Today, the Balancer v2 protocol was hacked. The attacker exploited a logical error in the access control function manageUserBalance of the V2 pool, which allowed unauthorized internal withdrawals through the validateUserBalanceOp function. Currently, the stolen funds have accumulated to $116.6 million and are still growing. Security firms such as PeckShield and Nansen have intervened and are conducting ongoing tracking.
Balancer is an established DeFi platform, this is the fifth "theft" incident involving Balancer.
February 2025: White hat hackers discovered a vulnerability that allowed for the infinite creation of tokens, earning $250,000, and the team promptly fixed it without causing any losses.
2024: Velocore protocol vulnerability, loss of 6.8 million USD
2023: Euler Finance vulnerability loss of $11.9 million
September 2023: Front-end hijacking attack, loss of $230,000
August 2023: V2 Pool Vulnerability, Loss of $2.1 Million
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
Today, the Balancer v2 protocol was hacked. The attacker exploited a logical error in the access control function manageUserBalance of the V2 pool, which allowed unauthorized internal withdrawals through the validateUserBalanceOp function. Currently, the stolen funds have accumulated to $116.6 million and are still growing. Security firms such as PeckShield and Nansen have intervened and are conducting ongoing tracking.
Balancer is an established DeFi platform, this is the fifth "theft" incident involving Balancer.
February 2025: White hat hackers discovered a vulnerability that allowed for the infinite creation of tokens, earning $250,000, and the team promptly fixed it without causing any losses.
2024: Velocore protocol vulnerability, loss of 6.8 million USD
2023: Euler Finance vulnerability loss of $11.9 million
September 2023: Front-end hijacking attack, loss of $230,000
August 2023: V2 Pool Vulnerability, Loss of $2.1 Million
June 2020: Flash loan attack, loss of $520,000