Реклама партнера — Название партнёра
UNIT.City — місце, де люди працюють... КРАЩЕ! Обирай свій простір просто зараз 👉

Hackers stole $120 million from DeFi protocol Balancer due to rounding error

The developers of the decentralized finance (DeFi) protocol Balancer, built on the Ethereum blockchain, said that attackers attacked their v2 pools and caused losses of $128 million. How did they do it?

Leave a comment
Hackers stole $120 million from DeFi protocol Balancer due to rounding error

The developers of the decentralized finance (DeFi) protocol Balancer, built on the Ethereum blockchain, said that attackers attacked their v2 pools and caused losses of $128 million. How did they do it?

Balancer provides flexible pools with custom token combinations, allowing users to deposit assets, earn commissions, and enable traders to exchange assets. The protocol is governed by the BAL token, which had a market cap of $65 million just before the incident, Bleeping Computer reports .

Balancer asked users to be cautious about potential scams or phishing attempts.

The company confirmed that its V2 Compostable Stable Pools were affected by the attack, which did not affect other Balancer pools, including the V3.

«Our team is working with leading security researchers to understand the root of the problem,» Balancer said.

The Balancer V2 exploit is reported to have arisen due to a precision rounding error in Vault exchange calculations.

How rounding worked in Balancer pools

Each exchange operation rounded down the token amounts, creating small discrepancies that an attacker could exploit repeatedly. By chaining multiple exchanges through the batchSwap function, these rounding losses led to significant price distortion.

However, some users attribute the hack to improper authorization and callback handling within Balancer V2 repositories.

Read the country's main IT news in our Telegram
Read the country’s main IT news in our Telegram
On the topic
Read the country’s main IT news in our Telegram
Ireland extradites Ukrainian suspected of cybercrimes by Russian hacker group Conti to US. He faces 25 years in prison
Ireland extradites Ukrainian suspected of cybercrimes by Russian hacker group Conti to US. He faces 25 years in prison
On the topic
Ireland extradites Ukrainian suspected of cybercrimes by Russian hacker group Conti to US. He faces 25 years in prison
Hackers from North Korea are attacking European drone manufacturers under the guise of employment: what does Ukraine have to do with it?
Hackers from North Korea are attacking European drone manufacturers under the guise of employment: what does Ukraine have to do with it?
On the topic
Hackers from North Korea are attacking European drone manufacturers under the guise of employment: what does Ukraine have to do with it?
A German citizen was "swindled" out of $60,000 by two crypto fraudsters from Vinnytsia region
A German citizen was «swindled» out of $60,000 by two crypto fraudsters from Vinnytsia region
On the topic
A German citizen was «swindled» out of $60,000 by two crypto fraudsters from Vinnytsia region

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.