Hackers exploited a vulnerability in the Balancer DeFi protocol's V2 pools, resulting in the theft of over $120 million in cryptocurrency, with at least $99 million stolen in ETH. The attack targeted Balancer's Compostable Stable Pools and was traced to either a precision rounding error in the Vault’s swap calculations or faulty access control mechanisms, allowing the attacker to manipulate token swaps and balances. Balancer confirmed that the exploit did not impact its V3 pools and has paused affected pools while working with security researchers to investigate the incident.
The company has warned users to be vigilant against phishing attempts and fraudulent messages purporting to be from its security team. Several other blockchain organizations connected to Balancer, such as the Berachain Foundation, Gnosis, Sonic, and Beefy, took emergency measures to protect user assets, including halting networks and freezing stolen funds where possible. Despite Balancer's history of multiple security audits and bug bounty programs, this incident highlights ongoing risks in DeFi protocols. A full post-mortem is expected once the investigation concludes.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On 2025-11-07, Trail of Bits published an analysis attributing the hack to a long-standing arithmetic edge case in Balancer v2, confirmed Balancer v3 was not affected, and issued broader defensive guidance for the DeFi ecosystem.
News outlets reported on 2025-11-03 that Balancer had suffered a major DeFi exploit, with estimated losses ranging from roughly $116 million to more than $120 million.
On 2025-11-03, attackers exploited a rounding-direction vulnerability in Balancer v2’s Stable Math logic, draining more than $100 million from vulnerable Composable Stable Pools across nine blockchain networks.
During a 2021 review of Balancer’s Linear Pools, Trail of Bits reported the same underlying arithmetic edge case later tied to the 2025 exploit, although its full exploitability was not understood at the time.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
blog.trailofbits.com
Open sourcesecurityboulevard.com
Open sourcethecyberexpress.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.