From Rounding Bug to Systemic Exploitation: A Deep Dive into Balancer’s $128M Attack

1. Incident Overview (A 2026 Retrospective) On November 3, 2025, Balancer—one of the core liquidity infrastructure protocols in decentralized finance (DeFi)—experienced a large-scale unauthorized value extraction event. The attacker targeted Composable Stable Pools, exploiting a rounding direction error in scaling m…

1. Incident Overview (A 2026 Retrospective)

On November 3, 2025, Balancer—one of the core liquidity infrastructure protocols in decentralized finance (DeFi)—experienced a large-scale unauthorized value extraction event. The attacker targeted Composable Stable Pools, exploiting a rounding direction error in scaling math combined with the composability of batchSwap. By executing complex multi-step swaps in rapid succession, they gradually distorted pool state and extracted value without triggering any effective safeguards.

The attack resulted in losses estimated between$116M and $128M, affecting both the main protocol and multiple forks, with assets including WETH, wstETH, and osETH.

From a 2026 perspective, this incident should not be understood solely as a bug exploit. It is more accurately described asa systematic manipulation of protocol rules. The attacker did not bypass permissions or alter contract code. Instead, they constructed transaction paths that amplified small numerical inconsistencies until the system itself accepted an incorrect asset distribution.

The root issue was not a single flaw, but the interaction of multiple design assumptions under adversarial conditions.

A useful analogy is a banking system:

  • Pools function as shared reserve accounts
  • The invariant acts as the accounting constraint
  • batchSwap resembles complex internal fund transfers
  • Rounding errors mirror small discrepancies in financial calculations
  • Internal balances function as ledger-based accounts

The critical point is:

The attacker did not break into the bank—they exploited the rules until the bank accepted the transfer as valid.

2. Attack Path: From Numerical Drift to Systemic Extraction

From a retrospective view, the attack unfolds in four phases. It was not a single exploit, but aprogressive system-level manipulation.

2.1 Initial Condition: Exploitable rounding direction error

The attack originated from a critical implementation flaw in Composable Stable Pools: in the _swapGivenOut (EXACT_OUT) path, the protocol incorrectly applied FixedPoint.mulDown (rounding down) when upscaling the output amount, whereas mulUp should have been used.

This rounding direction error caused the protocol to systematically underestimate the required input, effectively lowering the invariant under certain execution paths and enabling repeated exploitation.

While the impact of a single rounding operation is negligible, repeated execution along carefully constructed paths allows the error to accumulate, eventually producing a measurable deviation in pool state.

2.2 Amplification: batchSwap as a Path-Level Lever

The attacker leveraged batchSwap to turn this minor bias into a scalable strategy:

  • Executing multiple swaps within a single transaction
  • Routing assets across multiple pools
  • Repeating cycles to accumulate incremental gains

These operations were fully compliant with protocol design. Crucially, invariant checks were applied locally, not globally, meaning the system evaluated each step in isolation.

As a result, the entire path remained “valid” from the protocol’s perspective.

2.3 State Distortion: Creating a Hidden Deficit

As the cycles continued, the system entered a distorted state:

  • Local invariants remained satisfied
  • Global asset distribution drifted
  • A hidden deficit emerged

At this point, the protocol’s assumptions about equilibrium no longer held, yet no detection mechanisms were triggered.

2.4 Extraction: Internal Balance Settlement

Finally, the attacker invokedmanageUserBalanceto:

  • Move assets into internal balances
  • Withdraw them as legitimate claims

No permissions were bypassed. The system executed exactly as designed. Funds were then fragmented and bridged across chains, complicating traceability.

3. Fund Flow and Behavioral Patterns

Flow Structure

  1. Initial capital (flash loans or owned funds) enters pools
  2. Repeated batchSwap cycles (dozens to hundreds)
  3. Gradual invariant drift
  4. Internal balance accumulation
  5. Asset extraction
  6. Cross-chain dispersion

Behavioral Characteristics

  • High-frequency, structured execution
  • Fully automated strategy
  • Multi-chain obfuscation

Multiple analysis firms have noted that the attacker demonstrates advanced DeFi exploitation capabilities. Attribution remains inconclusive.

