Balancer’s official post-mortem on the November 3, 2025 exploit confirms that a subtle rounding bug in the stable pool invariant calculation in Balancer v2’s Composable Stable Pools allowed an attacker to manipulate pricing and drain more than $100 million across multiple chains. Security firms analyzing the incident describe it as an invariant‑manipulation attack: by repeatedly abusing a rounding-direction flaw in the computation of the pool’s “root invariant,” the attacker distorted Balancer Pool Token (BPT) pricing through carefully crafted batch swaps, enabling the extraction of excess assets while keeping on‑chain checks formally satisfied. According to Balancer’s post-mortem and independent analyses by Certora, Trail of Bits, OpenZeppelin and others, the core issue was that rounding in the invariant math did not consistently favor the protocol, creating exploitable edge cases in precision loss within the stable swap formula. The attacker deployed specialized contracts and tokens and executed a series of complex interactions targeting Balancer v2 Composable Stable Pools (especially on Ethereum, Base, Polygon, Arbitrum and other networks), ultimately siphoning more than $100–$120 million in high-value assets, including staked ETH derivatives, from Balancer and several forks. Trail of Bits explicitly identifies a “rounding direction issue” present in the code for years as the root cause, noting that existing audits and fuzzing had not captured this arithmetic edge case. The incident echoes earlier community warnings about rounding behavior and Solidity’s fixed‑precision arithmetic limits, including prior bugs in other DeFi protocols such as Bunni that also stemmed from subtle rounding/invariant assumptions in pool math. In response, Balancer emphasized that v3 was not affected because its invariant and rounding logic were redesigned and re‑verified, and the team moved v2 pools into recovery/paused modes while working on user compensation and remediation. Security firms are using the case to argue for much stronger invariant documentation, explicit reasoning about precision/rounding, and deeper fuzzing and formal verification for DeFi AMM math, since “battle‑tested” code and multiple audits alone proved insufficient to catch this class of bugs.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

Loading related coverage…

Comments

Loading comments…