Balancer Hack Exposes DeFi Vulnerability: Over $116 Million Drained Across Chains

11/4/2025, 4:35:33 AM
Beginner
Quick Reads
On November 3, 2025, the decentralized finance (DeFi) sector suffered a significant setback when the Balancer protocol, a prominent liquidity platform, was discovered to have a critical security vulnerability. Hackers exploited this flaw and stole over $116 million in digital funds within hours.

Balancer Hacked

Decentralized Finance (DeFi) faced another significant challenge. On November 3, 2025, the veteran liquidity protocol Balancer (BAL) experienced a major security vulnerability. Hackers stole over $116 million in assets within hours. The event prompted immediate concern within the on-chain community and ranks among the largest and most significant hacks in DeFi history.

On-chain analytics show the attacker targeted the Vault component of Balancer V2’s smart contract, exploiting insufficient authorization checks and callback-related vulnerabilities to manipulate liquidity pools and transfer assets without authorization. This breach did not result from a leaked private key, but rather a fundamental logic flaw in the smart contract itself.

Ethereum Severely Impacted


(Source: lookonchain)

As of now, Lookonchain’s wallet monitoring confirms that hackers have stolen over $116 million, with assets spanning major chains including Ethereum Mainnet, Arbitrum, Base, Sonic, Optimism, and Polygon. The stolen funds primarily include various liquid staking tokens (LSTs) such as rETH, frxETH, osETH, and rsETH—demonstrating a strong understanding of cross-chain DeFi asset structures.

Smart Contract Callback Vulnerability at the Core

Security researchers found that the attacker deployed malicious contracts during liquidity pool initialization, exploiting weak Vault authorization checks and abnormal state updates to bypass safeguards. This enabled unauthorized swaps across pools or manipulation of pool balances, allowing the attacker to quickly move assets.

Audit firm Kebabsec and several developers confirmed that the incident’s root cause was not authorization errors, but transaction state changes prior to withdrawal—enabling malicious exploitation during asset settlement.

Ecosystem Response

As the hack unfolded, several protocols deeply integrated with Balancer acted swiftly to protect themselves:

  • Lido rapidly withdrew its unaffected positions from Balancer to prevent risk contagion.
  • Berachain immediately suspended network operations and announced an emergency hard fork to patch vulnerabilities in the BEX platform linked to Balancer V2.

Berachain’s founder, Smokey The Bera, stated the team is collaborating with multiple centralized exchanges to blacklist the attacker’s wallet, while halting bridging, lending, and HONEY minting functions to protect liquidity providers’ capital.

Crypto Whales Rush to Withdraw


(Source: lookonchain)

One dormant wallet (0x0090) became a focal point during the incident. Lookonchain’s analysis revealed this whale sprang to life after news of the Balancer exploit broke, urgently withdrawing over $6.5 million in assets. This move illustrates market volatility and highlights DeFi investors’ heightened awareness of security threats.

Tracking the Hackers

On-chain analysts discovered the attacker is using Cow Protocol and multiple DEX platforms to gradually swap stolen LST assets into major tokens like ETH and USDC. For instance, 10 osETH was converted into 10.55 ETH, demonstrating the use of laundering and mixing techniques to complicate tracking efforts.

As of this writing, there is no sign the stolen funds can be recovered. Security teams are blacklisting wallet addresses and conducting ongoing on-chain surveillance to contain the threat.

How Can Investors Protect Themselves?

Balancer users and DeFi investors should take the following steps:

  • Withdraw immediately: Remove assets from Balancer V2 pools to prevent further losses.
  • Revoke permissions: Use Revoke.cash or DeBank to check and remove Balancer-related authorizations.
  • Monitor risk: Stay updated with official announcements and on-chain monitoring to guard against potential follow-up attacks.

Conclusion

The Balancer exploit once again exposes the vulnerability of smart contract security. While decentralization and self-custody lie at DeFi’s core, they also place full responsibility on users and developers. Going forward, balancing innovation and security will be critical to the future of decentralized finance. This incident may have lasting effects on Balancer, but it could also serve as a catalyst for upgrading DeFi’s security infrastructure.

Author: Allen
* The information is not intended to be and does not constitute financial advice or any other recommendation of any sort offered or endorsed by Gate.
* This article may not be reproduced, transmitted or copied without referencing Gate. Contravention is an infringement of Copyright Act and may be subject to legal action.

