The attack targeted Balancer's V2 Composable Stable Pools across multiple blockchain networks, making it the largest security breach in the protocol's history and one of the biggest DeFi exploits of 2025.The attack targeted Balancer's V2 Composable Stable Pools across multiple blockchain networks, making it the largest security breach in the protocol's history and one of the biggest DeFi exploits of 2025.

Balancer V2 Loses $128 Million in Major DeFi Hack

On November 3, 2025, Balancer, one of the oldest and most trusted decentralized finance (DeFi) platforms, fell victim to a massive hack that drained over $128 million from its users.

The hack began at 7:48 AM UTC on Monday morning. Attackers managed to steal approximately 6,587 WETH (worth about $24.5 million), 6,851 osETH (worth $26.9 million), and 4,260 wstETH (worth $19.3 million) along with other tokens. The stolen funds were quickly moved to newly created wallets controlled by the hackers.

How the Attack Worked

Security researchers discovered that the hackers exploited a critical flaw in Balancer V2’s smart contract code. The vulnerability existed in a function called “manageUserBalance,” which is supposed to control who can move funds within the system. According to blockchain security experts, the attacker took advantage of a faulty access check that confused two different sender identities, allowing unauthorized withdrawals.

The attack method was highly sophisticated. Hackers deployed malicious smart contracts and created fake tokens to manipulate the prices of real tokens in Balancer’s liquidity pools. They exploited tiny rounding errors in the system’s calculations, using multiple swaps in a single transaction to amplify these small discrepancies into massive price distortions. This allowed them to drain liquidity from the pools at wildly favorable exchange rates.

Source: @Balancer

What makes this attack particularly concerning is the level of planning involved. Blockchain data shows the attacker carefully prepared for months, funding their account through Tornado Cash using small deposits of 0.1 ETH to hide their tracks. This methodical approach suggests the work of a highly skilled and experienced hacker, possibly with connections to previous crypto exploits.

Multiple Blockchains Hit Hard

The damage wasn’t limited to just one network. Because Balancer operates across multiple blockchains, the hack spread rapidly. Ethereum suffered the worst losses at $99 million. Other networks also took significant hits: Berachain lost $12.86 million, Arbitrum lost $6.86 million, Base lost $3.9 million, Sonic lost $3.44 million, Optimism lost $1.58 million, and Polygon lost $232,000.

The ripple effects extended beyond Balancer itself. Several projects that had copied Balancer’s code (called “forks”) also became vulnerable to the same attack. Beets Finance reported about $3 million in affected funds, and Beefy Finance paused all products connected to Balancer V2 as a safety measure.

In a controversial move, Berachain validators completely halted their blockchain network and executed an emergency hard fork to protect an estimated $12 million in user funds. This decision sparked debate in the crypto community, as many believe that stopping and reversing blockchain transactions goes against the core principles of decentralization.

The Audit Question

Perhaps the most troubling aspect of this hack is that Balancer V2 had been audited more than 10 times by top security firms including OpenZeppelin, Trail of Bits, Certora, and ABDK. These audits took place between 2021 and 2023, yet the vulnerability still slipped through.

This failure has raised serious questions about the effectiveness of security audits in the DeFi space. Suhail Kakar, a blockchain researcher, said on social media: “Balancer went through 10+ audits. The vault was audited three separate times by different firms still got hacked for $110M. This space needs to accept that ‘audited by X’ means almost nothing.”

Security experts now argue that static code audits are no longer sufficient. Instead, DeFi platforms need continuous, real-time monitoring systems that can detect suspicious activity before funds are drained.

Market Impact and Recovery Efforts

The market reacted swiftly to the news. Balancer’s native BAL token fell 11.1% to $0.87, and the protocol’s total value locked plummeted from $776 million to $406 million within 24 hours. This massive outflow shows how quickly users lose confidence when security is compromised.

Balancer’s team responded by offering the attacker a deal: return all the stolen funds and keep 20% as a “white hat bounty” (worth roughly $25.6 million). The team gave the hacker 48 hours to accept and warned they would work with law enforcement and blockchain forensics specialists if the funds weren’t returned.

There has been some success in recovery efforts. StakeWise, one of the affected protocols, managed to recover approximately $19 million in osETH tokens and $1.7 million in osGNO tokens from the exploiter. This represents about 73.5% of the osETH that was stolen. The recovered funds will be returned to affected users based on their pre-attack balances.

The Bigger Picture

This hack fits into a troubling pattern for 2025. More than $2 billion in cryptocurrency was stolen by hackers in the first half of the year alone, with total losses now exceeding $2.2 billion. Most of these funds have been traced to hackers allegedly connected to North Korea’s government, which uses crypto theft as a key revenue source for its weapons programs.

