Balancer has offered a 20% bounty to white hats and the hacker if they return the stolen crypto. But as of now, the bounty remains unclaimed.Balancer has offered a 20% bounty to white hats and the hacker if they return the stolen crypto. But as of now, the bounty remains unclaimed.

Balancer’s $120M Meltdown: How A Series of Small Swaps Almost Broke a Top AMM

The Balancer v2 exploit on November 3rd resulted in losses of around $120 million across its main protocol and multiple forks. According to the SlowMist security team’s post-incident analysis, the exploit stemmed from a precision loss flaw in the integer fixed-point arithmetic used to calculate scaling factors inside Composable Stable Pools, which are designed for near-parity asset pairs such as USDC/USDT or WETH/stETH.

In the latest update, SlowMist confirmed that this flaw caused small but consistent price discrepancies during swaps, especially when attackers used the batch swap function to chain multiple operations within a single transaction. The attackers’ strategy was executed across several steps.

SlowMist Postmortem

The attacker swapped BPT for liquidity tokens to reduce the pool’s liquidity reserves, preparing for small-amount swaps. They performed swaps between liquidity tokens (osETH → WETH) to prepare for precise control of small-swap precision errors. They executed carefully controlled $osETH → swaps to accumulate precision errors. They swapped between liquidity tokens (WETH → osETH) to restore liquidity. They repeated steps 2-4 to amplify the error continuously. They swapped the liquidity tokens back into BPT to restore the pool balance.

The attacker first swapped BPT for liquidity tokens to drain and reduce the pool’s liquidity reserves in a bid to prepare for small-amount swaps. They then conducted swaps between liquidity tokens (osETH → WETH) to set up control over small-swap precision errors. Next, they executed highly controlled osETH → WETH swaps to intentionally build up precision errors.

Afterwards, the attacker swapped between liquidity tokens again (WETH → osETH) to restore enough liquidity. After repeating the steps 2-4 in loops to continuously expand the accumulated error, they finally swapped the liquidity tokens back into BPT to return the pool to a balanced state. Through repeatedly leveraging the precision flaw with small-sized swaps, the attacker pushed the system into settling a final “amountOut” that exceeded the true amountIn owed, and allowed them to pocket a massive profit.

SlowMist managed to trace the attacker’s operations across addresses and multiple chains. It found initial funds were routed through Tornado Cash, then through intermediate nodes and cross-chain gas.zip usage, before being assembled on Ethereum-based addresses holding thousands of ETH and WETH.

Remediation Efforts

As part of the remediation efforts, CSPv6 pools across the affected network were paused, CSPv6 factory disabled was disabled, gauges were killed for affected pools, and major LPs safely withdrew, among other steps.

The Balancer team coordinated with whitehats as well as cybersecurity partners and various networks to retrieve or freeze portions of the stolen funds. This included 5,041 StakeWise osETH worth about $19 million and 13,495 osGNO, estimated to be around $2 million.

To project teams and auditors facing similar scenarios, SlowMist said that the focus should be on enhancing test coverage for extreme cases and boundary conditions. Additionally, the firm urged the projects to pay particular attention to precision handling strategies under low-liquidity conditions.

The post Balancer’s $120M Meltdown: How A Series of Small Swaps Almost Broke a Top AMM appeared first on CryptoPotato.

Market Opportunity
TOP Network Logo
TOP Network Price(TOP)
$0.000096
$0.000096$0.000096
0.00%
USD
TOP Network (TOP) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

The post Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC appeared on BitcoinEthereumNews.com. Franklin Templeton CEO Jenny Johnson has weighed in on whether the Federal Reserve should make a 25 basis points (bps) Fed rate cut or 50 bps cut. This comes ahead of the Fed decision today at today’s FOMC meeting, with the market pricing in a 25 bps cut. Bitcoin and the broader crypto market are currently trading flat ahead of the rate cut decision. Franklin Templeton CEO Weighs In On Potential FOMC Decision In a CNBC interview, Jenny Johnson said that she expects the Fed to make a 25 bps cut today instead of a 50 bps cut. She acknowledged the jobs data, which suggested that the labor market is weakening. However, she noted that this data is backward-looking, indicating that it doesn’t show the current state of the economy. She alluded to the wage growth, which she remarked is an indication of a robust labor market. She added that retail sales are up and that consumers are still spending, despite inflation being sticky at 3%, which makes a case for why the FOMC should opt against a 50-basis-point Fed rate cut. In line with this, the Franklin Templeton CEO said that she would go with a 25 bps rate cut if she were Jerome Powell. She remarked that the Fed still has the October and December FOMC meetings to make further cuts if the incoming data warrants it. Johnson also asserted that the data show a robust economy. However, she noted that there can’t be an argument for no Fed rate cut since Powell already signaled at Jackson Hole that they were likely to lower interest rates at this meeting due to concerns over a weakening labor market. Notably, her comment comes as experts argue for both sides on why the Fed should make a 25 bps cut or…
Share
BitcoinEthereumNews2025/09/18 00:36
ZKP Climbs 300% in Presale Auction: Experts Choose This AI Coin Above XRP & Ethena for 2026

ZKP Climbs 300% in Presale Auction: Experts Choose This AI Coin Above XRP & Ethena for 2026

The worldwide market stays firm close to $3.32 trillion, but momentum slows as Bitcoin settles. The XRP price sits stuck below $2.10, and the Ethena price pulls
Share
Coinstats2026/01/19 05:15
ZKP Is the Only Presale Auction With Proof-Backed Rewards: Solana and Binance Left Behind

ZKP Is the Only Presale Auction With Proof-Backed Rewards: Solana and Binance Left Behind

Liquidity is rotating fast in January 2026. The market is no longer chasing top ten tokens based on name alone. […] The post ZKP Is the Only Presale Auction With
Share
Coindoo2026/01/19 06:02