Balancer Hack
Incident Overview
Balancer V2 liquidity pools were exploited via a flash loan attack resulting in a loss of 1,898,586 USD worth of stablecoins.
Balancer, an AMM-based DEX running on multiple chains including Ethereum, Optimism, and Fantom, was exploited on August 27, 2023. The attacker exploited the Balancer V2 liquidity pools in multiple transactions via a flashloan attack. They took a flash loan from Aave and used the loaned funds to exploit Balancer's smart contracts.
Balancer had made their users aware of the vulnerability on January 6, 2023, and mentioned that they started the mitigation process. On August 22, 2023, they disclosed that they had mitigated over 80% of the funds, while 4% of Balancer's TVL was still at risk. Users were advised to withdraw affected LPs immediately.
The stolen funds in all three affected chains were swapped for DAI and then bridged to the mainnet. The funds were transferred to other EOAs that are currently holding the funds as of August 29, 2023. The total loss was 1,898,586 USD worth of stablecoins such as USDT, USDC, and DAI.
This included 1,000,377 USD from Ethereum, 221,855 USD from the Optimism chain, and 676,354 USD from the Fantom chain.
Attackers:
- https://etherscan.io/address/0xEd187F37β¦2b7a9B
- https://optimistic.etherscan.io/address/0xbc794f1fβ¦b8fd3c
- https://ftmscan.com/address/0x64e08fa8β¦c86760
Funds Holders as of Aug 28, 2023:
- https://etherscan.io/address/0xb23711b9β¦df38c1
- https://etherscan.io/address/0x429313e5β¦b5762f
- https://etherscan.io/address/0xbc794f1fβ¦b8fd3c
Malicious Transactions:
- https://etherscan.io/tx/0x2a027c8bβ¦606c2d
- https://etherscan.io/tx/0x773fa597β¦0bfa4a
- https://etherscan.io/tx/0x42441d8eβ¦80daa4
- https://etherscan.io/tx/0x72a655ceβ¦64686e
- https://etherscan.io/tx/0x85d7aec3β¦b3c2df
Malicious Contracts:
- https://etherscan.io/address/0x2100dCd8β¦2944f0
- https://etherscan.io/address/0x48567fb8β¦af103b
- https://etherscan.io/address/0x7bceff0aβ¦b3ccca
- https://etherscan.io/address/0x254c36e9β¦A1eE14
- https://etherscan.io/address/0x561b6b0dβ¦647a1d
Funds Transfer Transactions:
- https://etherscan.io/tx/0x549e2865β¦ce616a
- https://etherscan.io/tx/0xa2b6caf2β¦495c44
- https://etherscan.io/tx/0x3e4bcdc3β¦58f1c4
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Balancer, these are the critical security checks that could have prevented this incident (August 2023).
- Verify all logic paths related to Flash Loan Attack are guarded by proper access controls and input validation - see the Flash Loans Attacks attack class for patterns
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialRelated Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Sources & References
Learn to Prevent the Next Balancer
The Balancer hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.