Balancer V1 pool loses $234K in exploit tied to calculation error
August 31, 2026, 4:29 AM
Around $234,000 in assets was stolen from a Balancer V1 BPool in an attack that exploited a calculation error, SlowMist reported. The attacker repeatedly used public swaps to drain the pool’s WBTC balance to near zero, then manipulated the `joinswapPoolAmountOut` function so the required WBTC input was calculated at roughly one satoshi. The attacker then deposited that tiny amount of WBTC, minted 4,408.8 BPT, and withdrew DPI, USDC, WETH and WBTC from the pool. The funds needed for the attack were sourced through flash loans from Spark, Aave, Morpho and Uniswap V3. SlowMist identified the lack of a minimum input threshold, a minimum pool balance requirement and validation checks to filter out calculation errors as the cause of the vulnerability.
Leave the first comment
You need to log in to leave a comment.
Log In