Need help? Support
BITCOIN
Tether Dominance USDT.D

Which pools were exploited at Balancer?

Published 481 words 3 min read

TLDR

Balancers hack targeted Balancer V2 Composable Stable Pools, and a later finding showed a value?extraction path in V2 Meta?Stable Pools. V3 was not affected per a post?incident update (Balancer V2 pools and V3 unaffected).

  1. Primary impact was on V2 Composable Stable Pools on Nov 3, with LPs holding liquid staking tokens most exposed (pool class named).
  2. A separate vector was identified in V2 Meta?Stable Pools during recovery reconciliation (meta?stable note).
  3. Exposure spanned Ethereum, Base, and Berachain, with LSTs like wstETH, sfrxETH, osETH, and rsETH in affected pools (multi?chain and LST set).

Deep Dive

1. V2 Composable Stable Pools

The attacker exploited Balancer V2 Composable Stable Pools, as acknowledged publicly after the incident. These are stable?style pools designed for correlated assets and were the focal point of the exploit on Nov 3 (explicit pool class).

  • LPs in these pools, especially those paired with liquid staking tokens, bore the greatest impact due to how the vault balances and swap paths were manipulated.
  • Reporting around the incident clusters the loss window around early November and aligns with composable stable pool mechanics.
What this means

If you were an LP in any V2 Composable Stable Pool around that date, review your positions and the projects reconciliation guidance before interacting again.

2. V2 Meta?Stable Pools

During the recovery effort, Balancer disclosed a new value?extraction path affecting V2 Meta?Stable Pools linked to the same incident window. This indicates the issue was not confined only to composable stable pools and widened the set needing reconciliation (meta?stable vector).

  • Meta?Stable Pools are designed for closely related assets with small price deviations, making them neighbors to stable?style mechanics.
  • This discovery led to additional safeguard steps and fund recovery actions.
What this means

Treat both V2 Composable Stable and V2 Meta?Stable Pools as affected classes until Balancer completes reconciliation and publishes final green?lights.

3. Tokens and Chains Involved

Coverage shows the impact spanned Ethereum, Base, and Berachain, and the stolen or moved assets featured liquid staking tokens such as wstETH, sfrxETH, osETH, and rsETH along with WETH (chains and token set).

  • Balancer later noted V3 was not affected and began white?hat recovery handling part of the funds via escrow, asking users to avoid interacting with listed pools during reconciliation (V3 unaffected and recovery note).
  • This aligns with ecosystem reports of multi?chain exposure and LST?heavy pool compositions.
What this means

If your exposure is in LST?paired V2 pools on these chains, prioritize checking Balancers recovery instructions and avoid interacting with flagged pools until the team completes returns.

Conclusion

The exploit centered on Balancer V2 stable?style architectures, first Composable Stable Pools and then Meta?Stable Pools, with LST?paired pools across Ethereum, Base, and Berachain most affected. V3 was reported as unaffected, and recovery steps are ongoing, so LPs should follow the latest official updates and refrain from interacting with flagged V2 pools until reconciliation finishes.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top