$128M exploit on Balancer V2 reveals how a rounding error slipped past 11 audits from firms like OpenZeppelin, Certora and many more


7 recorded changes
Want your article here?
Promote with Leviathan News

7 recorded changes
Want your article here?
Promote with Leviathan NewsOn 3 November 2025, Balancer’s V2 Composable Stable Pools were hit by a highly technical exploit that drained roughly $128–129 million in assets across multiple chains, despite the protocol having undergone at least 11 audits by firms including OpenZeppelin, Trail of Bits, Certora and ABKD. The attacker targeted a subtle rounding/precision error in Balancer V2’s scaling and invariant math (notably in the _upscaleArray / _upscale logic used for Composable Stable Pools), then amplified that tiny bias through carefully engineered batch swaps and micro-swaps, allowing pool prices and Balancer Pool Token (BPT) values to be manipulated and liquidity to be siphoned out at scale.
AI-generated background, compiled from web sources — not editorial content.

𝕏/@BitSafe_Finance ·

𝕏/@aave ·

𝕏/@IntuitMachine ·

aero.xyz ·

blog.celo.org ·

𝕏/@DavidLRipley ·

𝕏/@BitSafe_Finance ·

𝕏/@aave ·

𝕏/@IntuitMachine ·

aero.xyz ·

blog.celo.org ·

𝕏/@DavidLRipley ·
🚀 Love DeFi? Ready to dive in and start earning $SQUID while making an impact?