Balancer Hack Exposes DeFi Vulnerability: Over $116 Million Drained Across Chains

Beginner
Quick Reads
Last Updated 2026-03-28 02:26:45
Reading Time: 1m
On November 3, 2025, the decentralized finance (DeFi) sector suffered a significant setback when the Balancer protocol, a prominent liquidity platform, was discovered to have a critical security vulnerability. Hackers exploited this flaw and stole over $116 million in digital funds within hours.

Balancer Hacked

Decentralized Finance (DeFi) faced another significant challenge. On November 3, 2025, the veteran liquidity protocol Balancer (BAL) experienced a major security vulnerability. Hackers stole over $116 million in assets within hours. The event prompted immediate concern within the on-chain community and ranks among the largest and most significant hacks in DeFi history.

On-chain analytics show the attacker targeted the Vault component of Balancer V2’s smart contract, exploiting insufficient authorization checks and callback-related vulnerabilities to manipulate liquidity pools and transfer assets without authorization. This breach did not result from a leaked private key, but rather a fundamental logic flaw in the smart contract itself.

Ethereum Severely Impacted


(Source: lookonchain)

As of now, Lookonchain’s wallet monitoring confirms that hackers have stolen over $116 million, with assets spanning major chains including Ethereum Mainnet, Arbitrum, Base, Sonic, Optimism, and Polygon. The stolen funds primarily include various liquid staking tokens (LSTs) such as rETH, frxETH, osETH, and rsETH—demonstrating a strong understanding of cross-chain DeFi asset structures.

Smart Contract Callback Vulnerability at the Core

Security researchers found that the attacker deployed malicious contracts during liquidity pool initialization, exploiting weak Vault authorization checks and abnormal state updates to bypass safeguards. This enabled unauthorized swaps across pools or manipulation of pool balances, allowing the attacker to quickly move assets.

Audit firm Kebabsec and several developers confirmed that the incident’s root cause was not authorization errors, but transaction state changes prior to withdrawal—enabling malicious exploitation during asset settlement.

Ecosystem Response

As the hack unfolded, several protocols deeply integrated with Balancer acted swiftly to protect themselves:

  • Lido rapidly withdrew its unaffected positions from Balancer to prevent risk contagion.
  • Berachain immediately suspended network operations and announced an emergency hard fork to patch vulnerabilities in the BEX platform linked to Balancer V2.

Berachain’s founder, Smokey The Bera, stated the team is collaborating with multiple centralized exchanges to blacklist the attacker’s wallet, while halting bridging, lending, and HONEY minting functions to protect liquidity providers’ capital.

Crypto Whales Rush to Withdraw


(Source: lookonchain)

One dormant wallet (0x0090) became a focal point during the incident. Lookonchain’s analysis revealed this whale sprang to life after news of the Balancer exploit broke, urgently withdrawing over $6.5 million in assets. This move illustrates market volatility and highlights DeFi investors’ heightened awareness of security threats.

Tracking the Hackers

On-chain analysts discovered the attacker is using Cow Protocol and multiple DEX platforms to gradually swap stolen LST assets into major tokens like ETH and USDC. For instance, 10 osETH was converted into 10.55 ETH, demonstrating the use of laundering and mixing techniques to complicate tracking efforts.

As of this writing, there is no sign the stolen funds can be recovered. Security teams are blacklisting wallet addresses and conducting ongoing on-chain surveillance to contain the threat.

How Can Investors Protect Themselves?

Balancer users and DeFi investors should take the following steps:

  • Withdraw immediately: Remove assets from Balancer V2 pools to prevent further losses.
  • Revoke permissions: Use Revoke.cash or DeBank to check and remove Balancer-related authorizations.
  • Monitor risk: Stay updated with official announcements and on-chain monitoring to guard against potential follow-up attacks.

Conclusion

The Balancer exploit once again exposes the vulnerability of smart contract security. While decentralization and self-custody lie at DeFi’s core, they also place full responsibility on users and developers. Going forward, balancing innovation and security will be critical to the future of decentralized finance. This incident may have lasting effects on Balancer, but it could also serve as a catalyst for upgrading DeFi’s security infrastructure.

