Balancer Hack Exposes DeFi Vulnerability: Over $116 Million Drained Across Chains

2025-11-04 04:35:33
Beginner
Quick Reads
On November 3, 2025, the decentralized finance (DeFi) sector suffered a significant setback when the Balancer protocol, a prominent liquidity platform, was discovered to have a critical security vulnerability. Hackers exploited this flaw and stole over $116 million in digital funds within hours.

Balancer Hacked

Decentralized Finance (DeFi) faced another significant challenge. On November 3, 2025, the veteran liquidity protocol Balancer (BAL) experienced a major security vulnerability. Hackers stole over $116 million in assets within hours. The event prompted immediate concern within the on-chain community and ranks among the largest and most significant hacks in DeFi history.

On-chain analytics show the attacker targeted the Vault component of Balancer V2’s smart contract, exploiting insufficient authorization checks and callback-related vulnerabilities to manipulate liquidity pools and transfer assets without authorization. This breach did not result from a leaked private key, but rather a fundamental logic flaw in the smart contract itself.

Ethereum Severely Impacted


(Source: lookonchain)

As of now, Lookonchain’s wallet monitoring confirms that hackers have stolen over $116 million, with assets spanning major chains including Ethereum Mainnet, Arbitrum, Base, Sonic, Optimism, and Polygon. The stolen funds primarily include various liquid staking tokens (LSTs) such as rETH, frxETH, osETH, and rsETH—demonstrating a strong understanding of cross-chain DeFi asset structures.

Smart Contract Callback Vulnerability at the Core

Security researchers found that the attacker deployed malicious contracts during liquidity pool initialization, exploiting weak Vault authorization checks and abnormal state updates to bypass safeguards. This enabled unauthorized swaps across pools or manipulation of pool balances, allowing the attacker to quickly move assets.

Audit firm Kebabsec and several developers confirmed that the incident’s root cause was not authorization errors, but transaction state changes prior to withdrawal—enabling malicious exploitation during asset settlement.

Ecosystem Response

As the hack unfolded, several protocols deeply integrated with Balancer acted swiftly to protect themselves:

  • Lido rapidly withdrew its unaffected positions from Balancer to prevent risk contagion.
  • Berachain immediately suspended network operations and announced an emergency hard fork to patch vulnerabilities in the BEX platform linked to Balancer V2.

Berachain’s founder, Smokey The Bera, stated the team is collaborating with multiple centralized exchanges to blacklist the attacker’s wallet, while halting bridging, lending, and HONEY minting functions to protect liquidity providers’ capital.

Crypto Whales Rush to Withdraw


(Source: lookonchain)

One dormant wallet (0x0090) became a focal point during the incident. Lookonchain’s analysis revealed this whale sprang to life after news of the Balancer exploit broke, urgently withdrawing over $6.5 million in assets. This move illustrates market volatility and highlights DeFi investors’ heightened awareness of security threats.

Tracking the Hackers

On-chain analysts discovered the attacker is using Cow Protocol and multiple DEX platforms to gradually swap stolen LST assets into major tokens like ETH and USDC. For instance, 10 osETH was converted into 10.55 ETH, demonstrating the use of laundering and mixing techniques to complicate tracking efforts.

As of this writing, there is no sign the stolen funds can be recovered. Security teams are blacklisting wallet addresses and conducting ongoing on-chain surveillance to contain the threat.

How Can Investors Protect Themselves?

Balancer users and DeFi investors should take the following steps:

  • Withdraw immediately: Remove assets from Balancer V2 pools to prevent further losses.
  • Revoke permissions: Use Revoke.cash or DeBank to check and remove Balancer-related authorizations.
  • Monitor risk: Stay updated with official announcements and on-chain monitoring to guard against potential follow-up attacks.

Conclusion

The Balancer exploit once again exposes the vulnerability of smart contract security. While decentralization and self-custody lie at DeFi’s core, they also place full responsibility on users and developers. Going forward, balancing innovation and security will be critical to the future of decentralized finance. This incident may have lasting effects on Balancer, but it could also serve as a catalyst for upgrading DeFi’s security infrastructure.

