Balancer Hack Exposes DeFi Vulnerability: Over $116 Million Drained Across Chains

11/4/2025, 4:35:33 AM
Beginner
Quick Reads
On November 3, 2025, the decentralized finance (DeFi) sector suffered a significant setback when the Balancer protocol, a prominent liquidity platform, was discovered to have a critical security vulnerability. Hackers exploited this flaw and stole over $116 million in digital funds within hours.

Balancer Hacked

Decentralized Finance (DeFi) faced another significant challenge. On November 3, 2025, the veteran liquidity protocol Balancer (BAL) experienced a major security vulnerability. Hackers stole over $116 million in assets within hours. The event prompted immediate concern within the on-chain community and ranks among the largest and most significant hacks in DeFi history.

On-chain analytics show the attacker targeted the Vault component of Balancer V2’s smart contract, exploiting insufficient authorization checks and callback-related vulnerabilities to manipulate liquidity pools and transfer assets without authorization. This breach did not result from a leaked private key, but rather a fundamental logic flaw in the smart contract itself.

Ethereum Severely Impacted


(Source: lookonchain)

As of now, Lookonchain’s wallet monitoring confirms that hackers have stolen over $116 million, with assets spanning major chains including Ethereum Mainnet, Arbitrum, Base, Sonic, Optimism, and Polygon. The stolen funds primarily include various liquid staking tokens (LSTs) such as rETH, frxETH, osETH, and rsETH—demonstrating a strong understanding of cross-chain DeFi asset structures.

Smart Contract Callback Vulnerability at the Core

Security researchers found that the attacker deployed malicious contracts during liquidity pool initialization, exploiting weak Vault authorization checks and abnormal state updates to bypass safeguards. This enabled unauthorized swaps across pools or manipulation of pool balances, allowing the attacker to quickly move assets.

Audit firm Kebabsec and several developers confirmed that the incident’s root cause was not authorization errors, but transaction state changes prior to withdrawal—enabling malicious exploitation during asset settlement.

Ecosystem Response

As the hack unfolded, several protocols deeply integrated with Balancer acted swiftly to protect themselves:

  • Lido rapidly withdrew its unaffected positions from Balancer to prevent risk contagion.
  • Berachain immediately suspended network operations and announced an emergency hard fork to patch vulnerabilities in the BEX platform linked to Balancer V2.

Berachain’s founder, Smokey The Bera, stated the team is collaborating with multiple centralized exchanges to blacklist the attacker’s wallet, while halting bridging, lending, and HONEY minting functions to protect liquidity providers’ capital.

Crypto Whales Rush to Withdraw


(Source: lookonchain)

One dormant wallet (0x0090) became a focal point during the incident. Lookonchain’s analysis revealed this whale sprang to life after news of the Balancer exploit broke, urgently withdrawing over $6.5 million in assets. This move illustrates market volatility and highlights DeFi investors’ heightened awareness of security threats.

Tracking the Hackers

On-chain analysts discovered the attacker is using Cow Protocol and multiple DEX platforms to gradually swap stolen LST assets into major tokens like ETH and USDC. For instance, 10 osETH was converted into 10.55 ETH, demonstrating the use of laundering and mixing techniques to complicate tracking efforts.

As of this writing, there is no sign the stolen funds can be recovered. Security teams are blacklisting wallet addresses and conducting ongoing on-chain surveillance to contain the threat.

How Can Investors Protect Themselves?

Balancer users and DeFi investors should take the following steps:

  • Withdraw immediately: Remove assets from Balancer V2 pools to prevent further losses.
  • Revoke permissions: Use Revoke.cash or DeBank to check and remove Balancer-related authorizations.
  • Monitor risk: Stay updated with official announcements and on-chain monitoring to guard against potential follow-up attacks.

Conclusion

The Balancer exploit once again exposes the vulnerability of smart contract security. While decentralization and self-custody lie at DeFi’s core, they also place full responsibility on users and developers. Going forward, balancing innovation and security will be critical to the future of decentralized finance. This incident may have lasting effects on Balancer, but it could also serve as a catalyst for upgrading DeFi’s security infrastructure.

Author: Allen
* The information is not intended to be and does not constitute financial advice or any other recommendation of any sort offered or endorsed by Gate.
* This article may not be reproduced, transmitted or copied without referencing Gate. Contravention is an infringement of Copyright Act and may be subject to legal action.