Author: Allen
Disclaimer
* The information is not intended to be and does not constitute financial advice or any other recommendation of any sort offered or endorsed by Gate.
* This article may not be reproduced, transmitted or copied without referencing Gate. Contravention is an infringement of Copyright Act and may be subject to legal action.

Related Articles

What is Fartcoin? All You Need to Know About FARTCOIN
Intermediate

What is Fartcoin? All You Need to Know About FARTCOIN

Fartcoin (FARTCOIN) is a representative meme coin within the Solana ecosystem based on an AI-driven narrative. Its core concept originated from an experiment aimed at exploring the "boundaries between AI Agents and humor." More than just a digital asset with social attributes, the project deeply couples absurd humor culture with on-chain financial logic by integrating autonomous AI interaction models.
2026-04-04 22:01:19
Gold Price Forecast for the Next Five Years: 2026–2030 Trend Outlook and Investment Implications, Could It Reach $6,000?
Beginner

Gold Price Forecast for the Next Five Years: 2026–2030 Trend Outlook and Investment Implications, Could It Reach $6,000?

Analyze current gold price trends alongside authoritative five-year forecasts, integrating an evaluation of market risks and opportunities. This gives investors insight into the potential trajectory of gold prices and the main drivers expected to shape the market over the next five years.
2026-03-25 18:13:30
Aster vs Hyperliquid: Which Perp DEX Will Prevail?
Beginner

Aster vs Hyperliquid: Which Perp DEX Will Prevail?

Aster and Hyperliquid are the two representative protocols of the "purpose-built L1 path" within the current decentralized perpetual exchange (Perp DEX) sector. As a pioneer in the field, Hyperliquid has built a deep liquidity moat through its highly mature order book architecture and strong community consensus. Conversely, Aster, as a rising challenger, seeks to leapfrog the competition in high-performance trading through more aggressive multi-chain aggregation logic, private transaction modules, and an underlying execution environment optimized for 2026 market demands.
2026-03-24 11:58:33
AI-Native Settlement Layers: How United Stables Is Building the Next Financial Rail
Beginner

AI-Native Settlement Layers: How United Stables Is Building the Next Financial Rail

Stablecoins were originally designed as dollar substitutes within exchanges, primarily used for asset pricing and trade settlement. As on-chain financial ecosystems have matured, their role has expanded beyond simple payments to include collateral assets, cross-chain liquidity mediums, and unified settlement units. In particular, as AI systems and automated agents begin to participate directly in economic activity, demand has risen sharply for programmable value units capable of instant settlement. This shift is pushing stablecoins toward the role of foundational financial infrastructure.
2026-03-25 03:16:17
Aerodrome Tokenomics: How ve(3,3) Powers Base's Most Profitable DEX
Beginner

Aerodrome Tokenomics: How ve(3,3) Powers Base's Most Profitable DEX

AERO is the native token of Aerodrome Finance, a core decentralized exchange and liquidity protocol in the Base ecosystem. It is primarily used for liquidity incentives and ecosystem operations. veAERO is a governance NFT that users receive by locking AERO, representing both voting power and the right to share protocol revenue. Through a dual track structure of AERO as a utility token and veAERO as a governance credential, Aerodrome separates liquidity usage value from long term governance power, allowing participants to act as liquidity providers, governance decision makers, and revenue sharers within the same system.
2026-03-25 06:40:31
The ve(3,3) Flywheel Explained: How AERO Tokenomics Powers Aerodrome’s DeFi Economy
Beginner

The ve(3,3) Flywheel Explained: How AERO Tokenomics Powers Aerodrome’s DeFi Economy

In the competition for DeFi liquidity, high-inflation mining alone is no longer enough to build lasting advantages. Aerodrome applies the ve(3,3) economic model to redesign token emissions, voting mechanisms, and revenue distribution, creating a liquidity flywheel centered on governance and cash flow. This article examines AERO tokenomics, the veAERO locking mechanism, and protocol revenue models to explain how Aerodrome builds a sustainable DeFi economic system.
2026-03-25 06:41:58