Balancer V1 Pool Hacked for $234K in Same Bug Family

By Bitcoin News | Created at 2026-08-31 15:38:37 | Updated at 2026-08-31 16:34:17 1 hour ago

A Balancer V1-style liquidity pool lost roughly $234,000 to a rounding-error exploit on August 31, according to Slowmist, the same category of bug that drained $116 million from Balancer’s V2 pools last November.

Key Takeaways

  • A Balancer V1 pool lost about $234,000 to a rounding-error exploit on August 31, per Slowmist.
  • The attacker compressed WBTC reserves to dust, minting full BPT for a rounded-down 1-satoshi input.
  • Balancer Labs shut down as a company in March 2026 after a similar bug drained $116 million.

A Small Hack With a Familiar Signature

Even though Balancer has seen a similar scenario play out before, history once again repeated itself today. A few hours ago, blockchain security firm Slowmist highlighted a fresh exploit against a Balancer V1-style pool, this time for a comparatively modest $234,000.

Small as it is next to Balancer’s history, the bug family is unmistakable, i.e. a rounding error in how the protocol calculates token amounts during a swap, the same category of flaw that let an attacker drain $116 million from Balancer’s V2 pools across multiple chains last November.

How the Exploit Actually Worked

According to Slowmist’s technical breakdown, the attacker targeted the pool’s joinswapPoolAmountOut function, which lets a caller specify how many BPT, or Balancer Pool Tokens, they want to receive while the contract works backward to calculate the required input.

That reverse calculation, handled by calcSingleInGivenPoolOut, uses 18-decimal fixed-point math. By running a series of public swaps, the attacker compressed the pool’s WBTC reserves down to almost nothing. With the reserves reduced to dust, the math rounded the required input down to just 1 satoshi of WBTC, a fraction of a cent, while the contract still minted the full amount of BPT the attacker requested.

Slowmist said the pool was missing basic safeguards that could have stopped this, including a minimum effective input, a minimum pool balance, and relative-error validation. The contract’s MIN_BALANCE check, it noted, was only enforced during the bind and rebind functions, not during ordinary swaps. Slowmist published both the attacker’s wallet and the attack contract address as part of its alert.

Balancer’s Long Shadow

In March, Balancer Labs, the company behind the protocol, announced that it would shut down as a corporate entity, citing mounting legal exposure five months after the November 2025 exploit which sent the protocol’s total value locked tumbling from about $775 million to around $300 million.

Co-founder Fernando Martinelli said at the time that the DAO would take over operations in a leaner form specifically to get out from under “the liability of past security incidents.” The wallet behind that original hack has stayed active too, resurfacing five months later to move 1,100 ETH through Thorchain.

Today’s exploit hit WBTC, a tokenized representation of bitcoin, rather than Balancer’s own governance token, a reminder that even as bitcoin’s price sits comfortably near $78,000, the wrapped and tokenized versions of it living inside dementalized finance (DeFi) protocols carry their own, separate set of risks.

Read Entire Article