Balancer Breach: Over $116M Stolen in One of DeFi’s Largest Exploits

11/4/2025, 8:26:02 AM
Beginner
Quick Reads
On November 3, 2025, the decentralized finance (DeFi) space faced another major setback as Balancer (BAL) — one of the most established liquidity protocols — suffered a catastrophic exploit. In mere hours, attackers siphoned off over $116 million in assets, shaking confidence across the ecosystem and sparking immediate responses from projects integrated with Balancer V2.

The Exploit: How It Happened

The breach targeted Balancer V2’s Vault module, where attackers exploited a callback authorization flaw. This vulnerability allowed malicious contracts to manipulate liquidity pools and execute unauthorized transfers — not due to private key leaks, but a logic weakness within the contract design itself.

Key Details:

  • Attack vector: improper callback authorization
  • Target: Balancer V2 Vault smart contracts
  • Impact: $116M stolen across multiple blockchains

Type of assets affected: ETH and multiple liquid staking tokens (LSTs) such as WETH, rETH, frxETH, osETH, and rsETH

Chains and Assets Affected


(Image source: lookonchain)

Blockchain analysis confirmed that the Ethereum mainnet bore the brunt of the losses. However, the exploit extended across major networks including Arbitrum, Base, Sonic, Optimism, and Polygon, showcasing the attacker’s deep technical understanding of cross-chain liquidity structures.

Technical Breakdown

Security analysts discovered that the hacker deployed malicious contracts during pool initialization, exploiting a timing issue in the Vault’s state update mechanism. The vulnerability enabled unauthorized swaps and cross-pool balance manipulation, allowing for rapid fund extraction before detection.

Auditors from kebabsec and other independent developers noted that the flaw originated from state inconsistencies before asset withdrawal, rather than a straightforward permission check failure.

Ecosystem Reactions

As panic spread through the DeFi community, several projects with integrations to Balancer moved quickly:

  • Lido withdrew unaffected liquidity positions to prevent exposure.
  • Berachain temporarily halted its network and announced an emergency hard fork to patch vulnerabilities linked to Balancer V2.
  • Berachain’s founder, Smokey The Bera, confirmed coordination with centralized exchanges to blacklist attacker wallets and suspend key protocol functions such as bridging, lending, and HONEY minting.

On-Chain Movements and the “Whale Reaction”


(Image source: lookonchain)

Blockchain trackers observed dramatic activity from a dormant wallet (0x0090) that had been inactive for over three years. Moments after the exploit was disclosed, the whale withdrew over $6.5 million from Balancer — a clear indicator of the market’s growing fear and DeFi users’ hypersensitivity to protocol security.

Tracking the Attacker

On-chain data shows the hacker has been systematically converting stolen LSTs into ETH and USDC through Cow Protocol and various DEX platforms.

Example: 10 osETH → 10.55 ETH, a sign of ongoing laundering through decentralized exchanges and token mixers.

So far, no recovery attempts have succeeded, with security teams focusing on address flagging and real-time monitoring.

How Users Can Protect Themselves

If you interacted with Balancer or hold assets in its pools, immediate steps are recommended:

1.Withdraw all funds from Balancer V2 pools to minimize potential losses.

2.Revoke approvals using tools like Revoke.cash or DeBank to prevent further access by compromised contracts.

3.Stay informed by following Balancer’s official updates and community security channels.

A Wake-Up Call for DeFi Security

The Balancer exploit underscores a persistent issue in DeFi — the fragility of smart contract systems. While decentralization empowers users, it also places the full weight of risk on them and the developers maintaining protocol integrity.

This incident serves as both a devastating loss and a critical learning moment for the industry, emphasizing the need for more rigorous audits, layered defense mechanisms, and faster incident response frameworks.

Conclusion

The Balancer attack is not merely another DeFi hack — it’s a defining event in the ongoing evolution of blockchain security. As projects rebuild and users regain trust, one lesson remains clear: innovation must not come at the expense of security.

