ETH into 51.345576 WBTC. PeckShield concluded that a bZx sanity check was skipped under a particular contract condition, allowing the undercollateralized position.
PeckShield estimated an eventual 1,271-ETH benefit after accounting for the associated Compound position. bZx’s postmortem used a different 1,193-ETH loss figure. These quantities measure the transaction and resulting positions differently and should not be substituted for the uncertain information available on February 15. A second, separate bZx exploit on February 18 is outside this event record.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

