星球日报|11月 05, 2025 16:29
[Balancer Releases Preliminary Report on v2 Exploit: Rounding Logic Error in Batch Swap Transactions Exploited]
Odaily Planet Daily News – Balancer released a preliminary report on the v2 exploit incident on platform X, revealing that the composable stable pools of Balancer V2 were attacked on November 4 across multiple chains (including Ethereum, Base, Avalanche, Polygon, Arbitrum, etc.). The vulnerability stemmed from a rounding logic error in batchSwap transactions for EXACT_OUT trades. When the scaling factor is a non-integer value, the function rounds down, allowing attackers to manipulate pool balances and extract assets.
This incident only affected the composable stable pools of Balancer V2. Balancer V3 and other pool types were not impacted. The Balancer team, along with security partners and white-hat teams, acted swiftly, employing measures such as Hypernative's automatic pause, asset freezing, and white-hat interventions under the SEAL framework to successfully contain the attack's spread and recover some assets.
Balancer added that they are currently collaborating with security partners like SEAL and zeroShadow to conduct cross-chain tracking and asset recovery. The final verified losses and recovery data will be disclosed in a comprehensive technical review report.
The official team reminds users to only obtain confirmed information through Balancer's official channels. Operations on V3 and non-stable pools remain secure.
Share To
HotFlash
APP
X
Telegram
CopyLink