Market Maker Balancer Compromised: Key Facts Behind The $128 Million Hack

bitcoinistОпубліковано о 2025-11-04Востаннє оновлено о 2025-11-04

Анотація

The decentralized finance (DeFi) protocol and market maker Balancer recently suffered a significant exploit, resulting in the loss of over...

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

The decentralized finance (DeFi) protocol and market maker Balancer recently suffered a significant exploit, resulting in the loss of over $120 million in digital assets.

According to blockchain security firms, the total losses have now reached approximately $128 million, with ongoing withdrawals from the attacker’s wallet still being reported.

Details Of Balancer Attack

In a post on social media platform X (previously Twitter), Balancer acknowledged the exploit, stating that its engineering and security teams were investigating the breach with high priority. They added:

Balancer is committed to operational security, has undergone extensive auditing by top firms, and had bug bounties running for a long time to incentivize independent auditors. We are working closely with our security and legal teams to ensure user safety and are conducting a swift & thorough investigation. We’re grateful to our partners and the broader DeFi community for their support.

The company’s Chief Executive, Deddy Lavid, explained that the ongoing drain of funds likely results from compromised access control mechanisms within the protocol, which allowed the attackers to manipulate balances directly.

Market expert Adi Flips provided further insights into the exploit, detailing how the attack targeted Balancer’s V2 vaults and liquidity pools by exploiting vulnerabilities in the interactions of smart contracts. 

Preliminary investigations indicate that the exploit involved a maliciously deployed contract that manipulated vault calls during the initialization of pools. This manipulation was made possible due to improper authorization and callback handling, which allowed the attacker to circumvent existing safeguards. 

As a result, unauthorized swaps and balance manipulations occurred across interconnected pools, enabling the rapid drainage of assets within minutes.

The attack was initiated with a pivotal transaction on the Ethereum (ETH) mainnet, which directed assets to a new wallet controlled by the perpetrator. Following this, the stolen funds were consolidated, likely for laundering through mixers or bridges.

Stolen Assets Breakdown

The design of Balancer’s protocol, which allows for heavy interaction among its pools, exacerbated the impact of the exploit, according to Adi Flips’ analysis. 

He stated that similar vulnerabilities have been observed in automated market makers (AMMs) in the past, often linked to how they handle deflationary tokens or manage pool rebalancing.

Importantly, there is currently no evidence suggesting that a private key was compromised. The expert noted that this incident appears to be a pure smart contract exploit.

The breakdown of the stolen assets includes over $70 million in Ethereum, with additional losses of around $7 million from Base and Sonic combined, and approximately $2 million from other chains. 

According to ongoing investigations, the estimated total theft of the main assets, including wrapped Ethereum (WETH), staked Ethereum (wstETH), osETH, frxETH, rsETH, and rETH, is between $116 million and $128 million.

Balancer
The daily chart shows the total crypto market cap drop toward $3.51 trillion on Monday. Source: TOTAL on TradingView.com

Featured image from DALL-E, chart from TradingView.com

Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

Ronaldo is a seasoned crypto enthusiast with over four years of experience in the field. He is passionate about exploring the vast and dynamic world of decentralized finance (DeFi) and its practical applications for achieving economic sovereignty. Ronaldo is constantly seeking to expand his knowledge and expertise in the DeFi space, as he believes it holds tremendous potential for transforming the traditional financial landscape.

Пов'язані матеріали

DeepSeek Announces Permanent Price Cut, But Liang Wenfeng Is Not Trying to Be a "Cyber Bodhisattva"

DeepSeek has announced a permanent 75% discount on its V4-Pro API, significantly reducing its token prices. This move stands out as a major industry-wide price cut while competitors like Anthropic, OpenAI, and Google have been quietly raising theirs. The article contrasts this strategy with the broader trend of AI becoming more expensive, citing examples of companies like Microsoft and Uber struggling with high token costs as usage soars. While CEO Liang Wenfeng is hailed by some as a "Cyber Bodhisattva" for this普惠 approach, the article argues this is a strategic business choice, not mere altruism. DeepSeek's ability to maintain low prices is attributed to several structural advantages: lower-cost AI talent in China, the impending use of domestic昇腾 hardware for further cost reductions, and, most critically, access to China's cheaper and more abundant energy infrastructure, which drastically reduces the electricity costs dominating AI operations. The analysis suggests that for many commercial applications, a "good enough" model that is radically cheaper (e.g., 1% to 11% of GPT-5.5's cost) is more valuable than the absolute top-tier model. This allows for vastly more experimentation and iteration within a budget. Therefore, as AI generally becomes more expensive, DeepSeek's cost-competitiveness—rooted in China's energy and talent advantages—becomes its core strategic value and differentiator in the global market.

marsbit9 год тому

DeepSeek Announces Permanent Price Cut, But Liang Wenfeng Is Not Trying to Be a "Cyber Bodhisattva"

marsbit9 год тому

The Veil of Mythos Becomes Anthropic's Lever to Move Trillions

The article discusses Anthropic's reported upcoming $30 billion funding round, which would value the company at over $900 billion. It analyzes how the company has leveraged strategic narratives around its unreleased "Mythos" model, rather than just its publicly available products, to drive this massive valuation. Key points include Google's surprising $40 billion investment in a competitor, suggesting it is buying strategic positioning. Anthropic's "Glasswing" cybersecurity project and the unreleased Mythos model are portrayed not through direct proof, but through carefully crafted narratives of being "too powerful for public release," creating an aura of exclusive, high-level capability. This is bolstered by reports of the White House and NSA seeking access to Claude/Mythos despite previous security concerns, implying indispensable technology. Furthermore, Anthropic's reported rapid revenue growth—from a $1 billion annual run-rate in late 2024 to over $30 billion by April 2026, largely driven by enterprise API and Claude Code—provides a financial story for investors. The article concludes that Anthropic's core business model is effectively converting unverifiable technical potential, government interest, and future revenue projections into a compelling narrative that secures immense capital, using the actions of wealthy investors and powerful institutions as the ultimate validation of its worth.

marsbit12 год тому

The Veil of Mythos Becomes Anthropic's Lever to Move Trillions

marsbit12 год тому

Торгівля

Спот
Ф'ючерси
活动图片