BT Finance and Growth DeFi Hacks Wipe Out $2.7 Million in Back-to-Back DeFi Exploits
On February 9, 2021, two lesser-known decentralized finance projects, BT Finance and Growth DeFi, were drained within hours of each other, adding roughly $2.7 million combined to DeFi's growing list of protocol losses. Neither name carried much of a public profile beforehand — both surfaced mainly because attackers exploited them using familiar techniques.

BT Finance, marketed around the promise of "best yield for tokens," lost $1.5 million to an attacker who followed a well-worn playbook: manipulate an internal price, trigger the protocol's earn function, then withdraw the inflated balance. Developer Emiliano Bonassi confirmed the drain on Twitter, and the funds moved out in a single on-chain transaction. The project had previously gone through a PeckShield security audit, which did nothing to prevent the loss.
Growth DeFi, which had built up a somewhat larger and more established user base, fell to a more unusual mechanism. The attacker created a worthless custom token called AXZ, paired it with GRO to form a liquidity position, and staked that fabricated pair into Growth DeFi's staker contract. A missing conditional check in the contract's code then let the attacker withdraw a separate, legitimate liquidity pair instead of the fake one — netting roughly $1.3 million.
Researcher @r0bster97 laid out the sequence on Twitter:
- First, the attacker swapped 0.001 ETH for roughly 0.0148 GRO.
- Next, that ~0.0148 GRO was combined with 100,000,000,000 units of the fake AXZ token to seed a Uniswap liquidity pair.
- The staker contract's missing if-condition then allowed the attacker to withdraw about 27,516 GRO and 1,218 rAAVE in liquidity from Uniswap — a different, legitimate pair entirely.
- Finally, the attacker swapped the roughly 27,516 GRO for about 597 ETH on Uniswap, completing the cash-out.
Growth DeFi later published its own technical breakdown of the exploit on Medium.
The two incidents relied on different mechanics — straightforward price manipulation in BT Finance's case, a fake-token liquidity trick exploiting a missing code check in Growth DeFi's — but landed on the same outcome: roughly $2.7 million lost across both, with little apparent consequence for either attacker. It's a reminder that a passed audit doesn't guarantee safety, and that depositing into smaller, copycat protocols carries risk that isn't always visible up front.

Get new scam files the moment we publish them — usually 2–3 emails a week.