Balancer Got Wrecked in a $100 Million Exploit

TLDR

  • Balancer, one of the biggest and battle-tested DEXs, was exploited for over $100 million.
  • The pools affected were all V2 stable pools.
  • Some funds have been recovered, as whitehat hackers and DeFi security teams took immediate action.

If you woke up on November 3rd to news of a major DeFi exploit, you weren’t dreaming. Balancer, one of the bigger names in decentralized finance, took a hit that sent shockwaves through the crypto world. 

This wasn’t your run-of-the-mill hack. It was a sophisticated exploit targeting a specific type of pool on Balancer V2, and while the damage was significant, the response from the crypto community showed exactly why decentralized doesn’t mean disorganized. 

From whitehat hackers swooping in to save funds to entire blockchains hitting the pause button, this incident became a masterclass in crisis management. Let’s break down this mess. Time to get after it.

What Happened?

Around 7:45 AM UTC on Monday, November 3rd, someone discovered a vulnerability in Balancer V2’s Composable Stable Pools and exploited it. Think of Composable Stable Pools as special containers designed to hold similar assets (like different versions of stablecoins or wrapped tokens) and let people swap between them efficiently.

The problem? A tiny rounding error in how these pools handled certain types of swaps. Sounds boring, right? Except this tiny mathematical hiccup let attackers drain funds from pools across multiple blockchains, including Ethereum, Base, Avalanche, and several others.

Here’s the technical bit made simple: Balancer V2 lets you do “batch swaps,” which bundle multiple transactions together to save on gas fees. These swaps have a cool feature called “deferred settlement” — basically, you can borrow tokens temporarily as long as you pay them back. 

The exploit leveraged this feature, combined with incorrect rounding when scaling token amounts, enabling attackers to manipulate pool balances and withdraw funds that did not belong to them.

The attack specifically targeted Composable Stable V5 pools (older versions that couldn’t be paused anymore) while V6 pools got automatically protected. If you’re using Balancer V3 or any other type of Balancer pool, you’re in the clear — this vulnerability only affected this specific pool type.

The Damage Control Squad

What happened next is honestly pretty impressive. Within minutes of the exploit being detected, an entire crypto emergency response team mobilized. Here’s who showed up to help:

Hypernative caught the exploit at 7:46 AM UTC and by 8:07 AM, all pausable pools were locked down. That’s a 21-minute response time that would make most traditional finance security teams jealous.

Whitehat hackers jumped in under something called the SEAL Safe Harbor framework — a pre-agreed legal protection that lets good-guy hackers rescue funds without worrying about getting sued. BitFinding alone recovered approximately $ 600,000 worth of assets on the Ethereum Mainnet.

StakeWise managed to recover 5,041 osETH (approximately $19M) and 13,495 osGNO (roughly $1.7-2M), representing approximately 73.5% of the stolen osETH. 

Berachain validators actually halted their entire network and initiated an emergency hard fork to contain the damage. That’s like shutting down a highway to catch one specific car — drastic, but effective.

Sonic Labs froze suspected attacker addresses, preventing them from moving or converting stolen funds. Monerium froze about 1.3M EURe tokens. Gnosis restricted bridge activity to stop funds from escaping to other chains.

Even a MEV bot on Base got in on the action, recovering around $150K. When the robots are helping save your funds, you know it’s serious.

Who Got Hit?

The exploit primarily affected users with funds in Composable Stable V5 pools across multiple chains. Major liquidity providers like Crypto.com and Ether.fi were able to safely withdraw their positions (about $800K and $1.061M respectively) once the pause mechanisms kicked in.

The good news? If you’re using Balancer V3, you’re completely unaffected. Same goes for other Balancer V2 pool types like weighted pools or standard liquidity pools. The vulnerability was isolated to this specific subset of pools.

For those stuck in affected V5 pools, the situation is more complicated. The team is still reconciling exactly how much was lost versus recovered, and they’re working with security partners to trace every transaction before releasing official numbers. Any figures you see floating around social media are unconfirmed — the final accounting will come later.

What You Should Do Right Now

First, don’t panic. Check which pools you’re actually using. If you’re in a Composable Stable v6 pool, you can withdraw your funds proportionally through Recovery Mode — you’ll get your share of whatever’s left in the pool.

If you’re in a V5 pool, sit tight and wait for official guidance from Balancer. Don’t interact with these contracts until you get the all-clear.

More importantly, only trust information from Balancer’s official channels. Scammers are already circulating fake messages claiming to be from the Balancer Security Team. Don’t click unknown links. Don’t respond to random DMs offering to “help recover” your funds. If it sounds too good to be true, it’s probably someone trying to steal whatever you have left.

For everyone else watching this unfold, it’s a good reminder to diversify where you keep your crypto. Don’t put all your eggs in one DeFi protocol, no matter how battle-tested it seems. Use hardware wallets for long-term holdings. Keep only what you need for active trading or yield farming in hot wallets or smart contracts.

Beyond Balancer

This exploit is yet another example of how code vulnerabilities can remain hidden for years. We’ve seen this multiple times in 2025, unfortunately. These Composable Stable Pools had been live and audited by top security firms. They had active bug bounty programs. And yet, this specific combination of features created a vulnerability that was not discovered for years.

However, there’s a flip side — when the exploit occurred, the decentralized community responded faster and more effectively than most centralized systems could. Validators coordinated network halts. Whitehat hackers mobilized within minutes. Protocols across different chains worked together to freeze assets and limit damage.

You don’t see that kind of coordination in traditional finance, where one breach can take days or weeks to fully address while lawyers argue about liability.

What Comes Next

Balancer has committed to a comprehensive post-mortem once all the numbers are verified. This will include the technical root cause, the full sequence of mitigation efforts, and recommendations for migrating to Balancer V3 (which remains unaffected and represents the platform’s future).

Recovery efforts are ongoing, with SEAL and various security partners working to trace and potentially recover more funds. Some of this might involve legal action, some might involve negotiating with the attackers under the Safe Harbor framework.

For the broader crypto community, this incident will likely accelerate the push toward formal security frameworks like SEAL, which proved invaluable in coordinating the whitehat response. Expect more protocols to adopt similar pre-agreed legal protections for security researchers.

Stay Safe Out There

The Balancer exploit serves as a stark reminder that DeFi remains decentralized yet vulnerable. It’s exciting, innovative, and occasionally dangerous. However, it’s also proof that the community has improved at responding to crises.

Keep your eyes on official channels for updates. Don’t chase yield in pools you don’t understand. Use multiple wallets and protocols to spread your risk. And remember, in crypto, boring usually beats exciting when it comes to keeping your funds safe.

The investigation continues, more funds may be recovered, and Balancer will release detailed numbers once everything’s verified. Until then, stay cautious, stay informed, and don’t let one exploit scare you away from the genuine innovation happening in DeFi.

Disclaimer

This article is for educational and information purposes, and should not be considered financial advice. For more information visit our disclaimer page

About the Author

Countdown to next draw

days

hours

minutes

seconds