金色财经|Nov 05, 2025 20:20
[Balancer Releases Preliminary Report on Exploit Incident: Rounding Error in BatchSwap Logic Exploited]
According to a report by Jinse Finance, Balancer has released a preliminary report on the exploit incident, stating that the composable stable pools of Balancer V2 were attacked on November 4 across multiple chains, including Ethereum, Base, Avalanche, Polygon, Arbitrum, and others. The vulnerability stemmed from a rounding error in the batchSwap logic for EXACT_OUT transactions, which attackers exploited to manipulate pool balances and extract assets. This incident only affected the composable stable pools of Balancer V2, while Balancer V3 and other pool types were not impacted.
The Balancer team, along with security partners and white-hat teams, acted swiftly to contain the attack through measures such as Hypernative's automated pausing, asset freezing, and white-hat interventions under the SEAL framework. These efforts successfully mitigated the spread of the attack and recovered some of the stolen assets. Among the recoveries, StakeWise retrieved approximately 73.5% of the stolen osETH, while teams like BitFinding and Base MEV bot also assisted in recovering some funds.
Currently, Balancer is collaborating with security partners such as SEAL and zeroShadow to conduct cross-chain tracking and asset recovery. The final verified losses and recovery data will be disclosed in a comprehensive technical post-mortem report. The official team reminds users to only obtain confirmed information through Balancer's official channels, and operations on V3 and non-stable pools remain secure.
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink