Balancer V1 Exploit Results in $234,000 Loss
An exploit in Balancer V1 led to a significant financial loss. The attacker used a precision vulnerability to drain multiple assets from the pool.
An attacker exploited a rounding and precision vulnerability in the legacy Balancer V1 contracts, targeting the platform directly. By utilizing flash loans, the attacker was able to compress the WBTC reserves to near-zero, which facilitated the minting of a large amount of Balancer Pool Tokens (BPT) with only a minimal amount of WBTC involved.
Following the minting of BPT, the attacker executed a proportional exit from the pool, which allowed them to drain various assets including DPI, USDC, WETH, and WBTC. This maneuver resulted in a total loss of $234,000. The incident highlights the risks associated with vulnerabilities in smart contracts, particularly in legacy systems.
The exploit occurred on the Ethereum blockchain, which means that all transactions related to this incident can be traced on-chain. The specific addresses involved in the exploit were not provided, but the nature of the attack suggests that the movement of funds can be tracked through the blockchain's transaction history.
