A Phishing Email Cost bZx $55 Million Across Polygon and BSC
Not every exploit requires clever smart-contract engineering — sometimes an ordinary phishing email is enough. That was the case for bZx.network, whose first appearance on the Rekt leaderboard landed it directly in the top 10.
According to the project's account, a bZx developer received a phishing email at his personal computer containing a Word document with a malicious macro, disguised as a routine attachment. Opening it ran a script that compromised the mnemonic phrase of his personal wallet.

This was not bZx's first brush with trouble. In September 2020, the protocol had previously lost $8 million, which was later returned. Before that, in February 2020, two separate flash-loan exploits — among the first of their kind — cost the protocol $298,000 and $645,000 respectively. This latest breach marks bZx's fourth major security failure.
Given that track record, when bZx announced that the private key controlling its Polygon and BSC deployments had been compromised, the community's reaction leaned more toward weary resignation than surprise, with replies asking "is this like the 4th time?" and suggesting the team give up on crypto entirely.
01Timeline of disclosure
Roughly ten hours after its initial statement, bZx posted an update clarifying that a developer had fallen for a phishing attack and emphasizing that the smart contract code itself remained untouched — a distinction that offered little consolation to affected users. SlowMist maintained a running tally of losses, which had reached approximately $55 million at the time of reporting.
02What actually happened
bZx subsequently released a preliminary post-mortem documenting the attacker's addresses across Polygon, BSC (addresses one, two, and three), and Ethereum, including a primary wallet.
Unlike the technically complex exploits bZx had suffered previously, this incident traced back to a straightforward phishing attack: a developer opened a malicious Word macro attachment, which compromised the keys to his personal wallet. Critically, that externally owned account (EOA) held control over bZx's Polygon and BSC deployments — meaning what began as an individual compromise gave the attacker control of the protocol's contracts on both chains.
With that access, the attacker drained the contracts of BZRX tokens and modified the code to additionally allow extraction of tokens from any wallet that had granted token approvals to the affected contracts. Users are advised to check their exposure via approval checkers for Polygon and BSC, and a full list of bZx contracts is available for reference.
Although bZx initially suggested the damage was confined to the Polygon and BSC deployments, the attacker went further, moving stolen BZRX to Ethereum to use as collateral and borrowing a range of other assets against it. This route yielded less profit than a direct sale, but sidestepped the liquidity constraints of trying to dump such a large BZRX position on the open market.
03Response and containment attempts

bZx has stated that it contacted centralized services in an effort to freeze stolen assets, requesting that Circle freeze USDC linked to the exploit; funds held on Binance and in USDT were reportedly frozen quickly. The team also reached out directly to the attacker (also here), proposing to "chat and reach an agreement."
04Assessing the blame
That $55 million could be lost to something as simple as a single phishing email is difficult to reconcile with bZx's history of security incidents. While caution is expected of anyone in crypto — and especially of developers on high-TVL projects — human error of this kind should never have been able to cascade into a loss this large.
Whether responsibility rests solely with the protocol is a fair question, but allowing contract control across two chains to hinge on a single EOA's security is difficult to defend for any serious project; at $55 million on the line, there is little room to characterize it as anything other than a costly oversight. It also bears noting that the attacker's decision to continue draining individual users' approved wallets after already extracting millions reflects a particular degree of opportunism.
Get new scam files the moment we publish them — usually 2–3 emails a week.