Balancer V1 Pool Drained of $234K in Recurring Rounding-Error Exploit
Blockchain security firm Slowmist has reported that a Balancer V1-style liquidity pool was exploited on August 31, resulting in losses of roughly $234,000. The attack exploited a rounding-error vulnerability in the pool's smart contract logic, allowing the attacker to manipulate calculations and extract funds.
This is not an isolated incident. The same category of bug was responsible for a much larger breach last November, when Balancer's V2 pools lost approximately $116 million. The recurrence of this flaw across different versions of the protocol highlights how subtle mathematical errors in smart contract code can persist and be re-exploited over time, even after being identified in earlier incidents.
While this story centres on decentralised finance infrastructure rather than traditional business systems, it serves as a reminder for any organisation building or integrating with blockchain-based financial tools. Rounding and calculation errors are a recurring class of vulnerability in smart contracts, and businesses relying on third-party DeFi protocols should be aware that historical bug classes can resurface in new deployments if not properly patched.