Author: Allen
Disclaimer
* The information is not intended to be and does not constitute financial advice or any other recommendation of any sort offered or endorsed by Gate.
* This article may not be reproduced, transmitted or copied without referencing Gate. Contravention is an infringement of Copyright Act and may be subject to legal action.

Share

Crypto Calendar
OM Tokens Migration Ends
MANTRA Chain issued a reminder for users to migrate their OM tokens to the MANTRA Chain mainnet before January 15. The migration ensures continued participation in the ecosystem as $OM transitions to its native chain.
OM
-4.32%
2026-01-14
CSM Price Change
Hedera has announced that starting January 2026, the fixed USD fee for the ConsensusSubmitMessage service will increase from $0.0001 to $0.0008.
HBAR
-2.94%
2026-01-27
Vesting Unlock Delayed
Router Protocol has announced a 6-month delay in the vesting unlock of its ROUTE token. The team cites strategic alignment with the project’s Open Graph Architecture (OGA) and the goal of maintaining long-term momentum as key reasons for the postponement. No new unlocks will take place during this period.
ROUTE
-1.03%
2026-01-28
Tokens Unlock
Berachain BERA will unlock 63,750,000 BERA tokens on February 6th, constituting approximately 59.03% of the currently circulating supply.
BERA
-2.76%
2026-02-05
Tokens Unlock
Wormhole will unlock 1,280,000,000 W tokens on April 3rd, constituting approximately 28.39% of the currently circulating supply.
W
-7.32%
2026-04-02
sign up guide logosign up guide logo
sign up guide content imgsign up guide content img
Sign Up

Related Articles

Crypto Future Profit Calculator: How to Calculate Your Potential Gains
Beginner

Crypto Future Profit Calculator: How to Calculate Your Potential Gains

Crypto Future Profit Calculator helps traders estimate potential earnings from futures contracts by considering entry price, leverage, fees, and market movement.
2025-02-09 17:28:28
Crypto Futures Calculator: Easily Estimate Your Profits & Risks
Beginner

Crypto Futures Calculator: Easily Estimate Your Profits & Risks

Use a crypto futures calculator to estimate profits, risks, and liquidation prices. Optimize your trading strategy with accurate calculations.
2025-02-11 02:25:44
What is Oasis Network (ROSE)?
Beginner

What is Oasis Network (ROSE)?

The Oasis Network is driving the development of Web3 and AI through smart privacy technology. With its privacy protection, high scalability, and cross-chain interoperability, the Oasis Network is providing new possibilities for the future development of decentralized applications.
2025-05-20 09:41:15
The $50M Crypto Scam Nobody Is Talking About
Beginner

The $50M Crypto Scam Nobody Is Talking About

This investigation uncovers an elaborate over-the-counter (OTC) trading scheme that defrauded multiple institutional investors, revealing the mastermind "Source 1" and exposing critical vulnerabilities in crypto's gray-market dealings.
2025-06-26 11:12:31
What Are Crypto Options?
Beginner

What Are Crypto Options?

For many newcomers, options may seem a bit complex, but as long as you grasp the basic concepts, you can understand their value and potential in the entire encryption financial system.
2025-06-09 09:04:49
Gate Teams Up with Oracle Red Bull Racing to Launch the "Red Bull Racing Tour": Win Exclusive F1 Ticket & Share up to 5,000 GT in Prizes
Beginner

Gate Teams Up with Oracle Red Bull Racing to Launch the "Red Bull Racing Tour": Win Exclusive F1 Ticket & Share up to 5,000 GT in Prizes

On June 9, 2025, Gate, a global leading digital asset trading platform, officially launched the first phase of the “Red Bull Racing Tour”, a high-octane campaign that fuses the speed of F1 with the excitement of Web3. Combining trading competitions and interactive missions, this event gives users a chance to win an exclusive F1 Grand Prix ticket worth thousands of dollars, while competing to share a dynamic prize pool of up to 5,000 GT—bringing fans a triple win: watch, win, and earn.
2025-06-11 01:56:27