A legacy pool exploit spread across networks

On November 3, 2025, malicious transactions began hitting Balancer V2 Composable Stable Pools at 07:46 UTC across Ethereum, Arbitrum, Base, Optimism and Polygon. Balancer’s later incident timeline says its monitoring partner alerted the operations team at 07:52 UTC. At 09:50 UTC, Balancer publicly acknowledged a potential exploit affecting V2 pools, and at 11:01 UTC it enabled Recovery Mode on affected pools so remaining liquidity could be withdrawn through proportional exits.

The event-day picture was necessarily incomplete. The Block’s report, updated at 05:05 a.m. Eastern on November 3, cited PeckShield for an estimated $128.6 million in assets withdrawn from Balancer vaults and pointed to transaction logs showing large transfers of wrapped and staked-ether assets. That was an evolving gross-outflow estimate, not a final audited loss. Balancer had not yet published a root-cause analysis, and early observers could not safely assume that every V2 pool, every Balancer deployment or the newer V3 architecture was vulnerable.

Why the breach mattered

Balancer was not simply a token issuer. Its automated-market-maker contracts held liquidity and supplied pool infrastructure used directly and through other decentralized-finance applications. A defect in reusable pool logic could therefore appear on several networks in nearly the same window and could expose liquidity providers as well as integrations built around the affected pools.

The scope was serious but specific. Balancer’s subsequent review said the theft primarily hit legacy V5 Composable Stable Pools. It said V2 Weighted Pools, Gyro Pools and other Stable Pool designs were not affected by this attack, while V3 used a different architecture and was unaffected. That distinction matters: “Balancer was exploited” was accurate shorthand for the incident, but it was not evidence that every contract carrying the Balancer name had failed.

Emergency controls also changed the amount at risk while the incident was unfolding. Balancer’s later timeline says vulnerable V6 Composable Stable Pool implementations were paused by 08:07 UTC, protecting an estimated $19.3 million of liquidity. Recovery Mode did not reverse the theft; it reduced the complexity of exits for funds that remained.

What the numbers could and could not show

Public loss estimates differed because researchers were tracking multiple chains, token valuations, attacker withdrawals, internal Vault balances, white-hat interventions and, in some tallies, protocol forks outside Balancer’s control. The November 3 figure of $128.6 million reported by The Block should therefore be read as an attributed contemporaneous estimate of assets drained, with no common valuation timestamp published in that report.

Balancer’s November 18 post-mortem later used several measures. Its financial-impact section estimated $121.1 million in total losses across the five named networks and approximately $45.7 million protected or recovered, while its introduction described an estimated $94.8 million theft of user funds. The public report did not fully reconcile those labels. This reconstruction preserves the distinction rather than presenting one figure as a definitive event-day settlement.

Later technical clarification

On November 5, Check Point Research attributed the attack to arithmetic precision loss in Composable Stable Pool calculations combined with crafted batch swaps. Balancer’s November 18 account refined that explanation: an incorrect rounding direction in the “exact out” swap path became exploitable only when rate-provider imprecision and a deliberately induced low-liquidity state were also present. The attacker could then underpay for specified outputs and progressively distort the pool invariant used to value Balancer Pool Tokens.

Those findings explain why a tiny arithmetic inconsistency could become a large extraction, but they were not established in Balancer’s first November 3 warning. The durable event-day conclusion is narrower: specific legacy V2 pool contracts were being exploited across multiple networks, emergency containment was underway, and the final financial impact remained uncertain.

Primary sourceBalancer Protocol — Nov. 3 Exploit Post-Mortem

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.