The Balancer announced that hackers targeted v2 pools, with estimated losses exceeding $128 million. Specifically, the “V2 Compostable Stable Pools” were affected. Fortunately, the remaining pools, including V3, were not affected. This event comes to shake the already fragile trust in the decentralized finance (DeFi) ecosystem, as it demonstrates that even mature, auditable protocols are not invulnerable.

What is the Balancer Protocol and how does it work?
Balancer is a decentralized finance (DeFi) protocol based on the Ethereum blockchain, acting as an automated market-maker (AMM) and liquidity infrastructure. It offers flexible pools with custom token mixes; users can deposit assets, receive fees, and traders can exchange assets. The protocol is governed by the BAL token, which before the event had a market capitalization of approximately $65 million.
See also: New Phishing Attack Exploits Cloudflare and ZenDesk Pages
The exploit in detail: How the attack was carried out
According to security firm GoPlus Security, the flaw is traced to a rounding accuracy issue in the Balancer V2 Vault swap calculations. Specifically, each swap would round down the token amount, creating small discrepancies. The attacker exploited these discrepancies repeatedly, using the batchSwap function for chained swaps, resulting in large price distortion and massive liquidity removal.
Other experts attribute the incident to improper authorization and callback handling within Balancer's V2 vaults.
Balancer said its team is working with leading security researchers to fully understand the problem and will release more details about the attack later.

The wider implications and the message to the market
The fact that a protocol with extensive audits (Balancer V2 has been audited 11 times since 2021) was affected by such a serious exploit demonstrates that traditional security assessment models are no longer sufficient for DeFi. At the same time, the attack comes at a time when the DeFi market has already suffered significant losses this year — the total cryptocurrency thefts for 2025 have exceeded $2 billion. This means that security in the web3 environment should be considered a top priority for programs, users, and investors.
See also: Hackers exploit RMM tools to penetrate Logistics networks
What the user can do – Protection Guide
The Balancer incident serves as a reminder that DeFi users must adopt proactive security practices. Specifically:
- Check if you are placed in the affected pools (V2 Composable Stable Pools) and withdraw funds if possible.
- Revoke or limit token approvals for protocols you are not familiar with.
- Monitor protocol security announcements and avoid interacting with distributed frontends that may be phishing. Balancer, for example, warned users about potential phishing attempts.
- Focus on risk diversification: don't put all your funds in one unit/group and consider protocols with proven, multi-layered security measures.

Lesson for the entire DeFi ecosystem
The Balancer attack is a critical wake-up call for the entire decentralized finance landscape. No matter how “mature” or audited a protocol is, the nature of the technology — smart contracts, multi-party interactions, multi-network chains — creates complex attack surfaces that must be addressed with constant monitoring, multiple layers of security, and transparency in threat communication. Effective risk management is no longer just the responsibility of developers, but also of users who invest — and investors should demand from protocols not just audits, but active security and crisis management.
See also: New HttpTroy backdoor disguises itself as a VPN invoice
The only certainty? In the rapidly changing web3 landscape, security is not an “optional extra”, but a fundamental parameter for the trust and survival of DeFi protocols.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
