Balancer hack analysis explains how a rounding bug in upscale logic enabled cross-chain drain, detailing losses, recoveries, and safeguards.Balancer hack analysis explains how a rounding bug in upscale logic enabled cross-chain drain, detailing losses, recoveries, and safeguards.

Balancer hack: Rounding bug in upscale triggered $116.6M

2025/11/06 23:17
2분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다
balancer hack

Balancer teams issued a Balancer hack analysis after the incident on Nov 3, outlining how an original report and the Balancer incident report traced crypto asset flows, recovery steps and mitigation plans for affected users across paused pools.

What caused the Balancer hack upscale function rounding bug and cross network asset drain?

Protocol engineers traced the failure to an upscale function rounding bug that distorted token scaling during swaps. In this context, non-integer scaling factors produced small arithmetic discrepancies.

Consequently, attackers amplified those errors through repeated transactions and extracted liquidity across chains.

On Nov 3, Balancer reported losses totalling $116.6 million. The breach touched multiple networks and tokens, requiring immediate containment.

How did the bug enable the drain?

The bug altered internal scaling calculations. As a result, tiny rounding differences grew with large swap volumes. That produced exploitable pool imbalances that allowed quiet vault transfers before final withdrawals.

Which assets were affected?

  • 6,587 WETH
  • 6,851 osETH
  • 4,260 wstETH

How did security partners freeze pools and coordinate whitehat asset recovery efforts after the Balancer hack?

Immediate mitigation came from protocol teams and external partners. They enacted emergency steps to security partners freeze pools and halt vulnerable operations. Meanwhile, automated bots and white-hat groups began tracing and intercepting flows.

The coordinated response combined on-chain forensics, multisig freezes and negotiated returns. That said, some attacker-converted assets moved into ETH and remain irretrievable.

Did StakeWise actions affect the outcome during stakewise oseth recovery after the Balancer hack?

StakeWise led targeted restitution for its exposure. According to disclosed figures, it recovered $19M, roughly 73.5% of the drained osETH, and will return funds to affected users based on pre-incident balances.

What role did whitehat asset recovery efforts play?

Whitehat teams returned assets and supplied forensic leads that improved traceability. Moreover, their activity reduced net losses and aided coordination between affected projects and security partners.

Security experts emphasise the broader lesson: arithmetic edge-cases in token scaling pose systemic risk and demand stricter type checks.

As the original report notes, “Balancer identified a rounding bug” in the upscale logic, and independent reviewers recommend full reconciliations. Consequently, protocols should prioritise audits and standardized testing to close similar attack vectors.

Remaining work includes reconciliations and legal steps to secure residual funds. Some movement figures remain under review and are marked as [data to verify].

Independent audits and continuous monitoring are essential for long-term risk reduction.

시장 기회
CROSS 로고
CROSS 가격(CROSS)
$0.09759
$0.09759$0.09759
-3.05%
USD
CROSS (CROSS) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

Roll the Dice & Win Up to 1 BTC

Roll the Dice & Win Up to 1 BTCRoll the Dice & Win Up to 1 BTC

Invite friends & share 500,000 USDT!