Balancer Breach: Over $116M Stolen in One of DeFi’s Largest Exploits

11-4-2025, 8:26:02 AM
Beginner
Quick Reads
On November 3, 2025, the decentralized finance (DeFi) space faced another major setback as Balancer (BAL) — one of the most established liquidity protocols — suffered a catastrophic exploit. In mere hours, attackers siphoned off over $116 million in assets, shaking confidence across the ecosystem and sparking immediate responses from projects integrated with Balancer V2.

The Exploit: How It Happened

The breach targeted Balancer V2’s Vault module, where attackers exploited a callback authorization flaw. This vulnerability allowed malicious contracts to manipulate liquidity pools and execute unauthorized transfers — not due to private key leaks, but a logic weakness within the contract design itself.

Key Details:

  • Attack vector: improper callback authorization
  • Target: Balancer V2 Vault smart contracts
  • Impact: $116M stolen across multiple blockchains

Type of assets affected: ETH and multiple liquid staking tokens (LSTs) such as WETH, rETH, frxETH, osETH, and rsETH

Chains and Assets Affected


(Image source: lookonchain)

Blockchain analysis confirmed that the Ethereum mainnet bore the brunt of the losses. However, the exploit extended across major networks including Arbitrum, Base, Sonic, Optimism, and Polygon, showcasing the attacker’s deep technical understanding of cross-chain liquidity structures.

Technical Breakdown

Security analysts discovered that the hacker deployed malicious contracts during pool initialization, exploiting a timing issue in the Vault’s state update mechanism. The vulnerability enabled unauthorized swaps and cross-pool balance manipulation, allowing for rapid fund extraction before detection.

Auditors from kebabsec and other independent developers noted that the flaw originated from state inconsistencies before asset withdrawal, rather than a straightforward permission check failure.

Ecosystem Reactions

As panic spread through the DeFi community, several projects with integrations to Balancer moved quickly:

  • Lido withdrew unaffected liquidity positions to prevent exposure.
  • Berachain temporarily halted its network and announced an emergency hard fork to patch vulnerabilities linked to Balancer V2.
  • Berachain’s founder, Smokey The Bera, confirmed coordination with centralized exchanges to blacklist attacker wallets and suspend key protocol functions such as bridging, lending, and HONEY minting.

On-Chain Movements and the “Whale Reaction”


(Image source: lookonchain)

Blockchain trackers observed dramatic activity from a dormant wallet (0x0090) that had been inactive for over three years. Moments after the exploit was disclosed, the whale withdrew over $6.5 million from Balancer — a clear indicator of the market’s growing fear and DeFi users’ hypersensitivity to protocol security.

Tracking the Attacker

On-chain data shows the hacker has been systematically converting stolen LSTs into ETH and USDC through Cow Protocol and various DEX platforms.

Example: 10 osETH → 10.55 ETH, a sign of ongoing laundering through decentralized exchanges and token mixers.

So far, no recovery attempts have succeeded, with security teams focusing on address flagging and real-time monitoring.

How Users Can Protect Themselves

If you interacted with Balancer or hold assets in its pools, immediate steps are recommended:

1.Withdraw all funds from Balancer V2 pools to minimize potential losses.

2.Revoke approvals using tools like Revoke.cash or DeBank to prevent further access by compromised contracts.

3.Stay informed by following Balancer’s official updates and community security channels.

A Wake-Up Call for DeFi Security

The Balancer exploit underscores a persistent issue in DeFi — the fragility of smart contract systems. While decentralization empowers users, it also places the full weight of risk on them and the developers maintaining protocol integrity.

This incident serves as both a devastating loss and a critical learning moment for the industry, emphasizing the need for more rigorous audits, layered defense mechanisms, and faster incident response frameworks.

Conclusion

The Balancer attack is not merely another DeFi hack — it’s a defining event in the ongoing evolution of blockchain security. As projects rebuild and users regain trust, one lesson remains clear: innovation must not come at the expense of security.

