BTC $79,163.78 -0.71%
ETH $2,494.34 +0.03%
BNB $740.74 -0.96%
XRP $1.40 -0.79%
SOL $104.00 -2.08%
TRX $0.3338 -0.39%
DOGE $0.0900 +1.03%
ADA $0.2209 +1.34%
BCH $260.45 +1.50%
LINK $12.95 +5.18%
HYPE $85.01 -3.63%
AAVE $132.37 -0.66%
SUI $0.8200 +3.05%
XLM $0.1910 +3.93%
ZEC $1,168.99 -3.14%
BTC $79,163.78 -0.71%
ETH $2,494.34 +0.03%
BNB $740.74 -0.96%
XRP $1.40 -0.79%
SOL $104.00 -2.08%
TRX $0.3338 -0.39%
DOGE $0.0900 +1.03%
ADA $0.2209 +1.34%
BCH $260.45 +1.50%
LINK $12.95 +5.18%
HYPE $85.01 -3.63%
AAVE $132.37 -0.66%
SUI $0.8200 +3.05%
XLM $0.1910 +3.93%
ZEC $1,168.99 -3.14%

Review of Balancer's historical security incidents, resulting in a loss of 21 million dollars due to flash loans, front-end hijacking, and cross-protocol vulnerabilities

2025-11-03 17:11:05

The DeFi protocol Balancer is currently under attack, with losses exceeding $116.6 million across multiple chains, and the attack on Balancer is still ongoing.

According to the on-chain AI analysis tool CoinBob, the historical security incidents of Balancer are as follows:

  • June 2020 Flash Loan Attack: Attackers exploited a compatibility issue between the deflationary token (STA/STONK) and Balancer's smart contracts, repeatedly calling swapExactAmountIn to drain the liquidity pool, ultimately profiting $523,600.

  • August 2023 V2 Pool Vulnerability: The Balancer V2 pool suffered multiple flash loan attacks due to a code vulnerability, with total losses reaching $2.1 million. The team urgently paused the affected pools and advised users to withdraw their funds, but some funds that were not withdrawn in time were still exploited.

  • September 2023 Frontend Hijacking Attack: Hackers gained control of Balancer's frontend through BGP/DNS hijacking, tricking users into authorizing malicious contracts, resulting in a loss of $238,000. On-chain detective ZachXBT traced the funds to address 0x645710Af050E26bB96e295bdfB75B4a878088d7E.

  • 2023 Euler Incident Impact: Due to a vulnerability in Euler Finance, Balancer's bbeUSD pool suffered a loss of $11.9 million, accounting for 65% of the pool's TVL. The team took protective measures to limit liquidity withdrawals.

  • 2024 Velocore Attack Association: The Velocore vulnerability exploited Balancer-style CPMM pools, resulting in a loss of $6.8 million. Balancer's technical architecture was indirectly implicated due to cross-protocol integration.

Связанные теги
Связанные теги
app_icon
ChainCatcher Building the Web3 world with innovations.