On 3 November 2025, Balancer’s V2 Composable Stable Pools were hit by a highly technical exploit that drained roughly $128–129 million in assets across multiple chains, despite the protocol having undergone at least 11 audits by firms including OpenZeppelin, Trail of Bits, Certora and ABKD. The attacker targeted a subtle rounding/precision error in Balancer V2’s scaling and invariant math (notably in the _upscaleArray / _upscale logic used for Composable Stable Pools), then amplified that tiny bias through carefully engineered batch swaps and micro-swaps, allowing pool prices and Balancer Pool Token (BPT) values to be manipulated and liquidity to be siphoned out at scale.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Audit

Comments