Skip to content
← Back to newsBalancer Details $116 Million Hack in Post-Mortem Report, Cites Rounding Exploit
Security

Balancer Details $116 Million Hack in Post-Mortem Report, Cites Rounding Exploit

By ToTo BugelmanNewcomer0 rep· 11/6/2025

Decentralized finance (DeFi) protocol Balancer has released a preliminary post-mortem report detailing the sophisticated exploit that resulted in the loss of approximately $116 million. The attack, which targeted specific Balancer v2 Stable Pools and Composable Stable v5 pools, has prompted the protocol to pause affected pools and disable the creation of new vulnerable ones.

 

Key Takeaways

  • The exploit targeted Balancer v2 Stable Pools and Composable Stable v5 pools.

  • A combination of BatchSwaps, flashloans, and a flaw in the upscale rounding function was used.

  • Balancer is working with industry partners to recover funds and has offered a bounty.

 

The Exploit Mechanism

The breach was executed through a complex method involving Balancer's BatchSwaps feature, which allows multiple actions within a single transaction. The attacker combined this with flashloans and exploited a vulnerability in the upscale rounding function within the Stable Pools. This function is designed to round down when token prices are input, but the hacker found a way to manipulate these rounding values. In conjunction with BatchSwaps, this allowed them to drain funds from the stable pools, with exploited funds often remaining as internal balances within the Vault before being withdrawn.

 

Industry Response and Recovery Efforts

Security analysts suggest the attackers were highly skilled professionals who meticulously planned the operation, potentially for months. To obscure their trail, they funded the attack using small, incremental deposits of 0.1 Ether through Tornado Cash. Balancer has been collaborating with cybersecurity partners and other DeFi protocols to trace and freeze a portion of the stolen assets. Notably, around 5,041 StakeWise Staked ETH (osETH), valued at approximately $19 million, and 13,495 osGNO tokens, worth up to $2 million, have been traced and frozen.

 

BitFinding

 

Balancer's Actions and Future Safeguards

In response to the incident, Balancer has paused all affected pools and halted the creation of new "vulnerable" pools until a permanent security fix is implemented. The protocol has also offered a 20% white hat bounty to ethical hackers or the perpetrator for the return of the stolen funds, though no claims have been made as of this report. The team is conducting a full code review and coordinating additional third-party audits before reopening the compromised pools. Lessons learned from this attack will be integrated into new safeguard models for all future pool releases, emphasizing the ongoing need for robust security in the rapidly evolving DeFi landscape.

 

Sources

 

This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.