Blockchain security firm PeckShield published a transaction-level reconstruction on February 16, 2020 of the exploit that had prompted decentralized lending and margin-trading protocol bZx to restrict operations. The analysis showed that one Ethereum transaction had linked liquidity and trading functions across dYdX, Compound, bZx, Kyber and Uniswap.

The underlying transaction executed at 01:38:57 UTC on February 15 in Ethereum block 9,484,688. Its timing means February 16 was the date of the detailed public analysis, not the date of the on-chain operation. That distinction matters because bZx had acknowledged the exploit and paused the affected contract on February 15, but had not yet published its complete postmortem when PeckShield released its initial reconstruction.

One transaction, five connected protocols

PeckShield reported that the operation began with a 10,000-ETH flash loan from dYdX. A flash loan could be issued without conventional collateral because all of its programmed steps, including repayment, had to succeed inside one atomic Ethereum transaction. If repayment failed, the transaction would revert, although execution could still consume gas.

The transaction then supplied 5,500 ETH to Compound and borrowed 112 wrapped bitcoin, or WBTC. In a separate leg, 1,300 ETH was deposited into a bZx margin position described as a five-times short of ether relative to WBTC. Servicing that position caused 5,637.623762 ETH to be routed through Kyber’s liquidity system to a Uniswap reserve, which returned approximately 51.345576 WBTC.

That unusually large trade changed the relative balances—and therefore the quoted price—inside Uniswap’s automated pool. The operation subsequently sold the 112 WBTC borrowed through Compound into the altered pool and received approximately 6,871.412739 ETH. The transaction record also shows repayment of 10,000.00000000001 ETH to the flash-loan source.

Those figures describe transfers and contract calls, not a complete profit-and-loss statement. They do not by themselves value the remaining Compound position, bZx’s impaired exposure, transaction fees or subsequent recovery actions. PeckShield’s February 16 publication explicitly left a detailed profit calculation for later analysis.

Composability carried the risk

The institutional significance was larger than any one transfer. Each component performed a recognizable DeFi function: temporary liquidity, collateralized borrowing, leveraged trading, liquidity routing or automated exchange. The vulnerability emerged from their interaction at transaction scale, where borrowed capital could move prices in a relatively shallow pool and influence another protocol’s execution.

This was the adverse side of what developers called composability. Open smart contracts could be assembled without bilateral agreements between their operators, accelerating experimentation. The same openness meant that assumptions made by one application—about available liquidity, acceptable slippage or the cost of obtaining trading capital—could be invalidated by capabilities supplied elsewhere.

PeckShield characterized the event-day concern broadly as a risk inherent in shared, composable liquidity, especially for margin trades and borrowing systems. That was a security firm’s contemporaneous interpretation, not a final adjudication of responsibility. The public transaction established what executed; determining why protective checks failed required review of bZx’s code and configuration.

The response also illustrated a governance tension. bZx’s ability to pause the affected functionality limited continued use while the team investigated, but it demonstrated that emergency administrative control remained part of an application marketed within decentralized finance.

What remained unresolved on February 16

By February 16, the defensible record was that the transaction succeeded, bZx had restricted affected operations, and an independent security firm had reconstructed the cross-protocol path. The attacker’s real-world identity, the final economic loss, allocation of any shortfall and the adequacy of proposed repairs remained unresolved. Descriptions such as hack, exploit, arbitrage or manipulation reflected competing interpretations rather than a court or regulatory finding.

Later clarification

On February 17, PeckShield expanded its work and attributed the first incident to arbitrage that exploited a bZx implementation bug rather than a pure oracle attack. That later conclusion clarifies the mechanism but was not yet established in the February 16 analysis.

Primary sourceEtherscan — Ethereum transaction in block 9,484,688

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.