Share

Crypto Calendar
Ripple Swell 2025 in New York
Ripple announced that its flagship event, Ripple Swell, will return to New York on November 3rd-5th.
XRP
-3.18%
2025-11-04
Blockchain Futurist Conference in Miami
Bone ShibaSwap will participate in the Blockchain Futurist Conference in Miami on November 5 to 6.
BONE
-7.03%
2025-11-05
Battle of the Builders
Cardano schedules Battle of the Builders for November 11, a live pitch event for projects building or planning to build on Cardano. The top three teams will win prizes, with applications open until October 3.
ADA
-3.44%
2025-11-10
AMA on X
Sushi will host an AMA on X with Hemi Network on March 13th at 18:00 UTC to discuss their latest integration.
SUSHI
-4.7%
2025-11-12
Sub0 // SYMBIOSIS in Buenos Aires
Polkadot has announced sub0 // SYMBIOSIS, its new flagship conference, to be held in Buenos Aires from November 14 to 16. The event is described as hyper immersive, aiming to bring builders and the broader ecosystem together under one roof.
DOT
-3.94%
2025-11-15
sign up guide logosign up guide logo
sign up guide content imgsign up guide content img
Start Now
Sign up and get a
$100
Voucher!
Create Account

Related Articles

Pi Coin Transaction Guide: How to Transfer to Gate.io
Beginner

Pi Coin Transaction Guide: How to Transfer to Gate.io

Pi Network is a decentralized cryptocurrency network for the general public, using the Stellar Consensus Protocol (SCP) consensus mechanism, which allows users to easily mine Pi tokens from their mobile devices and use them for payments and transactions. With the official opening of the mainnet on February 20, 2025, investors can deposit and trade $PI on exchanges such as Gate.io. This article details how to securely transfer Pi Coins to Gate.io, including obtaining a deposit address, completing the transfer using the Pi Network mainnet wallet, and the exchange's arrival confirmation process. In addition, we have analysed $PI investment risks, including market volatility, compliance and potential fraud risks, to remind investors to take risk management before trading.
2/25/2025, 8:21:43 AM
Flare Crypto Explained: What Is Flare Network and Why It Matters in 2025
Beginner

Flare Crypto Explained: What Is Flare Network and Why It Matters in 2025

Discover what Flare Crypto is, how it works, its use cases, tokenomics, and why it's gaining traction in the blockchain space in 2025.
4/15/2025, 1:21:45 AM
What is N2: An AI-Driven Layer 2 Solution
Beginner

What is N2: An AI-Driven Layer 2 Solution

This article introduces N2 (Niggachain AI Layer 2), the world's first AI-driven Layer 2 blockchain solution. N2 combines AI technology and quantum computing resistance to address the limitations of traditional blockchains in scalability, transaction speed, and cost. Its core technologies include '0-second block time', AI-driven network optimization, and quantum-resistant security protection, aiming to improve transaction efficiency and ensure system stability.
12/23/2024, 7:21:00 AM
How to Use a Crypto Whale Tracker: Top Tool Recommendation for 2025 to Follow Whale Moves
Beginner

How to Use a Crypto Whale Tracker: Top Tool Recommendation for 2025 to Follow Whale Moves

This article will take you through what is a crypto whale tracker and why it has become the "must-have weapon" for encryption investors. We will recommend seven mainstream Whale tracking tools, and combined with usage scenarios, teach you how to efficiently use these tools to obtain first-hand signals from the market. Of course, Whale behavior may also be a "lure," so while using these tools, you also need to have a certain level of judgment and data interpretation ability. This article is suitable for beginners to quickly get started, as well as for experienced players to optimize strategies.
4/14/2025, 6:57:17 AM
Understand Baby doge coin in one article
Beginner

Understand Baby doge coin in one article

Baby Doge Coin, also known as "Baby Dog Token", is a meme token derived from the Dogecoin community, which gained popularity through Elon Musk's tweets and enhanced token utility through mechanisms such as deflation, payment integration, and NFT ecosystem. This article comprehensively analyzes the project background, token information, application scenarios, and market performance of Baby Doge, helping investors quickly understand its potential and risks.
2/14/2025, 4:53:03 PM
How to Sell Pi Coin: A Beginner's Guide
Beginner

How to Sell Pi Coin: A Beginner's Guide

This article provides detailed information about Pi Coin, how to complete KYC verification, and choose the right exchange to sell Pi Coin. We also provide specific steps for selling Pi Coin and remind of important matters to pay attention to when selling, helping novice users complete Pi Coin transactions smoothly.
2/26/2025, 9:20:50 AM