DeFi protocol Balancer says an attacker exploited its V2 Composable Stable Pools on November 3, resulting in an estimated ~$128M in losses across blockchains
Some $128 million in crypto was stolen from Balancer liquidity pools on Ethereum and beyond, with Berachain halting its chain as a result.
DecryptRyan S. Gladwin
Context & Ripple Effects
Balancer’s loss is another large DeFi security failure in a coverage history that includes the Poly Network cross-chain theft and a roughly $130M Cream Finance attack. The recurring scale of these incidents matters because core liquidity infrastructure can transmit a protocol-level failure beyond one application.
Here, the impact reached multiple chains and prompted Berachain to halt, making operational continuity—not only the stolen assets—the immediate issue.
First-order effects
Balancer liquidity-pool participants face the estimated loss tied to the affected V2 Composable Stable Pools across Ethereum and other chains.
Berachain’s halt interrupts activity on that network while it addresses exposure to the incident.
Second-order effects
Protocols and chain operators using or connected to the affected pool design will need to assess exposure and decide whether to pause, restrict, or reroute liquidity.
A chain-level halt can fragment liquidity and delay transactions for users and applications that depend on the affected network, rather than containing disruption within Balancer alone.
Third-order effects
If exploits of shared DeFi liquidity components continue to produce cross-chain interruptions, security review and contingency controls will become a competitive requirement for protocols and chains seeking to retain liquidity.
The episode reinforces the crypto legitimacy gap: repeated large losses and emergency halts make reliability a system-wide adoption constraint, not merely a risk borne by a single protocol’s users.
The trend: DeFi is moving toward a harsher test of composability, where a vulnerability in shared liquidity infrastructure can create operational risk across interconnected chains.
Today, around 7:48 AM UTC, an exploit affected Balancer V2 Composable Stable Pools. Our team is working with leading security researchers to understand the issue and will share additional findings and a full post-mortem as soon as possible. Because these pools have been live [ima…
1/4 Balancer V2 Attack Analysis Balancer V2 and its forks suffered a devastating attack across multiple chains, resulting in over $128M in losses. GoPlus detected and alerted users immediately. Here's what happened and how the attacker exploited a critical vulnerability. 🧵 [image…
Just half an hour earlier, StakeWise DAO emergency multisig has executed a series of transactions, recovering ~5,041 osETH (~$19M) and 13,495 osGNO (~$1.7M) tokens from the Balancer exploiter. On Ethereum mainnet, this represents 73.5% of the ~6,851 osETH stolen earlier today, [i…
Here's everything you need to know about the Balancer Hack: 1. The attack targeted Balancer's V2 vaults and liquidity pools, exploiting a vulnerability in smart contract interactions. Preliminary analysis from on-chain investigators points to a maliciously deployed contract that …
Fascinating how different chains responded differently to the $128M @Balancer hack. Berachain had validators halt the network (Balancer very tightly integrated into their ecosystem). Polygon validators censoring hacker's transactions to freeze them in place. Sonic added
Balancer v2 launched in 2021 and is one of the most looked at and forked smart contracts since. It's very scary. Every time such an old contract can be exploited, it (rightfully) sets Defi adoption back by 6-12 months.
Update: the balancer hacker has added console logs onchain. there is also a good probability that the hackers vibe coded the attack or used LLMs. Here's why I think that: >hackers usually never leave console.log in production code. >when console.log does appear on-chain, [image]
Balancer v2's $128M hack wasn't a surprise. It was an architectural inevitability. In October, we warned about V2's “cross-contract trust boundary.” On Nov 3, a hacker walked right through that door. We've written a post-mortem article. How it happened and what every DeFi dev [im…
Even though I stepped back from active work on Balancer, it still represents many years of work and a vision I deeply believe in. Watching today's events unfold has been difficult, and very painful to be honest. The team is handling this with the professionalism and dedication I