Balancer has offered a 20% bounty to white hats and the hacker if they return the stolen crypto. But as of now, the bounty remains unclaimed.Balancer has offered a 20% bounty to white hats and the hacker if they return the stolen crypto. But as of now, the bounty remains unclaimed.

Balancer’s $120M Meltdown: How A Series of Small Swaps Almost Broke a Top AMM

2025/11/07 15:10
3 min read
For feedback or concerns regarding this content, please contact us at [email protected]

The Balancer v2 exploit on November 3rd resulted in losses of around $120 million across its main protocol and multiple forks. According to the SlowMist security team’s post-incident analysis, the exploit stemmed from a precision loss flaw in the integer fixed-point arithmetic used to calculate scaling factors inside Composable Stable Pools, which are designed for near-parity asset pairs such as USDC/USDT or WETH/stETH.

In the latest update, SlowMist confirmed that this flaw caused small but consistent price discrepancies during swaps, especially when attackers used the batch swap function to chain multiple operations within a single transaction. The attackers’ strategy was executed across several steps.

SlowMist Postmortem

The attacker swapped BPT for liquidity tokens to reduce the pool’s liquidity reserves, preparing for small-amount swaps. They performed swaps between liquidity tokens (osETH → WETH) to prepare for precise control of small-swap precision errors. They executed carefully controlled $osETH → swaps to accumulate precision errors. They swapped between liquidity tokens (WETH → osETH) to restore liquidity. They repeated steps 2-4 to amplify the error continuously. They swapped the liquidity tokens back into BPT to restore the pool balance.

The attacker first swapped BPT for liquidity tokens to drain and reduce the pool’s liquidity reserves in a bid to prepare for small-amount swaps. They then conducted swaps between liquidity tokens (osETH → WETH) to set up control over small-swap precision errors. Next, they executed highly controlled osETH → WETH swaps to intentionally build up precision errors.

Afterwards, the attacker swapped between liquidity tokens again (WETH → osETH) to restore enough liquidity. After repeating the steps 2-4 in loops to continuously expand the accumulated error, they finally swapped the liquidity tokens back into BPT to return the pool to a balanced state. Through repeatedly leveraging the precision flaw with small-sized swaps, the attacker pushed the system into settling a final “amountOut” that exceeded the true amountIn owed, and allowed them to pocket a massive profit.

SlowMist managed to trace the attacker’s operations across addresses and multiple chains. It found initial funds were routed through Tornado Cash, then through intermediate nodes and cross-chain gas.zip usage, before being assembled on Ethereum-based addresses holding thousands of ETH and WETH.

Remediation Efforts

As part of the remediation efforts, CSPv6 pools across the affected network were paused, CSPv6 factory disabled was disabled, gauges were killed for affected pools, and major LPs safely withdrew, among other steps.

The Balancer team coordinated with whitehats as well as cybersecurity partners and various networks to retrieve or freeze portions of the stolen funds. This included 5,041 StakeWise osETH worth about $19 million and 13,495 osGNO, estimated to be around $2 million.

To project teams and auditors facing similar scenarios, SlowMist said that the focus should be on enhancing test coverage for extreme cases and boundary conditions. Additionally, the firm urged the projects to pay particular attention to precision handling strategies under low-liquidity conditions.

The post Balancer’s $120M Meltdown: How A Series of Small Swaps Almost Broke a Top AMM appeared first on CryptoPotato.

Market Opportunity
TOP Network Logo
TOP Network Price(TOP)
$0.0000699
$0.0000699$0.0000699
0.00%
USD
TOP Network (TOP) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Tags:

You May Also Like

Polygon Tops RWA Rankings With $1.1B in Tokenized Assets

Polygon Tops RWA Rankings With $1.1B in Tokenized Assets

The post Polygon Tops RWA Rankings With $1.1B in Tokenized Assets appeared on BitcoinEthereumNews.com. Key Notes A new report from Dune and RWA.xyz highlights Polygon’s role in the growing RWA sector. Polygon PoS currently holds $1.13 billion in RWA Total Value Locked (TVL) across 269 assets. The network holds a 62% market share of tokenized global bonds, driven by European money market funds. The Polygon POL $0.25 24h volatility: 1.4% Market cap: $2.64 B Vol. 24h: $106.17 M network is securing a significant position in the rapidly growing tokenization space, now holding over $1.13 billion in total value locked (TVL) from Real World Assets (RWAs). This development comes as the network continues to evolve, recently deploying its major “Rio” upgrade on the Amoy testnet to enhance future scaling capabilities. This information comes from a new joint report on the state of the RWA market published on Sept. 17 by blockchain analytics firm Dune and data platform RWA.xyz. The focus on RWAs is intensifying across the industry, coinciding with events like the ongoing Real-World Asset Summit in New York. Sandeep Nailwal, CEO of the Polygon Foundation, highlighted the findings via a post on X, noting that the TVL is spread across 269 assets and 2,900 holders on the Polygon PoS chain. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 Key Trends From the 2025 RWA Report The joint publication, titled “RWA REPORT 2025,” offers a comprehensive look into the tokenized asset landscape, which it states has grown 224% since the start of 2024. The report identifies several key trends driving this expansion. According to…
Share
BitcoinEthereumNews2025/09/18 00:40
Shiba Inu’s 1,549% Spike: Can Bulls Take Control Again And Trigger An Explosive Rally?

Shiba Inu’s 1,549% Spike: Can Bulls Take Control Again And Trigger An Explosive Rally?

Shiba Inu (SHIB) has experienced a sudden increase in futures net flows, skyrocketing more than 1,549% in one day. The spike comes amid broader market volatility
Share
NewsBTC2026/03/17 04:30
US Stocks Surge Higher: Major Indices Post Significant Gains in Bullish Trading Session

US Stocks Surge Higher: Major Indices Post Significant Gains in Bullish Trading Session

BitcoinWorld US Stocks Surge Higher: Major Indices Post Significant Gains in Bullish Trading Session Major US stock indices closed substantially higher today,
Share
bitcoinworld2026/03/17 04:30