PANews reported on November 6th that Balancer released a preliminary incident report on the v2 vulnerability exploit, stating that Hypernative monitoring detected an exploit targeting Balancer V2 Composable Stable Pools at 15:46 (UTC+8) on Monday. Affected networks include Ethereum, Base, Avalanche, Gnosis, Berachain, Polygon, Sonic, Arbitrum, and Optimism. The initial root cause is an incorrect rounding direction in the `EXACT_OUT` function of the `batchSwap` and `upscale` functions, leading to manipulation of pool balances. CSP v6 has been automatically paused and Recovery Mode enabled ; CSP v5 is affected. Mitigation progress: StakeWise recovered approximately 5,041 osETH and 13,495 osGNO ; Base MEV and BitFinding recovered approximately $750,000; Monerium froze approximately 1.3 million Euros ; Berachain suspended its chain; and Sonic froze related addresses. The final losses are pending verification by multiple parties.PANews reported on November 6th that Balancer released a preliminary incident report on the v2 vulnerability exploit, stating that Hypernative monitoring detected an exploit targeting Balancer V2 Composable Stable Pools at 15:46 (UTC+8) on Monday. Affected networks include Ethereum, Base, Avalanche, Gnosis, Berachain, Polygon, Sonic, Arbitrum, and Optimism. The initial root cause is an incorrect rounding direction in the `EXACT_OUT` function of the `batchSwap` and `upscale` functions, leading to manipulation of pool balances. CSP v6 has been automatically paused and Recovery Mode enabled ; CSP v5 is affected. Mitigation progress: StakeWise recovered approximately 5,041 osETH and 13,495 osGNO ; Base MEV and BitFinding recovered approximately $750,000; Monerium froze approximately 1.3 million Euros ; Berachain suspended its chain; and Sonic froze related addresses. The final losses are pending verification by multiple parties.

Balancer: EXACT_OUT rounding error combined with batchSwap causes pool balance manipulation.

2025/11/06 09:49

PANews reported on November 6th that Balancer released a preliminary incident report on the v2 vulnerability exploit, stating that Hypernative monitoring detected an exploit targeting Balancer V2 Composable Stable Pools at 15:46 (UTC+8) on Monday. Affected networks include Ethereum, Base, Avalanche, Gnosis, Berachain, Polygon, Sonic, Arbitrum, and Optimism. The initial root cause is an incorrect rounding direction in the `EXACT_OUT` function of the `batchSwap` and `upscale` functions, leading to manipulation of pool balances. CSP v6 has been automatically paused and Recovery Mode enabled ; CSP v5 is affected. Mitigation progress: StakeWise recovered approximately 5,041 osETH and 13,495 osGNO ; Base MEV and BitFinding recovered approximately $750,000; Monerium froze approximately 1.3 million Euros ; Berachain suspended its chain; and Sonic froze related addresses. The final losses are pending verification by multiple parties.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Share Insights