While there’s no confirmed attribution for the Balancer hack, the sophisticated planning and execution bear similarities to attacks carried out by the infamous Lazarus Group, a North Korean state-sponsored hacking organization known for extensive preparation before major heists.

Balancer confirmed that only V2 Composable Stable Pools were affected, and that Balancer V3 and other pool types remain secure. The team is working with security researchers to produce a detailed post-mortem report and has warned users about fake messages circulating that impersonate Balancer’s official communications.

When Trust Breaks Down

The Balancer exploit serves as a wake-up call for the entire DeFi industry. Despite being one of the most established and audited protocols, it still fell victim to a devastating attack. This incident proves that even extensive security measures don’t guarantee protection, and that the crypto space must evolve beyond current practices to stay ahead of increasingly sophisticated hackers. The question now is whether the industry will learn from this failure and implement the real-time monitoring and layered security systems needed to prevent the next major breach.

Market Opportunity
Major Logo
Major Price(MAJOR)
$0.11366
$0.11366$0.11366
+0.54%
USD
Major (MAJOR) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

U.S. Coinbase Premium Turns Negative Amid Asian Buying Surge

U.S. Coinbase Premium Turns Negative Amid Asian Buying Surge

U.S. institutional demand falls as Asian markets buy Bitcoin dips, causing negative Coinbase premium.
Share
CoinLive2025/12/23 14:20
Crucial ETH Unstaking Period: Vitalik Buterin’s Unwavering Defense for Network Security

Crucial ETH Unstaking Period: Vitalik Buterin’s Unwavering Defense for Network Security

BitcoinWorld Crucial ETH Unstaking Period: Vitalik Buterin’s Unwavering Defense for Network Security Ever wondered why withdrawing your staked Ethereum (ETH) isn’t an instant process? It’s a question that often sparks debate within the crypto community. Ethereum founder Vitalik Buterin recently stepped forward to defend the network’s approximately 45-day ETH unstaking period, asserting its crucial role in safeguarding the network’s integrity. This lengthy waiting time, while sometimes seen as an inconvenience, is a deliberate design choice with profound implications for security. Why is the ETH Unstaking Period a Vital Security Measure? Vitalik Buterin’s defense comes amidst comparisons to other networks, like Solana, which boast significantly shorter unstaking times. He drew a compelling parallel to military operations, explaining that an army cannot function effectively if its soldiers can simply abandon their posts at a moment’s notice. Similarly, a blockchain network requires a stable and committed validator set to maintain its security. The current ETH unstaking period isn’t merely an arbitrary delay. It acts as a critical buffer, providing the network with sufficient time to detect and respond to potential malicious activities. If validators could instantly exit, it would open doors for sophisticated attacks, jeopardizing the entire system. Currently, Ethereum boasts over one million active validators, collectively staking approximately 35.6 million ETH, representing about 30% of the total supply. This massive commitment underpins the network’s robust security model, and the unstaking period helps preserve this stability. Network Security: Ethereum’s Paramount Concern A shorter ETH unstaking period might seem appealing for liquidity, but it introduces significant risks. Imagine a scenario where a large number of validators, potentially colluding, could quickly withdraw their stake after committing a malicious act. Without a substantial delay, the network would have limited time to penalize them or mitigate the damage. This “exit queue” mechanism is designed to prevent sudden validator exodus, which could lead to: Reduced decentralization: A rapid drop in active validators could concentrate power among fewer participants. Increased vulnerability to attacks: A smaller, less stable validator set is easier to compromise. Network instability: Frequent and unpredictable changes in validator numbers can lead to performance issues and consensus failures. Therefore, the extended period is not a bug; it’s a feature. It’s a calculated trade-off between immediate liquidity for stakers and the foundational security of the entire Ethereum ecosystem. Ethereum vs. Solana: Different Approaches to Unstaking When discussing the ETH unstaking period, many point to networks like Solana, which offers a much quicker two-day unstaking process. While this might seem like an advantage for stakers seeking rapid access to their funds, it reflects fundamental differences in network architecture and security philosophies. Solana’s design prioritizes speed and immediate liquidity, often relying on different consensus mechanisms and validator economics to manage security risks. Ethereum, on the other hand, with its proof-of-stake evolution from proof-of-work, has adopted a more cautious approach to ensure its transition and long-term stability are uncompromised. Each network makes design choices based on its unique goals and threat models. Ethereum’s substantial value and its role as a foundational layer for countless dApps necessitate an extremely robust security posture, making the current unstaking duration a deliberate and necessary component. What Does the ETH Unstaking Period Mean for Stakers? For individuals and institutions staking ETH, understanding the ETH unstaking period is crucial for managing expectations and investment strategies. It means that while staking offers attractive rewards, it also comes with a commitment to the network’s long-term health. Here are key considerations for stakers: Liquidity Planning: Stakers should view their staked ETH as a longer-term commitment, not immediately liquid capital. Risk Management: The delay inherently reduces the ability to react quickly to market volatility with staked assets. Network Contribution: By participating, stakers contribute directly to the security and decentralization of Ethereum, reinforcing its value proposition. While the current waiting period may not be “optimal” in every sense, as Buterin acknowledged, simply shortening it without addressing the underlying security implications would be a dangerous gamble for the network’s reliability. In conclusion, Vitalik Buterin’s defense of the lengthy ETH unstaking period underscores a fundamental principle: network security cannot be compromised for the sake of convenience. It is a vital mechanism that protects Ethereum’s integrity, ensuring its stability and trustworthiness as a leading blockchain platform. This deliberate design choice, while requiring patience from stakers, ultimately fortifies the entire ecosystem against potential threats, paving the way for a more secure and reliable decentralized future. Frequently Asked Questions (FAQs) Q1: What is the main reason for Ethereum’s long unstaking period? A1: The primary reason is network security. A lengthy ETH unstaking period prevents malicious actors from quickly withdrawing their stake after an attack, giving the network time to detect and penalize them, thus maintaining stability and integrity. Q2: How long is the current ETH unstaking period? A2: The current ETH unstaking period is approximately 45 days. This duration can fluctuate based on network conditions and the number of validators in the exit queue. Q3: How does Ethereum’s unstaking period compare to other blockchains? A3: Ethereum’s unstaking period is notably longer than some other networks, such as Solana, which has a two-day period. This difference reflects varying network architectures and security priorities. Q4: Does the unstaking period affect ETH stakers? A4: Yes, it means stakers need to plan their liquidity carefully, as their staked ETH is not immediately accessible. It encourages a longer-term commitment to the network, aligning staker interests with Ethereum’s stability. Q5: Could the ETH unstaking period be shortened in the future? A5: While Vitalik Buterin acknowledged the current period might not be “optimal,” any significant shortening would likely require extensive research and network upgrades to ensure security isn’t compromised. For now, the focus remains on maintaining robust network defenses. Found this article insightful? Share it with your friends and fellow crypto enthusiasts on social media to spread awareness about the critical role of the ETH unstaking period in Ethereum’s security! To learn more about the latest Ethereum trends, explore our article on key developments shaping Ethereum’s institutional adoption. This post Crucial ETH Unstaking Period: Vitalik Buterin’s Unwavering Defense for Network Security first appeared on BitcoinWorld.
Share
Coinstats2025/09/18 15:30
USD/JPY jumps to near 148.30 as Fed Powell’s caution on rate cuts boosts US Dollar

