SlowMist|11月 06, 2025 10:27
🚨 Recently, @Balancer V2 suffered a major exploit. Multiple projects and forked versions across several blockchains were impacted, with total losses of ~120M. The following is the SlowMist Security Team’s detailed analysis of the attack.
🧩 Attack flow:
1️⃣ The attacker swapped BPT for liquidity tokens to reduce the pool’s liquidity reserves, preparing for small-amount swaps.
2️⃣ They performed swaps between liquidity tokens (osETH → WETH) to prepare for precise control of small-swap precision errors.
3️⃣ They executed carefully controlled $osETH → swaps to accumulate precision errors.
4️⃣ They swapped between liquidity tokens (WETH → osETH) to restore liquidity.
5️⃣ They repeated steps 2–4 to amplify the error continuously.
6️⃣ They swapped the liquidity tokens back into BPT to restore pool balance.
7️⃣ By exploiting the error magnified via small-amount swaps, the attacker caused the final settled amountOut to be much larger than the required amountIn, thereby realizing substantial profits.
⚙️ Root Cause: In the implementation of Balancer V2’s Composable Stable Pool (Stable Math based on Curve’s StableSwap), there existed a precision loss issue in the integer fixed-point arithmetic used to compute the scalingFactors. This led to small but compounding price discrepancies/errors during token swaps. The attacker exploited this flaw by executing a series of small swaps under low-liquidity conditions, amplifying the accumulated deviation into significant cumulative profits.
🔒 SlowMist Insight: Project teams and auditors, when facing similar scenarios, should enhance test coverage for extreme cases and boundary conditions, with particular attention to precision handling strategies under low-liquidity conditions.
Full analysis 👉 https://slowmist.medium.com/when-small-flaws-collapse-a-giant-inside-balancers-100m-hack-85b9e92a9ae3(SlowMist)
Share To
HotFlash
APP
X
Telegram
CopyLink