Balancer V2 Hack

Reported loss $128M
Arbitrum Base Ethereum Optimism Polygon Sonic
Composable Stable Pools Exploit

What happened

On November 3, 2025, attackers exploited rounding errors in Balancer V2 Composable Stable Pools. Balancer's post-mortem reports $121.1 million in losses; Check Point estimates $128.64 million across six networks. These estimates should not be treated as interchangeable.

Balancer's separate $45.7 million protected-or-recovered figure includes funds prevented from being stolen, so it is not a reimbursement total.

Technical root cause

In _swapGivenOut, scaling rounded the output amount down before StableMath calculated the input, allowing underpayment. Rate-provider imprecision, low liquidity and BPT composability made the error exploitable. The internal-balance feature was used for extraction but did not cause the vulnerability.

How it happened

  1. The attacker used BPT exit-swaps to reduce vulnerable pool liquidity and amplify rounding errors.
  2. Exact-out swaps calculated insufficient input for the requested output.
  3. Repeated swaps reduced the invariant and BPT value, leaving surplus assets after settlement.
  4. Funds accumulated in Vault internal balances and were subsequently withdrawn.
  5. Responders paused vulnerable V6 pools, activated recovery mode and conducted rescue operations.

Protocol details

Classification Protocol Logic / Exchange (DEX) / Token & Share Accounting
Protocol Type DEX
Implementation language Solidity
Protocol links Website @Balancer

Security review history

Funds Recovery

38.1%

Recovered

$48.8M

Net Loss

$79,232,000

Post-Incident Timeline

  • 2025-11-28

    Total Recovered: ~$48.8 million StakeWise Recovery: $20.7 million Berachain Full Recovery: $12.8 million White-hat and Internal Recoveries: ~$8 million Additional MEV Bot Recoveries: $750,000+

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.