Close Menu
Altcoin ObserverAltcoin Observer
  • Regulation
  • Bitcoin
  • Altcoins
  • Market
  • Analysis
  • DeFi
  • Security
  • Ethereum
Categories
  • Altcoins (2,274)
  • Analysis (2,427)
  • Bitcoin (3,028)
  • Blockchain (1,857)
  • DeFi (2,208)
  • Ethereum (2,151)
  • Event (78)
  • Exclusive Deep Dive (1)
  • Landscape Ads (2)
  • Market (2,254)
  • Press Releases (10)
  • Reddit (1,692)
  • Regulation (2,112)
  • Security (2,910)
  • Thought Leadership (3)
  • Videos (43)
Hand picked
  • Balancer hacked? Ethereum DeFi Powerhouse Sees $110 Million in Crypto Moved
  • US National Debt 2025 Hits $38 trillion: Will Crypto be the best hedge against dollar debasement in 2025?
  • Bitwise sees a glimmer of hope for investors after a dark week
  • Luxembourg transfers 1% of its national wealth to Bitcoin
  • Cardano founder Charles Hoskinson and Scaramucci’s company are investing in Trump-linked US Bitcoin in a $220 million funding round.
We are social
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Facebook X (Twitter) Instagram
  • About us
  • Disclaimer
  • Terms of service
  • Privacy policy
  • Contact us
Facebook X (Twitter) Instagram YouTube LinkedIn
Altcoin ObserverAltcoin Observer
  • Regulation
  • Bitcoin
  • Altcoins
  • Market
  • Analysis
  • DeFi
  • Security
  • Ethereum
Events
Altcoin ObserverAltcoin Observer
Home»DeFi»Balancer hacked? Ethereum DeFi Powerhouse Sees $110 Million in Crypto Moved
DeFi

Balancer hacked? Ethereum DeFi Powerhouse Sees $110 Million in Crypto Moved

November 16, 2025No Comments
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Balancer, a decentralized finance (DeFi) protocol with a locked value of over $750 million, appears to have been hit with its biggest exploit yet, with on-chain data showing over $110 million in digital assets drained to a new wallet.

The affected funds include 6,850 osETH, 6,590 WETH and 4,260 wstETH, blockchain data analyzed by CoinDesk showed and appear to impact vaults on Balancer version 2 (V2).

Further analysis shows that various safes have also been hit and drained in Sonic, Polygon, and Base.

How the attack took place

The attack occurred due to faulty access control in its “manageUserBalance” function, according to security tool Decurity.

The vulnerability stems from validateUserBalanceOp, which checks msg.sender against a user-provided op.sender, a logic flaw that allows unauthorized withdrawals via the UserBalanceOpKind.WITHDRAW_INTERNAL operation.

In effect, this means that attackers could trigger internal balance withdrawals from Balancer smart contracts without the proper permissions.