Market Maker Balancer Compromised: Key Facts Behind The $128 Million Hack

bitcoinist發佈於 2025-11-04更新於 2025-11-04

文章摘要

The decentralized finance (DeFi) protocol and market maker Balancer recently suffered a significant exploit, resulting in the loss of over...

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

The decentralized finance (DeFi) protocol and market maker Balancer recently suffered a significant exploit, resulting in the loss of over $120 million in digital assets.

According to blockchain security firms, the total losses have now reached approximately $128 million, with ongoing withdrawals from the attacker’s wallet still being reported.

Details Of Balancer Attack

In a post on social media platform X (previously Twitter), Balancer acknowledged the exploit, stating that its engineering and security teams were investigating the breach with high priority. They added:

Balancer is committed to operational security, has undergone extensive auditing by top firms, and had bug bounties running for a long time to incentivize independent auditors. We are working closely with our security and legal teams to ensure user safety and are conducting a swift & thorough investigation. We’re grateful to our partners and the broader DeFi community for their support.

The company’s Chief Executive, Deddy Lavid, explained that the ongoing drain of funds likely results from compromised access control mechanisms within the protocol, which allowed the attackers to manipulate balances directly.

Market expert Adi Flips provided further insights into the exploit, detailing how the attack targeted Balancer’s V2 vaults and liquidity pools by exploiting vulnerabilities in the interactions of smart contracts. 

Preliminary investigations indicate that the exploit involved a maliciously deployed contract that manipulated vault calls during the initialization of pools. This manipulation was made possible due to improper authorization and callback handling, which allowed the attacker to circumvent existing safeguards. 

As a result, unauthorized swaps and balance manipulations occurred across interconnected pools, enabling the rapid drainage of assets within minutes.

The attack was initiated with a pivotal transaction on the Ethereum (ETH) mainnet, which directed assets to a new wallet controlled by the perpetrator. Following this, the stolen funds were consolidated, likely for laundering through mixers or bridges.

Stolen Assets Breakdown

The design of Balancer’s protocol, which allows for heavy interaction among its pools, exacerbated the impact of the exploit, according to Adi Flips’ analysis. 

He stated that similar vulnerabilities have been observed in automated market makers (AMMs) in the past, often linked to how they handle deflationary tokens or manage pool rebalancing.

Importantly, there is currently no evidence suggesting that a private key was compromised. The expert noted that this incident appears to be a pure smart contract exploit.

The breakdown of the stolen assets includes over $70 million in Ethereum, with additional losses of around $7 million from Base and Sonic combined, and approximately $2 million from other chains. 

According to ongoing investigations, the estimated total theft of the main assets, including wrapped Ethereum (WETH), staked Ethereum (wstETH), osETH, frxETH, rsETH, and rETH, is between $116 million and $128 million.

Balancer
The daily chart shows the total crypto market cap drop toward $3.51 trillion on Monday. Source: TOTAL on TradingView.com

Featured image from DALL-E, chart from TradingView.com

Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

Ronaldo is a seasoned crypto enthusiast with over four years of experience in the field. He is passionate about exploring the vast and dynamic world of decentralized finance (DeFi) and its practical applications for achieving economic sovereignty. Ronaldo is constantly seeking to expand his knowledge and expertise in the DeFi space, as he believes it holds tremendous potential for transforming the traditional financial landscape.

你可能也喜歡

DeepSeek永久降价,但梁文锋并不想做「赛博菩萨」

DeepSeek宣布将V4-Pro API的75%折扣永久化,全球同步生效,基础输入/输出价格大幅降低至0.435美元/百万Token和0.87美元/百万Token。在AI行业普遍涨价的背景下,这一逆势降价行动被社区称为“赛博菩萨”行为。但创始人梁文锋并非纯粹做慈善,而是选择了开源普惠的商业模式。 当前AI行业正变得越来越贵,微软、Uber等大公司的Token预算消耗远超预期,而Anthropic、OpenAI和谷歌等巨头已在过去六个月内悄悄提价。随着用户习惯建立,AI补贴时代已结束,供需关系反转导致价格上涨。 DeepSeek的持续降价展现了一种反向定价权。其竞争力来源于多个方面:国产昇腾算力支持未来将进一步降低成本;中国相对较低的AI人才成本;最重要的是能源体系优势——中国西部绿电价格仅为欧美的1/5到1/4,且拥有完整的电力结构和“东数西算”等调度能力,电力成本占AI运营成本的60%-70%,这构成了系统性的成本优势。 虽然DeepSeek V4与顶尖闭源模型仍有客观差距,且商业收入目前落后于国内其他AI公司,但其极低的推理成本(仅为GPT-5.5的约1%到11%)满足了大量实际商业场景对“勉强能用+足够便宜+足够稳定”的需求。当AI整体越贵,DeepSeek的性价比优势就越突出,其商业价值也由此体现。

marsbit9 小時前

DeepSeek永久降价,但梁文锋并不想做「赛博菩萨」

marsbit9 小時前

Mythos的面纱,成了Anthropic撬动万亿的杠杆

Anthropic公司即将以超9000亿美元估值完成巨额融资,其核心策略是通过构建“Mythos”模型的强大叙事来撬动资本与市场。Mythos被描述为“强到不能公开发布”的AI模型,与之相关的网络安全项目“Glasswing”虽公布了一些漏洞发现数据,但缺乏可验证的参照系,巧妙地将“不公开”包装为责任感和技术卓越的证明。 同时,美国政府的态度变化为叙事提供了关键背书。尽管曾将Anthropic列为供应链风险,但白宫及NSA等机构被曝寻求使用其高级模型(很可能是Mythos),这传递出该技术“不可替代”且通过最高标准审查的信号,极大地增强了其可信度与商业价值。 商业数据方面,Anthropic向投资者展示了惊人的收入增长,特别是Claude Code产品增长迅猛,推动公司整体年化收入预期超过500亿美元。谷歌持续巨额投资(承诺最高400亿美元)则提供了强大的资本背书,吸引了更多投资人跟进,共同推高估值。 本质上,Anthropic的成功在于其卓越的“讲故事”能力:它将一个无法被公众验证的技术能力(Mythos),结合政府机构的“隐性”认可、爆炸性的收入预期以及顶级投资者的真金白银,整合成一个强大且自洽的叙事。这个叙事说服了市场中最有影响力的参与者,从而将“不可验证的潜力”转化为实实在在的万亿级估值。

marsbit12 小時前

Mythos的面纱,成了Anthropic撬动万亿的杠杆

marsbit12 小時前

交易

現貨
合約
活动图片