On August 31 an attacker drew around $234,000 out of a Balancer V1 pool through a rounding error. The old contracts cannot be paused, so liquidity providers have to exit themselves.
An attacker exploited a Balancer V1 pool, causing around $234,000 in losses through a rounding flaw after compressing WBTC reserves. It underscores the risks in other immutable Balancer V1 pools that still use the legacy joins and exits computations.
An attacker drained approximately $234,000 from a legacy Balancer V1 liquidity pool on August 31, 2026. The vulnerability allowed the minting of 4,408.8 BPT tokens by depositing just a single satoshi after compressing WBTC reserves. The attack utilized nested flash loans from platforms such as Aave, Spark, Morpho, and Uniswap V3.
A Balancer V1-style liquidity pool lost roughly $234,000 to a rounding-error exploit on August 31, according to Slowmist, the same category of bug that drained $116 million from Balancer's V2 pools last November.
Token of Power suffered an exploit on Tuesday that drained more than $1.5 million from its liquidity pool. On-chain firms Blockaid, PeckShield, and Cyvers flagged the incident in posts on X.
The Balancer exploiter reactivated wallets that had been dormant for five months and began converting 1,100 ETH into BTC through THORChain. Funds stolen from Balancer amount to approximately $120 million in ETH, and the laundering pattern replicates the one used in the KelpDAO hack.