Skip to content

Balancer Pool Hacked $234K Vulnerability Exploited

Balancer V1 Pool Exploited for $234,000 Due to Rounding Error

  • A Balancer V1 pool lost approximately $234,000 on August 31 due to a rounding-error exploit.
  • The attacker compressed WBTC reserves to dust, minting full BPT for a rounded-down input of just one satoshi.
  • Balancer Labs shut down in March after a similar bug drained $116 million from its V2 pools in November.
  • The exploit targeted the joinswapPoolAmountOut function using reverse calculation with fixed-point math.
  • The contract lacked safeguards like minimum effective input and relative-error validation during ordinary swaps.

This incident highlights ongoing vulnerabilities in decentralized finance (DeFi) protocols like Balancer, where rounding errors can be exploited for significant financial gain. The attack’s similarity to previous exploits underlines the importance of robust security measures in smart contracts.

Despite Balancer Labs’ closure following past security incidents, vulnerabilities persist, as demonstrated by this recent exploit involving WBTC reserves and BPT minting processes.(Source)

Share