Disclaimer:

This is not investment advice. This information is provided for informational purposes only and should not be construed as a recommendation to buy, sell, or hold any asset. Cryptocurrency trading involves a risk of loss. Gate US services may be restricted in certain jurisdictions. For more information, please see our legal disclosures: https://us.gate.com/legal/disclosures

Author: Allen
This is not investment advice. This information is provided for informational purposes only and should not be construed as a recommendation to buy, sell or hold any asset. Cryptocurrency trading involves a risk of loss.
Gate US services may be restricted in certain jurisdictions. For more information, please see our legal disclosures: https://us.gate.com/legal/disclosures

Share

Crypto Calendar
DeFi Day Del Sur in Buenos Aires
Aave reports that the fourth edition of DeFi Day del Sur will be held in Buenos Aires on November 19th.
AAVE
-1.32%
2025-11-18
DevConnect in Buenos Aires
COTI will participate in DevConnect in Buenos Aires on November 17th-22nd.
COTI
-5.31%
2025-11-21
Tokens Unlock
Hyperliquid will unlock 9,920,000 HYPE tokens on November 29th, constituting approximately 2.97% of the currently circulating supply.
HYPE
14.47%
2025-11-28
Abu Dhabi Meetup
Helium will host the Helium House networking event on December 10 in Abu Dhabi, positioned as a prelude to the Solana Breakpoint conference scheduled for December 11–13. The one-day gathering will focus on professional networking, idea exchange and community discussions within the Helium ecosystem.
HNT
-0.85%
2025-12-09
Hayabusa Upgrade
VeChain has unveiled plans for the Hayabusa upgrade, scheduled for December. This upgrade aims to significantly enhance both protocol performance and tokenomics, marking what the team calls the most utility-focused version of VeChain to date.
VET
-3.53%
2025-12-27
sign up guide logosign up guide logo
sign up guide content imgsign up guide content img
Start Now
Unlock more opportunities today
Create Account

Related Articles

Midnight Network Ignites Cardano’s Next Chapter with NIGHT Token Mining and Privacy Innovation
Beginner

Midnight Network Ignites Cardano’s Next Chapter with NIGHT Token Mining and Privacy Innovation

Cardano’s ecosystem is experiencing renewed excitement as the Midnight Network launches its NIGHT token mining program, unlocking new possibilities for privacy technology and decentralized participation. With zero-knowledge proofs, community-driven distribution, and major technical upgrades on the Cardano mainnet, the project signals a new era of growth and innovation.
11/3/2025, 8:22:43 AM
DeFi TVL Hits $237 Billion: What the 2025 Surge Means for Crypto Investor
Beginner

DeFi TVL Hits $237 Billion: What the 2025 Surge Means for Crypto Investor

Global DeFi TVL surged to $237B in 2025, reaching a multi-year high. Discover what’s driving this growth, the top blockchains by TVL, and what it means for investors.
11/4/2025, 11:11:02 AM
Understanding the Liquidation Heat Map: How Traders Use It to Spot Hidden Risk Zones
Beginner

Understanding the Liquidation Heat Map: How Traders Use It to Spot Hidden Risk Zones

Learn what a liquidation heat map is and how to read it. Discover how traders use this visual tool to detect liquidation clusters and manage risk effectively.
11/6/2025, 8:34:17 AM
Polymarket Bets on Satoshi Nakamoto Moving Bitcoin in 2025 Surge from 2% to 15%: What Does It Mean for the Market?
Beginner

Polymarket Bets on Satoshi Nakamoto Moving Bitcoin in 2025 Surge from 2% to 15%: What Does It Mean for the Market?

Polymarket’s odds of Satoshi Nakamoto moving Bitcoin in 2025 have jumped from 2% to 15%. Here’s why traders are betting on the mysterious Bitcoin founder again.
11/6/2025, 8:37:54 AM
COAI Token Uncovered: A Beginner’s Guide to the ChainOpera AI Ecosystem
Beginner

COAI Token Uncovered: A Beginner’s Guide to the ChainOpera AI Ecosystem

Discover what the COAI token is, how the ChainOpera AI ecosystem works, recent price and listing updates, and what beginners should know before diving in.
10/28/2025, 9:12:34 AM
MetaMask Multi-Chain Accounts Launch at End of October – One Wallet to Rule All Networks
Beginner

MetaMask Multi-Chain Accounts Launch at End of October – One Wallet to Rule All Networks

MetaMask will launch its multi-chain accounts feature at the end of October, letting you manage EVM and non-EVM networks in one wallet. A beginner’s guide to what this means and how to use it.
10/24/2025, 9:58:18 AM