Balancer website hijack puts users at risk

Balancer’s user interface woes follow an exploit last month targeting its liquidity pools

article-image

Vladimir Kazakov/Shutterstock, modified by Blockworks

share

DeFi liquidity protocol Balancer is staring down yet another security vulnerability, this time targeting its user interface. 

The platform issued a notice on social media Tuesday evening, urging users not to interact with the main Balancer UI until further notice as they investigate. Investors and users of Balancer are advised to remain vigilant and await further updates.

Crypto sleuth ZachXBT, revealed on X, formerly Twitter, that the stolen funds are being funneled into a specific Ethereum address. Approximately $238,000 has reportedly been pilfered so far. 

Analysis of the address shows it currently holds 68 ether (ETH) valued at more than $111,000, based on the current ETH price of $1,636.

In the last eight hours, a series of ERC-20 token transfers involving the address labeled “Balancer Attacker” can be viewed from Etherscan, a popular analytics tool. 

Tokens, including Balancer’s native BAL token, liquid staked ether, Aave’s wrapped tokens, and several others, have so far been transferred in and out of the address.

The developments Wednesday follow a series of assaults against the protocol in recent weeks including an exploit of a critical vulnerability in its v2 pools late last month.

Built on the Ethereum blockchain, Balancer functions as both an automated market maker and a liquidity protocol, allowing users to trade tokens directly from its liquidity pools, without the need for a traditional order book.

In recent hours, Balancer’s native token (BAL) has experienced some volatility, though the full extent of the financial fallout remains to be seen. BAL is down 3.2% on the day from a top of $3.44 to $3.27, exchange data shows.

Balancer is not the first DeFi platform to fall victim to a cyber-attack this year. There has been a noticeable uptick in security breaches targeting DeFi projects in recent months, leading to a broader conversation in the industry about the need for enhanced security measures.

The Balancer team said it is currently investigating the issue, and it’s yet unclear how the attackers managed to exploit the system. Blockworks has reached out to learn more.


Get the news in your inbox. Explore Blockworks newsletters:

Tags

Decoding crypto and the markets. Daily, with Byron Gilliam.

Upcoming Events

Old Billingsgate

Mon - Wed, October 13 - 15, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

Industry City | Brooklyn, NY

TUES - THURS, JUNE 24 - 26, 2025

Permissionless IV serves as the definitive gathering for crypto’s technical founders, developers, and builders to come together and create the future.If you’re ready to shape the future of crypto, Permissionless IV is where it happens.

recent research

Research Report Templates.png

Research

Content Delivery Networks (CDNs) represent low-hanging fruit in a massive market ripe for Web3-driven disruption. The global CDN market was valued at ~$28B in 2024, and is projected to surpass $140B by 2034, (18.75% CAGR) underscoring the immense demand for efficient content delivery.

article-image

Sponsored

Connect in one click from any device to help build a verifiable world and earn rewards

article-image

The Flippening was always a meme, but for a moment it wasn’t so funny

article-image

Frachtis is focused on pre-seed and seed rounds in both consumer apps and AI

article-image

Markets look forward, even when we can’t see past the news

article-image

Solana’s price run might stall as ETH gains institutional favor

article-image

The soccer club is using the XRP-compatible Root blockchain and is expected to release a mobile racing game, too