Technical Analysis: How was Balancer Hacked for $120 Million, and Where was the Vulnerability? On [date], Balancer, a popular decentralized exchange (DEX), was hacked for $120 million in a sophisticated attack. The vulnerability exploited in this atta...
Original Article Title: "Balancer $120M Hack Vulnerability Technical Analysis"
Original Source: ExVul Security
Foreword
On November 3, 2025, the Balancer protocol was attacked on multiple chains including Arbitrum and Ethereum, resulting in a $120 million asset loss. The attack was primarily due to a dual vulnerability involving precision loss and Invariant manipulation.
Chainlink's infrastructure has long maintained the highest standards in the Web3 space, making it a natural choice for X Layer, which is dedicated to providing institutional-grade tools for developers.
The key issue in this attack lies in the protocol's logic for handling small transactions. When users conduct exchanges with small amounts, the protocol invokes the _upscaleArray function, which uses mulDown for rounding down values. When the balance in the transaction and the input amount both hit a specific rounding boundary (e.g., the 8-9 wei range), a noticeable relative precision error occurs.
This precision error is propagated to the calculation of the protocol's Invariant value D, causing an abnormal reduction in the D value. The fluctuation of the D value directly lowers the price of the Balancer Pool Token (BPT) in the Balancer protocol. The hacker exploited this suppressed BPT price through a premeditated trading path to conduct arbitrage, ultimately leading to a massive asset loss.
Exploited Transaction:
https://etherscan.io/tx/0x6ed07db1a9fe5c0794d44cd36081d6a6df103fab868cdd75d581e3bd23bc9742
Asset Transfer Transaction:
https://etherscan.io/tx/0xd155207261712c35fa3d472ed1e51bfcd816e616dd4f517fa5959836f5b48569
Technical Analysis
Attack Vector
The entry point of the attack was the Balancer: Vault contract, with the corresponding entry function being the batchSwap function, which internally calls onSwap for token exchanges.

From the perspective of function parameters and restrictions, several pieces of information can be obtained:
1. The attacker needs to call this function through the Vault and cannot call it directly.
2. The function will internally call _scalingFactors() to get the scaling factor for scaling operations.
3. The scaling operation is concentrated in either _swapGivenIn or _swapGivenOut.
Attack Pattern Analysis
BPT Price Calculation Mechanism
In Balancer's stable pool model, the BPT Price is a crucial reference point that determines how much BPT a user receives and how much each BPT receives in assets.

In the pool's exchange calculation:

Where the part acting as the BPT Price anchor is an immutable value D, which means controlling the BPT Price requires controlling D. Let's analyze the calculation process of D further:

In the above code, the calculation process of D depends on the scaled balances array. This means that an operation is needed to change the precision of these balances, leading to an incorrect D calculation.
Root Cause of Precision Loss

Scaling Operation:

As shown above, when passing through _upscaleArray, if the balance is very small (e.g., 8-9 wei), the rounding down in mulDown will result in significant precision loss.
Attack Process Detailed
Phase 1: Adjustment to Rounding Boundary

Phase 2: Trigger Precision Loss (Core Vulnerability)

Phase 3: Exploiting Depressed BPT Price for Profit

Above, the attacker uses Batch Swap to perform multiple exchanges in one transaction:
1. First Exchange: BPT → cbETH (balance adjustment)
2. Second Exchange: wstETH (8) → cbETH (trigger precision loss)
3. Third Exchange: Underlying Asset → BPT (profit-taking)
All these exchanges occur in the same batch swap transaction, sharing the same balance state, but each exchange calls _upscaleArray to modify the balances array.
Lack of Callback Mechanism
The main process is initiated by the Vault. How does this lead to accumulating precision loss? The answer lies in the passing mechanism of the balances array.

Looking at the above code, although Vault creates a new currentBalances array each time onSwap is called, in Batch Swap:
1. After the first swap, the balance is updated (but due to precision loss, the updated value may be inaccurate)
2. The second swap continues the calculation based on the result of the first swap
3. Precision loss accumulates, eventually causing the invariant value D to significantly decrease
Key Issue:

Summary
The Balancer attack can be summarized for the following reasons:
1. Scaling Function Uses Round Down: _upscaleArray uses mulDown for scaling, which results in significant relative precision loss when the balance is very small (e.g., 8-9 wei).
2. Invariant Value Calculation Is Sensitivity to Precision: The calculation of the invariant value D relies on the scaled balances array, and precision loss directly affects the calculation of D, causing D to decrease.
3. Lack of Invariant Value Change Validation: During the swap process, there was no validation to ensure that the change in the invariant value D was within a reasonable range, allowing attackers to repeatedly exploit precision loss to suppress the BPT price.
4. Accumulation of Precision Loss in Batch Swaps: Within the same batch swap, the precision loss from multiple swaps accumulates and eventually leads to significant financial losses.
These two issues—precision loss and lack of validation—combined with the attacker's careful design of boundary conditions, resulted in this loss.
This article is a contribution and does not represent the views of BlockBeats.
You may also like

Crypto Price Prediction Today 18 February – XRP, Bitcoin, Ethereum
Key Takeaways XRP’s potential as a replacement for SWIFT is bolstered by regulatory approvals, potentially driving its price…