4. A Paradigm Shift: From Rounding Bugs to Mechanism-Level Exploitation

The industry has largely understood how the attack worked. The more important question is what it represents.

While the attack did not bypass permission controls, its root cause remains a long-standing rounding direction bug in the codebase, which was systematically amplified through composable swap paths.

4.1 From Exploits to Economic Manipulation

  • Traditional attacks:Identify a flaw → Bypass constraints → Extract funds
  • This attack:Respected all constraints → Operated within protocol rules → Extracted value through composition

The implication is critical: Code can be correct, yet the system can still fail.

4.2 Broken Assumptions in DeFi Design

Balancer implicitly assumes:

Participants behave as rational arbitrageurs, not adversarial strategists.

In reality:

  • Attackers actively search for edge-case compositions
  • They optimize across multiple mechanisms
  • They exploit systemic, not local, weaknesses

4.3 The Collapse of Invariants as Security Boundaries

Historically, invariants were treated as guarantees.

This incident shows:

  • Invariants can be gradually degraded
  • Local correctness does not imply global safety

Security is no longer defined by formulas, but by execution paths.

5. Response and Effectiveness

5.1 What Worked

Balancer and ecosystem participants responded rapidly:

  • Paused affected pools
  • Coordinated liquidity withdrawals
  • Patched rounding inconsistencies
  • Accelerated V3 design improvements

These actions were effective in the short term because they:

  • Disabled the known attack vector
  • Reduced exploitable liquidity
  • Addressed the immediate numerical issue

Impact:

  • Short-term: contained losses and stabilized confidence
  • Long-term: informed improvements in math consistency and validation

5.2 What Didn’t

However, these fixes addressed symptoms, not the underlying model.

  1. Fixing rounding does not fix composability risk
  2. Invariant checks remain local
  3. No behavioral anomaly detection exists

In short: the protocol fixedthisexploit, but notthis classof exploits.

6. Defensive Recommendations

  1. Path-Level Invariant Validation
    Validate entire execution paths, not individual steps, to prevent cumulative drift.
  2. Deterministic Rounding Rules
    Enforce consistent rounding across all calculations to eliminate directional bias.
  3. Adversarial Simulation
    Stress-test protocols against worst-case attacker strategies before deployment.
  4. Bounded Composability
    Limit swap complexity and execution depth to reduce exploit surfaces.
  5. Behavioral Monitoring
    Detect anomalous patterns such as cyclic paths and high-frequency structured trades.
  6. Internal Balance Controls
    Introduce delays or constraints on internal balance withdrawals to disrupt extraction phases.

In summary:Security must evolve fromcode correctnesstobehavioral correctness under adversarial conditions.

7. Conclusion

The Balancer V2 exploit marks a turning point in DeFi security.

It demonstrates that systems can fail without being broken. The attacker did not violate rules—they followed them more precisely than the system anticipated.

This shifts the security paradigm:

  • From verifying code
  • To validating mechanisms

In adversarial environments, correctness is not enough. Systems must remain stable under manipulation, not just under normal use.

Balancer is not an isolated incident—it is a signal.

References

  1. Certora –Breaking Down the Balancer Hack[Technical Analysis]
  2. SlowMist –When Small Flaws Collapse a Giant[Technical Analysis]
  3. Trail of Bits –Balancer Hack Analysis and Guidance[Incident Report]
  4. PeckShield – On-chain Alert Reports [On-chain Analysis]
  5. Cyvers – Real-time Threat Detection Reports [On-chain Analysis]
  6. Balancer Official Postmortem [Incident Report]

Insight Report Source: Global Cybersecurity Alliancehttps://www.gcsa.org