Balancer website hijack puts users at risk

Balancer’s user interface woes follow an exploit last month targeting its liquidity pools

article-image

Vladimir Kazakov/Shutterstock, modified by Blockworks

share

DeFi liquidity protocol Balancer is staring down yet another security vulnerability, this time targeting its user interface. 

The platform issued a notice on social media Tuesday evening, urging users not to interact with the main Balancer UI until further notice as they investigate. Investors and users of Balancer are advised to remain vigilant and await further updates.

Crypto sleuth ZachXBT, revealed on X, formerly Twitter, that the stolen funds are being funneled into a specific Ethereum address. Approximately $238,000 has reportedly been pilfered so far. 

Analysis of the address shows it currently holds 68 ether (ETH) valued at more than $111,000, based on the current ETH price of $1,636.

In the last eight hours, a series of ERC-20 token transfers involving the address labeled “Balancer Attacker” can be viewed from Etherscan, a popular analytics tool. 

Tokens, including Balancer’s native BAL token, liquid staked ether, Aave’s wrapped tokens, and several others, have so far been transferred in and out of the address.

The developments Wednesday follow a series of assaults against the protocol in recent weeks including an exploit of a critical vulnerability in its v2 pools late last month.

Built on the Ethereum blockchain, Balancer functions as both an automated market maker and a liquidity protocol, allowing users to trade tokens directly from its liquidity pools, without the need for a traditional order book.

In recent hours, Balancer’s native token (BAL) has experienced some volatility, though the full extent of the financial fallout remains to be seen. BAL is down 3.2% on the day from a top of $3.44 to $3.27, exchange data shows.

Balancer is not the first DeFi platform to fall victim to a cyber-attack this year. There has been a noticeable uptick in security breaches targeting DeFi projects in recent months, leading to a broader conversation in the industry about the need for enhanced security measures.

The Balancer team said it is currently investigating the issue, and it’s yet unclear how the attackers managed to exploit the system. Blockworks has reached out to learn more.


Get the news in your inbox. Explore Blockworks newsletters:

Tags

Decoding crypto and the markets. Daily, with Byron Gilliam.

Upcoming Events

Old Billingsgate

Mon - Wed, October 13 - 15, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

Flashnote Template (41).png

Research

We believe that few tokens at the application layer are diverging more from fundamentals than ZORA. Its fully-diluted P/S sits at 90x, pricing significant growth despite a consistent decline in weekly revenues since late July. We foresee an 80% decrease in protocol net margins due to a recent update to the fee structure that reduces trading fees from 3% to 1%, while boosting creators’ portion of the fee split. ZORA’s supply overhang also represents a near-term headwind, with 45% of ZORA’s supply (4.5B tokens or $350M at current prices) earmarked for the team & investors beginning to unlock on October 23, 2025 (36-month linear vesting schedule).

article-image

Insiders have the best information — markets should be willing to pay for it

article-image

The CFTC-regulated exchange is opening doors to crypto builders and traders through grants, partnerships, and new deposit options

by Blockworks /
article-image

DFS tells banking organizations to integrate blockchain monitoring tools to curb money laundering and sanctions risks

by Blockworks /
article-image

New short and long-term priorities include L1 gas boosts, ZK-EVMs, privacy reads, and a lean, quantum-resistant Ethereum

by Blockworks /
article-image

The new stBTC token redistributes Bitcoin gas fees to users, creating liquid yield without inflation or lockups

by Blockworks /
article-image

The reserve will collect protocol revenues to back W token, alongside new yield and unlock schedule

by Blockworks /