XRP Price Prediction: XRP is Outpacing Solana and Targeting Binance Coin Next – Should You Invest Now?
Key Takeaways XRP Ledger has moved into the sixth place by tokenized real-world asset value, surpassing Solana and…

New AI Predicts the Price of XRP, Dogecoin, and Solana By 2026
Key Takeaways ChatGPT anticipates significant price increases for XRP, Dogecoin, and Solana by the end of 2026. XRP…

Arthur Hayes Shares Two Scenarios for Bitcoin Price, Calling for a Major Crypto Rally
Key Takeaways Arthur Hayes predicts a significant crypto rally fueled by a $572 billion liquidity injection from the…

Bitcoin Price Prediction: Abu Dhabi Gov Funds Buy $1 Billion in BTC – What Do They Know?
Key Takeaways Abu Dhabi has revealed a $1 billion stake in Bitcoin through major ETF investments, signaling strong…

Bitcoin’s Divergence From Nasdaq Signals Dollar Liquidity Risk, Says Arthur Hayes
Key Takeaways Arthur Hayes highlights a concerning divergence between Bitcoin and the Nasdaq, pointing to a potential dollar…

Lagarde’s Possible Early Exit Could Alter Digital Euro Plans and Stablecoin Oversight
Key Takeaways Christine Lagarde’s potential departure as ECB president may disrupt the digital euro timeline and stablecoin policies.…

HYLQ Strategy Invests in Hyperliquid Quantum Solutions Pioneer qLABS, Acquires 18,333,334 qONE Tokens
Key Takeaways HYLQ Strategy Corp has made a strategic investment in qLABS, purchasing over 18 million qONE tokens…

WLFI Crypto Surges Toward $0.12 as Whale Purchase Precedes Trump-Linked Forum
Key Takeaways Whale accumulation has spurred a rally in WLFI crypto prices, reaching towards $0.12 ahead of a…

Cathie Wood Reverses Path with $6.9 Million Purchase in Coinbase Stock – Is ARK Strategizing a Rebound?
Key Takeaways ARK Invest acquires 41,453 shares of Coinbase, showing renewed interest post recent divestment. This acquisition by…

Crypto Lobby Establishes Working Group to Advocate for Prediction Market Regulatory Clarity
Key Takeaways The Digital Chamber announced the Prediction Markets Working Group to promote federal oversight of prediction markets.…

Peter Thiel Discreetly Withdraws from Ethereum Treasury Venture ETHZilla – A Cautionary Note for the DAT Model?
Key Takeaways Peter Thiel and Founders Fund have completely exited their position in ETHZilla. Thiel’s withdrawal raises questions…

Coin Center Advocates Protecting Crypto Developer Liability
Key Takeaways Coin Center is actively lobbying the U.S. Senate to safeguard crypto developer liability protections. The ongoing…

$150B in US Tax Refunds Could Catalyze Fresh Crypto Inflows, Historical Trends Indicate
Key Takeaways The IRS anticipates distributing approximately $150 billion in tax refunds to U.S. consumers by the end…

Oracle Error Leads DeFi Lender Moonwell to $1.8 Million in Bad Debt
Key Takeaways A critical oracle pricing glitch caused Moonwell to incur nearly $1.8 million in bad debt. The…

Crypto Price Prediction Today 18 February – XRP, Solana, Dogecoin
Key Takeaways XRP targets a $5 move, driven by its role as an alternative to SWIFT for cross-border…

China’s DeepSeek AI Predicts the Price of XRP, PEPE, and Shiba Inu By the End of 2026
Key Takeaways DeepSeek AI suggests significant potential price increases for XRP, PEPE, and Shiba Inu by 2026. XRP…

XRP Battles Key Support Amid Grayscale Sentiment Surge
Key Takeaways XRP has experienced a 29% price drop recently, creating a tense atmosphere among traders eyeing key…
Crypto Price Prediction Today 18 February – XRP, Bitcoin, Ethereum
Key Takeaways XRP’s potential as a replacement for SWIFT is bolstered by regulatory approvals, potentially driving its price…
XRP Price Prediction: XRP is Outpacing Solana and Targeting Binance Coin Next – Should You Invest Now?
Key Takeaways XRP Ledger has moved into the sixth place by tokenized real-world asset value, surpassing Solana and…
New AI Predicts the Price of XRP, Dogecoin, and Solana By 2026
Key Takeaways ChatGPT anticipates significant price increases for XRP, Dogecoin, and Solana by the end of 2026. XRP…
Arthur Hayes Shares Two Scenarios for Bitcoin Price, Calling for a Major Crypto Rally
Key Takeaways Arthur Hayes predicts a significant crypto rally fueled by a $572 billion liquidity injection from the…
Bitcoin Price Prediction: Abu Dhabi Gov Funds Buy $1 Billion in BTC – What Do They Know?
Key Takeaways Abu Dhabi has revealed a $1 billion stake in Bitcoin through major ETF investments, signaling strong…
Bitcoin’s Divergence From Nasdaq Signals Dollar Liquidity Risk, Says Arthur Hayes
Key Takeaways Arthur Hayes highlights a concerning divergence between Bitcoin and the Nasdaq, pointing to a potential dollar…