1. Incident Overview (A 2026 Retrospective)
On November 3, 2025, Balancer—one of the core liquidity infrastructure protocols in decentralized finance (DeFi)—experienced a large-scale unauthorized value extraction event. The attacker targeted Composable Stable Pools, exploiting a rounding direction error in scaling math combined with the composability of batchSwap. By executing complex multi-step swaps in rapid succession, they gradually distorted pool state and extracted value without triggering any effective safeguards.
The attack resulted in losses estimated between$116M and $128M, affecting both the main protocol and multiple forks, with assets including WETH, wstETH, and osETH.
From a 2026 perspective, this incident should not be understood solely as a bug exploit. It is more accurately described asa systematic manipulation of protocol rules. The attacker did not bypass permissions or alter contract code. Instead, they constructed transaction paths that amplified small numerical inconsistencies until the system itself accepted an incorrect asset distribution.
The root issue was not a single flaw, but the interaction of multiple design assumptions under adversarial conditions.
A useful analogy is a banking system:
- Pools function as shared reserve accounts
- The invariant acts as the accounting constraint
- batchSwap resembles complex internal fund transfers
- Rounding errors mirror small discrepancies in financial calculations
- Internal balances function as ledger-based accounts
The critical point is:
The attacker did not break into the bank—they exploited the rules until the bank accepted the transfer as valid.
2. Attack Path: From Numerical Drift to Systemic Extraction
From a retrospective view, the attack unfolds in four phases. It was not a single exploit, but aprogressive system-level manipulation.
2.1 Initial Condition: Exploitable rounding direction error
The attack originated from a critical implementation flaw in Composable Stable Pools: in the _swapGivenOut (EXACT_OUT) path, the protocol incorrectly applied FixedPoint.mulDown (rounding down) when upscaling the output amount, whereas mulUp should have been used.
This rounding direction error caused the protocol to systematically underestimate the required input, effectively lowering the invariant under certain execution paths and enabling repeated exploitation.
While the impact of a single rounding operation is negligible, repeated execution along carefully constructed paths allows the error to accumulate, eventually producing a measurable deviation in pool state.
2.2 Amplification: batchSwap as a Path-Level Lever
The attacker leveraged batchSwap to turn this minor bias into a scalable strategy:
- Executing multiple swaps within a single transaction
- Routing assets across multiple pools
- Repeating cycles to accumulate incremental gains
These operations were fully compliant with protocol design. Crucially, invariant checks were applied locally, not globally, meaning the system evaluated each step in isolation.
As a result, the entire path remained “valid” from the protocol’s perspective.
2.3 State Distortion: Creating a Hidden Deficit
As the cycles continued, the system entered a distorted state:
- Local invariants remained satisfied
- Global asset distribution drifted
- A hidden deficit emerged
At this point, the protocol’s assumptions about equilibrium no longer held, yet no detection mechanisms were triggered.
2.4 Extraction: Internal Balance Settlement
Finally, the attacker invokedmanageUserBalanceto:
- Move assets into internal balances
- Withdraw them as legitimate claims
No permissions were bypassed. The system executed exactly as designed. Funds were then fragmented and bridged across chains, complicating traceability.
3. Fund Flow and Behavioral Patterns
Flow Structure
- Initial capital (flash loans or owned funds) enters pools
- Repeated batchSwap cycles (dozens to hundreds)
- Gradual invariant drift
- Internal balance accumulation
- Asset extraction
- Cross-chain dispersion
Behavioral Characteristics
- High-frequency, structured execution
- Fully automated strategy
- Multi-chain obfuscation
Multiple analysis firms have noted that the attacker demonstrates advanced DeFi exploitation capabilities. Attribution remains inconclusive.
4. A Paradigm Shift: From Rounding Bugs to Mechanism-Level Exploitation
The industry has largely understood how the attack worked. The more important question is what it represents.
While the attack did not bypass permission controls, its root cause remains a long-standing rounding direction bug in the codebase, which was systematically amplified through composable swap paths.
4.1 From Exploits to Economic Manipulation
- Traditional attacks:Identify a flaw → Bypass constraints → Extract funds
- This attack:Respected all constraints → Operated within protocol rules → Extracted value through composition
The implication is critical: Code can be correct, yet the system can still fail.
4.2 Broken Assumptions in DeFi Design
Balancer implicitly assumes:
Participants behave as rational arbitrageurs, not adversarial strategists.
In reality:
- Attackers actively search for edge-case compositions
- They optimize across multiple mechanisms
- They exploit systemic, not local, weaknesses
4.3 The Collapse of Invariants as Security Boundaries
Historically, invariants were treated as guarantees.
This incident shows:
- Invariants can be gradually degraded
- Local correctness does not imply global safety
Security is no longer defined by formulas, but by execution paths.
5. Response and Effectiveness
5.1 What Worked
Balancer and ecosystem participants responded rapidly:
- Paused affected pools
- Coordinated liquidity withdrawals
- Patched rounding inconsistencies
- Accelerated V3 design improvements
These actions were effective in the short term because they:
- Disabled the known attack vector
- Reduced exploitable liquidity
- Addressed the immediate numerical issue
Impact:
- Short-term: contained losses and stabilized confidence
- Long-term: informed improvements in math consistency and validation
5.2 What Didn’t
However, these fixes addressed symptoms, not the underlying model.
- Fixing rounding does not fix composability risk
- Invariant checks remain local
- No behavioral anomaly detection exists
In short: the protocol fixedthisexploit, but notthis classof exploits.
6. Defensive Recommendations
- Path-Level Invariant Validation
Validate entire execution paths, not individual steps, to prevent cumulative drift. - Deterministic Rounding Rules
Enforce consistent rounding across all calculations to eliminate directional bias. - Adversarial Simulation
Stress-test protocols against worst-case attacker strategies before deployment. - Bounded Composability
Limit swap complexity and execution depth to reduce exploit surfaces. - Behavioral Monitoring
Detect anomalous patterns such as cyclic paths and high-frequency structured trades. - Internal Balance Controls
Introduce delays or constraints on internal balance withdrawals to disrupt extraction phases.
In summary:Security must evolve fromcode correctnesstobehavioral correctness under adversarial conditions.
7. Conclusion
The Balancer V2 exploit marks a turning point in DeFi security.
It demonstrates that systems can fail without being broken. The attacker did not violate rules—they followed them more precisely than the system anticipated.
This shifts the security paradigm:
- From verifying code
- To validating mechanisms
In adversarial environments, correctness is not enough. Systems must remain stable under manipulation, not just under normal use.
Balancer is not an isolated incident—it is a signal.
References
- Certora –Breaking Down the Balancer Hack[Technical Analysis]
- SlowMist –When Small Flaws Collapse a Giant[Technical Analysis]
- Trail of Bits –Balancer Hack Analysis and Guidance[Incident Report]
- PeckShield – On-chain Alert Reports [On-chain Analysis]
- Cyvers – Real-time Threat Detection Reports [On-chain Analysis]
- Balancer Official Postmortem [Incident Report]
Insight Report Source: Global Cybersecurity Alliancehttps://www.gcsa.org
Get updates in your inbox
We respect your privacy. See our Privacy Policy