Balancer V2
On November 3, 2025, an attacker drained roughly $128 million from Balancer's v2 pools across nine chains in a single coordinated exploit, with Ethereum absorbing the largest share, near $91.5M. The attack targeted a rounding flaw in Balancer's Composable Stable Pool math rather than a stolen key or a manipulated oracle, which is why the same transaction template worked, largely unchanged, on Arbitrum, Base, Optimism, Polygon, Avalanche, Gnosis, Sonic and Berachain within hours of the first strike (rekt.news; CoinDesk).
How the attack works
Composable Stable Pools hold tokens with different decimal precision — USDC's 6, DAI's 18, WBTC's 8 — and normalize all balances to 18 decimals ("upscaling") before running swap math. The upscale function always rounded down; a code comment reportedly called the expected impact of that rounding "minimal." The attacker turned that assumption into a lever: by flash-minting the pool's LP token and running dozens of tiny swaps inside one transaction — over 65 by some counts — each swap shaved off a negligible amount through rounding, but the losses compounded and quietly deflated the pool's internal invariant, the figure the contract trusts to represent real reserves. Once invariant and reality diverged, the attacker redeemed the inflated LP position for real underlying tokens at the mispriced rate, extracting more than was ever deposited. Some technical write-ups (Halborn) also describe a second stage — an access-control gap in the vault's internal-balance withdrawal path used to claim the mispriced balances directly. That's broader than the "Composable Stable Pools" label suggests, but the rounding is what created the exploitable gap in the first place.
What happened next
Monitoring firm Hypernative flagged abnormal swap activity at 07:46 UTC, and Balancer paused v2 pools within about twenty minutes — fast enough to limit further losses, not fast enough to stop copycat attacks on other chains within the hour. Recovery varied sharply by chain: Berachain reportedly halted its network and executed an emergency hard fork to reclaim about $12.86M, Polygon validators reportedly censored the attacker's transactions to freeze funds there, and partners including StakeWise (~$19.7M) and Certora (~$4.1M) recovered smaller pools of assets elsewhere. rekt.news puts total recovered or frozen funds at roughly $38.4M — most of the $128M remained unrecovered at time of reporting, well short of zero. Balancer's TVL fell from about $775M before the exploit to roughly $258M weeks later; in late November the DAO opened a governance discussion on redistributing about $8M in recovered tokens to affected LPs pro-rata, alongside whitehat bounties capped at $1M per incident (CoinDesk). The protocol kept operating; this was reported as its third known security incident, after episodes in 2021 and 2023.
What follows from this
- Any pool that normalizes mixed-decimal tokens before running invariant math carries this risk class — rounding direction at precision boundaries is a security choice, not a cosmetic one, and needs proof of safety under adversarial, high-iteration input, not just average-case checks.
- Composability multiplies blast radius: forks that inherit the same pool library (Beethoven X, Beets Finance, BEX) turn one bug into a same-day, multi-protocol, multi-chain incident.
- There's no signal visible to a depositor in advance — the flawed code had already passed earlier audits; diversifying across protocols and pool designs is the practical mitigation, not reading Solidity.
- Recovery increasingly depends on chain-level governance rather than the protocol itself: chains able to intervene, via validator censorship or an emergency fork, recovered materially more than chains that could not.
Sources
- Balancer Hit by Apparent Exploit as $110M in Crypto Moves to New Wallets — CoinDesk ↗
- Balancer DAO Starts Discussing $8M Recovery Plan After $110M Exploit Cut TVL by Two-Thirds — CoinDesk ↗
- Balancer — Rekt II — Rekt News ↗
- Explained: The Balancer Hack (November 2025) — Halborn ↗
Sources checked 07.08.2026
On-chain DeFi carries smart-contract risk. Keep core funds on a regulated exchange.