
Balancer V2
HackedDeFi · $BAL · born 2020 · ✝ 2025
A rounding flaw in stable pools cost it ~$128M across six chains.
Balancer V2 was a leading automated market maker whose Composable Stable Pools contained an exploitable logic flaw. In 2025 attackers abused that flaw to drain roughly $128M across Ethereum, Arbitrum, Base, Polygon, Sonic, and Optimism.
- Peak
- ~$128M stolen
- Cause
- Hacked
- Year of death
- 2025
☠️ Cause of death
An exploit in the Composable Stable Pool math let attackers manipulate balances and extract funds across every chain the pools were deployed on.
📓 Lessons left behind
- —Shared pool logic multiplies blast radius across chains.
- —Stable-pool invariants need formal verification.
- —Battle-tested code can still hide latent math bugs.
🌱 The idea that survived
Invariant testing
Pushed AMMs toward formal verification and invariant testing of pool accounting math.
#defi#amm#protocol-logic#multichain