Share

Crypto Calendar
Blok Zinciri Gelecekçi Konferansı Miami'de
Bone ShibaSwap, 5-6 Kasım tarihlerinde Miami'de düzenlenecek Blockchain Futurist Konferansı'na katılacak.
BONE
-7.03%
2025-11-05
Yapıcılar Savaşı
Cardano, 11 Kasım'da Cardano üzerinde inşa eden veya inşa etmeyi planlayan projeler için bir canlı sunum etkinliği olan Battle of the Builders'ı planlıyor. İlk üç takım ödüller kazanacak ve başvurular 3 Ekim'e kadar açık olacak.
ADA
-3.44%
2025-11-10
X'te AMA
Sushi, Hemi Network ile birlikte 13 Mart'ta UTC saatine göre 18:00'de X üzerinde bir AMA düzenleyecek ve son entegrasyonlarını tartışacak.
SUSHI
-4.7%
2025-11-12
Sub0 // SYMBIOSIS Buenos Aires'te
Polkadot, 14-16 Kasım tarihlerinde Buenos Aires'te düzenlenecek yeni amiral konferansı sub0 // SYMBIOSIS'i duyurdu. Etkinlik, inşaatçıları ve daha geniş ekosistemi tek bir çatı altında bir araya getirmeyi amaçlayan hiper sürükleyici bir deneyim olarak tanımlanıyor.
DOT
-3.94%
2025-11-15
Buenos Aires'teki DeFi Day Del Sur
Aave, DeFi Day del Sur'un dördüncü edisyonunun 19 Kasım'da Buenos Aires'te gerçekleştirileceğini bildirdi.
AAVE
-1.32%
2025-11-18
sign up guide logosign up guide logo
sign up guide content imgsign up guide content img
Start Now
Sign up and get a
$100
Voucher!
Create Account

Related Articles

Pi Coin Transaction Guide: How to Transfer to Gate.io
Beginner

Pi Coin Transaction Guide: How to Transfer to Gate.io

Pi Network is a decentralized cryptocurrency network for the general public, using the Stellar Consensus Protocol (SCP) consensus mechanism, which allows users to easily mine Pi tokens from their mobile devices and use them for payments and transactions. With the official opening of the mainnet on February 20, 2025, investors can deposit and trade $PI on exchanges such as Gate.io. This article details how to securely transfer Pi Coins to Gate.io, including obtaining a deposit address, completing the transfer using the Pi Network mainnet wallet, and the exchange's arrival confirmation process. In addition, we have analysed $PI investment risks, including market volatility, compliance and potential fraud risks, to remind investors to take risk management before trading.
2/25/2025, 8:21:43 AM
Flare Crypto Explained: What Is Flare Network and Why It Matters in 2025
Beginner

Flare Crypto Explained: What Is Flare Network and Why It Matters in 2025

Discover what Flare Crypto is, how it works, its use cases, tokenomics, and why it's gaining traction in the blockchain space in 2025.
4/15/2025, 1:21:45 AM
What is N2: An AI-Driven Layer 2 Solution
Beginner

What is N2: An AI-Driven Layer 2 Solution

This article introduces N2 (Niggachain AI Layer 2), the world's first AI-driven Layer 2 blockchain solution. N2 combines AI technology and quantum computing resistance to address the limitations of traditional blockchains in scalability, transaction speed, and cost. Its core technologies include '0-second block time', AI-driven network optimization, and quantum-resistant security protection, aiming to improve transaction efficiency and ensure system stability.
12/23/2024, 7:21:00 AM
How to Use a Crypto Whale Tracker: Top Tool Recommendation for 2025 to Follow Whale Moves
Beginner

How to Use a Crypto Whale Tracker: Top Tool Recommendation for 2025 to Follow Whale Moves

This article will take you through what is a crypto whale tracker and why it has become the "must-have weapon" for encryption investors. We will recommend seven mainstream Whale tracking tools, and combined with usage scenarios, teach you how to efficiently use these tools to obtain first-hand signals from the market. Of course, Whale behavior may also be a "lure," so while using these tools, you also need to have a certain level of judgment and data interpretation ability. This article is suitable for beginners to quickly get started, as well as for experienced players to optimize strategies.
4/14/2025, 6:57:17 AM
Understand Baby doge coin in one article
Beginner

Understand Baby doge coin in one article

Baby Doge Coin, also known as "Baby Dog Token", is a meme token derived from the Dogecoin community, which gained popularity through Elon Musk's tweets and enhanced token utility through mechanisms such as deflation, payment integration, and NFT ecosystem. This article comprehensively analyzes the project background, token information, application scenarios, and market performance of Baby Doge, helping investors quickly understand its potential and risks.
2/14/2025, 4:53:03 PM
Solana (SOL) In-Depth Research: An Emerging Power in the Blockchain Space
Beginner

Solana (SOL) In-Depth Research: An Emerging Power in the Blockchain Space

Investors considering Solana should fully understand the associated risks. The cryptocurrency market is highly volatile and uncertain, and Solana’s price may fluctuate significantly due to market sentiment, macroeconomic conditions, industry policies, and other factors. Investors could face substantial price risks, leading to significant asset depreciation. Given these risks, investors should adopt cautious strategies. They should allocate investments wisely, avoiding over-concentration in Solana. It is advisable to limit Solana’s share in the total investment portfolio, such as not exceeding 10%, to diversify risks.
4/7/2025, 1:10:00 AM