Disclaimer:

This is not investment advice. This information is provided for informational purposes only and should not be construed as a recommendation to buy, sell, or hold any asset. Cryptocurrency trading involves a risk of loss. Gate US services may be restricted in certain jurisdictions. For more information, please see our legal disclosures: https://us.gate.com/legal/disclosures

Author: Allen
This is not investment advice. This information is provided for informational purposes only and should not be construed as a recommendation to buy, sell or hold any asset. Cryptocurrency trading involves a risk of loss.
Gate US services may be restricted in certain jurisdictions. For more information, please see our legal disclosures: https://us.gate.com/legal/disclosures

Share

Crypto Calendar
Abu Dhabi Meetup
Helium will host the Helium House networking event on December 10 in Abu Dhabi, positioned as a prelude to the Solana Breakpoint conference scheduled for December 11–13. The one-day gathering will focus on professional networking, idea exchange and community discussions within the Helium ecosystem.
HNT
-0.85%
2025-12-09
Hayabusa Upgrade
VeChain has unveiled plans for the Hayabusa upgrade, scheduled for December. This upgrade aims to significantly enhance both protocol performance and tokenomics, marking what the team calls the most utility-focused version of VeChain to date.
VET
-3.53%
2025-12-27
Litewallet Sunsets
Litecoin Foundation has announced that the Litewallet app will officially sunset on December 31. The app is no longer actively maintained, with only critical bug fixes addressed until that date. Support chat will also be discontinued after this deadline. Users are encouraged to transition to Nexus Wallet, with migration tools and a step-by-step guide provided within Litewallet.
LTC
-1.1%
2025-12-30
OM Tokens Migration Ends
MANTRA Chain issued a reminder for users to migrate their OM tokens to the MANTRA Chain mainnet before January 15. The migration ensures continued participation in the ecosystem as $OM transitions to its native chain.
OM
-4.32%
2026-01-14
CSM Price Change
Hedera has announced that starting January 2026, the fixed USD fee for the ConsensusSubmitMessage service will increase from $0.0001 to $0.0008.
HBAR
-2.94%
2026-01-27
sign up guide logosign up guide logo
sign up guide content imgsign up guide content img
Start Now
Unlock more opportunities today
Create Account

Related Articles

Bitcoin Halving Chart: Key Dates, Trends, and Future Predictions
Beginner

Bitcoin Halving Chart: Key Dates, Trends, and Future Predictions

Discover Bitcoin halving history, key dates, trends, and price predictions. Learn how the latest April 2024 halving impacts supply, mining, and market trends.
11-26-2025, 9:44:31 AM
Bitcoin Halving Chart:Understanding the Changes in Bitcoin Supply and Price Trends
Beginner

Bitcoin Halving Chart:Understanding the Changes in Bitcoin Supply and Price Trends

The Bitcoin Halving is a significant event that not only changes the supply dynamics of Bitcoin but also results in significant price fluctuations after each halving. By looking at the Bitcoin Halving chart, we can clearly see the impact of each halving on the market, miners, prices, and market sentiment. In the future, as the Bitcoin supply gradually approaches its limit, the significance of the halving event will become increasingly important. For investors and miners, understanding the patterns of Bitcoin Halving and its market impact will help make wiser decisions in the dynamic cryptocurrency market.
11-26-2025, 9:43:18 AM
US December Rate Cut Forecast: Will the Federal Reserve Finally Pivot?
Beginner

US December Rate Cut Forecast: Will the Federal Reserve Finally Pivot?

With inflation cooling and the labor market losing steam, markets are debating whether the Federal Reserve will cut rates in December. This article breaks down data, expectations, and potential impacts.
11-18-2025, 7:39:52 AM
Midnight Network Ignites Cardano’s Next Chapter with NIGHT Token Mining and Privacy Innovation
Beginner

Midnight Network Ignites Cardano’s Next Chapter with NIGHT Token Mining and Privacy Innovation

Cardano’s ecosystem is experiencing renewed excitement as the Midnight Network launches its NIGHT token mining program, unlocking new possibilities for privacy technology and decentralized participation. With zero-knowledge proofs, community-driven distribution, and major technical upgrades on the Cardano mainnet, the project signals a new era of growth and innovation.
11-3-2025, 8:22:43 AM
Federal Reserve Ends Quantitative Tightening — How the End of QT Could Reshape Global Markets in 2025
Beginner

Federal Reserve Ends Quantitative Tightening — How the End of QT Could Reshape Global Markets in 2025

The Federal Reserve officially ends Quantitative Tightening, easing liquidity pressure and reshaping expectations for bonds, stocks, the dollar, and global risk assets.
12-3-2025, 11:51:12 AM
DeFi TVL Hits $237 Billion: What the 2025 Surge Means for Crypto Investor
Beginner

DeFi TVL Hits $237 Billion: What the 2025 Surge Means for Crypto Investor

Global DeFi TVL surged to $237B in 2025, reaching a multi-year high. Discover what’s driving this growth, the top blockchains by TVL, and what it means for investors.
11-4-2025, 11:11:02 AM