USD/JPY jumps to near 148.30 as Fed Powell’s caution on rate cuts boosts US Dollar

The post USD/JPY jumps to near 148.30 as Fed Powell’s caution on rate cuts boosts US Dollar appeared on BitcoinEthereumNews.com. USD/JPY climbs to near 148.30 as Fed’s Powell didn’t endorse aggressive dovish stance. Fed’s Powell warns of slowing job demand and upside inflation risks. Japan’s Jibun Bank Manufacturing PMI declines at a faster pace in September. The USD/JPY pair trades 0.45% higher to near 148.30 during the European trading session on Wednesday. The pair gains sharply as the US Dollar (USD) outperforms a majority of its peers, following comments from Federal Reserve (Fed) Chair Jerome Powell that the central bank needs to be cautious on further interest rate cuts. During the press time, the US Dollar Index (DXY), which tracks the Greenback’s value against six major currencies, rises almost 0.4% to near 97.60. The USD Index resumes its upside journey after a two-day corrective move. On Tuesday, Fed’s Powell stated at the Greater Providence Chamber of Commerce that the upside inflation risks and labor market concerns have posed a challenging situation for the central bank, which is prompting officials to exercise caution on further monetary policy easing. Powell also stated that the current interest rate range is “well positioned to respond to potential economic developments”. Fed Powell’s comments were similar to statements from Federal Open Market Committee (FOMC) members St. Louis Fed President Alberto Musalem, Atlanta Fed President Raphael Bostic, and Cleveland Fed President Beth Hammack who stated on Monday that the central bank needs to cautious over unwinding monetary policy restrictiveness further, citing persistent inflation risks. Going forward, investors will focus on the US Durable Goods Orders and Personal Consumption Expenditure Price Index (PCE) data for August, which will be released on Thursday and Friday, respectively. In Japan, the manufacturing business activity has declined again in September. Preliminary Jibun Bank Manufacturing PMI data came in lower at 48.4 against 49.7 in August. Economists had anticipated the Manufacturing PMI to…
Share
BitcoinEthereumNews2025/09/25 01:31