‘Critical vulnerability’ reported in Balancer v2 pools

The vulnerability has been mitigated in around 80% of the affected v2 pools

article-image

Tang Yan Song/Shutterstock modified by Blockworks

share

Liquidity protocol Balancer has discovered and disclosed a “critical vulnerability” affecting more than 100 of its v2 pools across eight blockchains.

Balancer said the issue has been mitigated in around 80% of the impacted pools. The remaining 20% of affected pools represent roughly 4% of Balancer’s total value locked (TVL).

The Balancer team posted a list of affected pools on its GitHub page and its emergency subDAO has been activated, enabling users to exit from affected pools. 

“We believe funds in the mitigated pools (labeled ‘mitigated’) are safe, but nevertheless strongly recommend timely migration to safe pools, or withdrawal,” Jeff Bennett, a software engineer at Balancer Labs, wrote in a post. 

Bennett urged all liquidity providers to exit their positions in affected pools immediately. 

“Pools that could not be mitigated are labeled ‘at risk.’ If you are [a liquidity provider] in any of these pools, please exit immediately,” he wrote.

The situation had an immediate market impact. The price of Balancer’s native token BAL dipped by over 4% on the news of the vulnerabilities. BAL’s price has since recovered, trading at $3.47 at the time of writing. 

Blockworks Research analyst Spencer Hughes noted that the Balancer vulnerability shows that smart contract audits cannot guarantee total safety, and that it is important to note that they never claimed to be.

“With ~$830M TVL, a Balancer exploit would have left one of the most prominent DEXs for dead,” Hughes said. “Emergency SubDAOs are definitely very important for all DeFi protocols, and it is great that they were able to act before anything malicious could occur.”


Start your day with top crypto insights from David Canellis and Katherine Ross. Subscribe to the Empire newsletter.

Tags

Upcoming Events

Salt Lake City, UT

WED - FRI, OCTOBER 9 - 11, 2024

Pack your bags, anon — we’re heading west! Join us in the beautiful Salt Lake City for the third installment of Permissionless. Come for the alpha, stay for the fresh air. Permissionless III promises unforgettable panels, killer networking opportunities, and mountains […]

recent research

aptos cover3.jpg

Research

A fragmented liquidity landscape across L2s has led to newfound appreciation for predominantly monolithic L1 architectures over the past year, especially when considering qualifying capabilities like high throughput and low latency. Despite Aptos being a relatively young blockchain when compared to other L1s, a combination of design choices, network adoption, partnerships, and dApp development proves that the network is primed for breakout momentum over the coming years.

article-image

Tokens for soccer teams Paris Saint-Germain and FC Barcelona mirror their victories and losses

article-image

Coinbase’s stablecoin revenue jumped 15% quarter over quarter

article-image

Stronghold Digital Mining’s market value compared to its peers is “hard for us to understand,” CEO says

article-image

Binance and detained exec Tigran Gambaryan may face three court appearances on May 17 after the most recent adjournment pushed another Nigerian trial back

article-image

Sponsored

The Earn section on Zerion now offers users the ability to stake, liquid stake, restake, and earn DeFi yields

article-image

Relatively soon, blockchain will become the only part of fintech that matters.