Cos(余弦)😶🌫️|Nov 06, 2025 03:32
The team finally found some time to put this together…
Accumulated feathers sink the boat — Analysis of Balancer's $100M+ hack
https://mp.weixin.(qq.com)/s/zywPIK08hpy-Ug6rc9Qysw
Root cause: In the implementation of Balancer v2's Composable Stable Pool (based on Curve StableSwap's Stable Math), there was a precision loss issue in the integer fixed-point operations of the scalingFactors, which led to tiny but compounding price discrepancies/errors during token swaps. The attacker exploited these errors by performing small swaps in low liquidity conditions to amplify the discrepancy for significant cumulative profits.
By the way, here's an example of one set of transactions involved in the attack:
Attack transaction: 0x6ed07db1a9fe5c0794d44cd36081d6a6df103fab868cdd75d581e3bd23bc9742
Withdrawal transaction: 0xd155207261712c35fa3d472ed1e51bfcd816e616dd4f517fa5959836f5b48569
The key vulnerability lies in the "attack transaction," not the "withdrawal transaction." This was the point that was initially prone to misanalysis.
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink