
Balancer encountered a major security incident in November 2025, with total losses reaching $116 million. Fortunately, white hat hackers, the internal team, and StakeWise successfully recovered about $28 million. Community members promptly submitted a new proposal to establish a specific refund plan for the $8 million recovered by the white hats and the internal team, while the $20 million portion from StakeWise is handled independently.
The proposal emphasizes three core principles:
This ensures that compensation is fair and accurate, alleviating the burden on victims.
Deddy Lavid, CEO of security company Cyvers, calls this the most complex attack of 2025. Despite the Balancer smart contracts undergoing 11 audits by four firms, attackers exploited the weakness in the EXACT_OUT rounding function of Stable Pools.
Attacks exploit rounding up through computational manipulation, combined with batch swapping, significantly draining the liquidity pool and exposing the reality that audits cannot completely eliminate evolving vulnerabilities.
The compensation proposal from the Balancer community demonstrates maturity in crisis response, ensuring fair restitution through non-socialized principles. This incident reminds the DeFi ecosystem that regardless of how rigorous the audits are, continuously strengthening risk management and contract security remains a key challenge.











