HomeSecurityBalancer DeFi hacked: $128 million stolen

Balancer DeFi hacked: $128 million stolen

The Balancer announced that hackers targeted v2 pools, with estimated losses exceeding $128 million. Specifically, the “V2 Compostable Stable Pools” were affected. Fortunately, the remaining pools, including V3, were not affected. This event comes to shake the already fragile trust in the decentralized finance (DeFi) ecosystem, as it demonstrates that even mature, auditable protocols are not invulnerable.

Balancer DeFi hacked: $128 million stolen

What is the Balancer Protocol and how does it work?

Balancer is a decentralized finance (DeFi) protocol based on the Ethereum blockchain, acting as an automated market-maker (AMM) and liquidity infrastructure. It offers flexible pools with custom token mixes; users can deposit assets, receive fees, and traders can exchange assets. The protocol is governed by the BAL token, which before the event had a market capitalization of approximately $65 million.

See also: New Phishing Attack Exploits Cloudflare and ZenDesk Pages

The exploit in detail: How the attack was carried out

According to security firm GoPlus Security, the flaw is traced to a rounding accuracy issue in the Balancer V2 Vault swap calculations. Specifically, each swap would round down the token amount, creating small discrepancies. The attacker exploited these discrepancies repeatedly, using the batchSwap function for chained swaps, resulting in large price distortion and massive liquidity removal.

Other experts attribute the incident to improper authorization and callback handling within Balancer's V2 vaults.

Balancer said its team is working with leading security researchers to fully understand the problem and will release more details about the attack later.

Balancer DeFi hacked: $128 million stolen

The wider implications and the message to the market

The fact that a protocol with extensive audits (Balancer V2 has been audited 11 times since 2021) was affected by such a serious exploit demonstrates that traditional security assessment models are no longer sufficient for DeFi. At the same time, the attack comes at a time when the DeFi market has already suffered significant losses this year — the total cryptocurrency thefts for 2025 have exceeded $2 billion. This means that security in the web3 environment should be considered a top priority for programs, users, and investors.

See also: Hackers exploit RMM tools to penetrate Logistics networks

What the user can do – Protection Guide

The Balancer incident serves as a reminder that DeFi users must adopt proactive security practices. Specifically:

  • Check if you are placed in the affected pools (V2 Composable Stable Pools) and withdraw funds if possible.
  • Revoke or limit token approvals for protocols you are not familiar with.
  • Monitor protocol security announcements and avoid interacting with distributed frontends that may be phishing. Balancer, for example, warned users about potential phishing attempts.
  • Focus on risk diversification: don't put all your funds in one unit/group and consider protocols with proven, multi-layered security measures.
Balancer DeFi hacked: $128 million stolen

Lesson for the entire DeFi ecosystem

The Balancer attack is a critical wake-up call for the entire decentralized finance landscape. No matter how “mature” or audited a protocol is, the nature of the technology — smart contracts, multi-party interactions, multi-network chains — creates complex attack surfaces that must be addressed with constant monitoring, multiple layers of security, and transparency in threat communication. Effective risk management is no longer just the responsibility of developers, but also of users who invest — and investors should demand from protocols not just audits, but active security and crisis management.

See also: New HttpTroy backdoor disguises itself as a VPN invoice

The only certainty? In the rapidly changing web3 landscape, security is not an “optional extra”, but a fundamental parameter for the trust and survival of DeFi protocols.

Source: www.bleepingcomputer.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS