On August 31 an attacker drew around $234,000 out of a Balancer V1 pool through a rounding error. The old contracts cannot be paused, so liquidity providers have to exit themselves.
An attacker exploited a Balancer V1 pool, causing around $234,000 in losses through a rounding flaw after compressing WBTC reserves. It underscores the risks in other immutable Balancer V1 pools that still use the legacy joins and exits computations.
An attacker drained approximately $234,000 from a legacy Balancer V1 liquidity pool on August 31, 2026. The vulnerability allowed the minting of 4,408.8 BPT tokens by depositing just a single satoshi after compressing WBTC reserves. The attack utilized nested flash loans from platforms such as Aave, Spark, Morpho, and Uniswap V3.