Cryptocurrency [loss] $110M+

"Balancer Hit by Apparent Exploit as $110M in Crypto Moves to New Wallets"

2025-11-03 [vendor] Balancer [chain] ethereum, polygon
Primary Source ↗
Financial Loss $110.0M (110,000,000 USD)
Blockchain(s) Ethereum, Polygon

Incident Details

The defi protocol Balancer suffered a major exploit that drained over $110 million across several blockchains, including Ethereum, Polygon, Base, and Sonic. Attackers exploited faulty access control in the manageUserBalance function of Balancer’s v2 smart contract, enabling unauthorized internal withdrawals. The stolen tokens included 6,850 osETH, 6,590 wETH, and 4,260 wstETH, later consolidated into new wallets likely for laundering.The exploit also impacted forked protocols like Beets Finance, which lost around $3 million. Balancer’s BAL token dropped over 10% following the theft.This was Balancer’s third major security incident since 2020, despite prior audits by OpenZeppelin and Trail of Bits.

Total loss estimated at $110,000,000.

Technical Details

Initial Attack Vector
Smart contract access control vulnerability
Vendor / Product
Balancer

Timeline

  1. 2025-11-03 Breach occurred
  2. 2025-11-03 Publicly disclosed