The Balancer team has issued their first report after a significant security incident that resulted in approximately $116 million in losses.
The detailed report elaborates on how the breach occurred and the actions being taken in response.
The breach occurred on November 3 and it specifically affected two pool types within Balancer: v2 Stable Pools and Composable Stable v5 Pools.
Did you know?
Subscribe – We publish new crypto explainer videos every week!
What Are Flash Loans? TOP Ways to Make Passive Income Explained
The attacker leveraged a technique combining transaction bundling, known as BatchSwaps, with flash loans, which are loans that are executed and reimbursed in a singular transaction. They exploited a vulnerability within the system’s rounding mechanism used for certain token exchanges.
Typically, this function rounds values down, but the attacker had the capability to manipulate the rounding process to their benefit.
The combination of the rounding issue and the bundled transactions allowed the attacker to extract funds from the targeted pools. Balancer indicated that many of the stolen assets were initially retained in its internal balance system before being transferred out in subsequent operations.
In response to the incident, Balancer has collaborated with various blockchain security entities and protocol teams to either recover or freeze part of the stolen assets. This effort included retrieving approximately $19 million worth of StakeWise Staked ETH (osETH) and around $2 million in osGNO tokens.
To mitigate further risks, Balancer has halted all affected pools and temporarily disabled the creation of new pools of these types.
In a related note, a recent cyber incident involving Seedify, which supports Web3 gaming projects, resulted in the loss of around $1.2 million. How did it happen? Read the full story.
