CryptoReal
CASE FILE — Feb 9, 2021

BT Finance and Growth DeFi Hacks Wipe Out $2.7 Million in Back-to-Back DeFi Exploits

On February 9, 2021, two lesser-known decentralized finance projects, BT Finance and Growth DeFi, were drained within hours of each other, adding roughly $2.7 million combined to DeFi's growing list of protocol losses. Neither name carried much of a public profile beforehand — both surfaced mainly because attackers exploited them using familiar techniques.

BT Finance, marketed around the promise of "best yield for tokens," lost $1.5 million to an attacker who followed a well-worn playbook: manipulate an internal price, trigger the protocol's earn function, then withdraw the inflated balance. Developer Emiliano Bonassi confirmed the drain on Twitter, and the funds moved out in a single on-chain transaction. The project had previously gone through a PeckShield security audit, which did nothing to prevent the loss.

Growth DeFi, which had built up a somewhat larger and more established user base, fell to a more unusual mechanism. The attacker created a worthless custom token called AXZ, paired it with GRO to form a liquidity position, and staked that fabricated pair into Growth DeFi's staker contract. A missing conditional check in the contract's code then let the attacker withdraw a separate, legitimate liquidity pair instead of the fake one — netting roughly $1.3 million.

Researcher @r0bster97 laid out the sequence on Twitter:

Sums referenced in this case file
  • First, the attacker swapped 0.001 ETH for roughly 0.0148 GRO.
  • Next, that ~0.0148 GRO was combined with 100,000,000,000 units of the fake AXZ token to seed a Uniswap liquidity pair.
  • The staker contract's missing if-condition then allowed the attacker to withdraw about 27,516 GRO and 1,218 rAAVE in liquidity from Uniswap — a different, legitimate pair entirely.
  • Finally, the attacker swapped the roughly 27,516 GRO for about 597 ETH on Uniswap, completing the cash-out.

Growth DeFi later published its own technical breakdown of the exploit on Medium.

The two incidents relied on different mechanics — straightforward price manipulation in BT Finance's case, a fake-token liquidity trick exploiting a missing code check in Growth DeFi's — but landed on the same outcome: roughly $2.7 million lost across both, with little apparent consequence for either attacker. It's a reminder that a passed audit doesn't guarantee safety, and that depositing into smaller, copycat protocols carries risk that isn't always visible up front.

BT FinanceGrowth DeFi
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.