Balancer disclosed on June 29, 2020, that an attacker had drained assets from two of its automated-market-maker pools containing fee-on-transfer tokens. The protocol identified STA and STONK as the affected tokens and said the problem was confined to pools containing tokens that deducted fees during transfers.
The disclosure mattered beyond the immediate loss. Balancer was designed as permissionless infrastructure: anyone could create a pool and bind supported tokens without asking a central operator. The incident showed that composability also imported assumptions. A pool could execute exactly as coded and still lose assets when a token's transfer behavior differed from the accounting model the pool expected.
How the accounting was manipulated
Balancer's event-day explanation said the attacker borrowed ETH through dYdX, converted it to wrapped ether, and repeatedly traded WETH against STA. STA charged a transfer fee, so each trade delivered less STA to the pool contract than Balancer's internal record assumed.
After enough repetitions, the attacker invoked Balancer's `gulp()` function, which synchronized the pool's stored token balance with the token contract's actual balance. With the actual STA balance close to zero, Balancer's formula treated STA as extremely expensive relative to the pool's other assets. The attacker could then exchange trivial quantities of STA for valuable assets at distorted prices.
A separate event-day analysis by 1inch traced a complex Ethereum transaction that repeated the WETH-STA trade 24 times after a flash loan of 104,000 WETH. It said the same path drained WETH, wrapped bitcoin, Synthetix and Chainlink tokens from one pool, followed minutes later by a second pool transaction. Those technical findings were an investigator's reconstruction of public transactions, not an audit or judicial finding.
Loss estimates and their limits
1inch estimated the affected pool loss at nearly $500,000 and the attacker's proceeds at almost $425,000. The difference reflected, among other things, its estimate that 2.4 million STA notionally worth about $100,000 was converted into 109 WETH worth about $25,000. Those were event-day mark-to-market estimates. The analysis did not identify a shared pricing venue, price timestamp or realized-dollar conversion, so the values should be read as approximate exposure rather than audited loss.
Security researcher Ankur Agrawal wrote on June 29 that the attack occurred in Ethereum block 10,355,807 on June 28 and exceeded $500,000 across pools containing STA and STONK. Agrawal also published what he described as the full report submitted to Balancer on May 6. The report identified the mismatch between Balancer's stored balances and fee-on-transfer tokens, described using `gulp()` to reset the balance near zero, and outlined draining the pool afterward.
That history made the incident a test of disclosure and triage, not merely contract code. On June 29, Balancer said it had warned that transfer-fee tokens could have unintended effects, excluded STA from its BAL mining whitelist, and had not known this specific attack was possible. It planned to blacklist such tokens in its interface, expand documentation and continue audits. Because the contracts were permissionless, an interface blacklist could reduce exposure through Balancer's own front end but could not prevent tokens from being added at the contract level.
Market context on June 29
The broader crypto market did not show a comparable dislocation in Kraken's UTC-day report. Kraken recorded XBT at $9,181.30, up 0.7% for the reporting day, on $83.1 million of exchange volume; ETH was $227.78, up 1.3%, on $18.8 million. Those figures cover Kraken only, not a consolidated global close, and do not establish that the Balancer incident caused any market move.
Later clarification
On June 30, Balancer said Agrawal's report had described the attack but the team had judged it impractical. It announced reimbursement for affected liquidity providers and changes to its bounty process. That later response clarifies accountability; it was not yet part of the initial June 29 disclosure.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

