Balancer, a long-standing decentralized finance (DeFi) platform on Ethereum, is currently being scrutinized after a suspected exploit resulted in a loss of $70.9 million. The stolen liquid staked Ether (ETH) tokens were quickly moved to a newly generated wallet. Blockchain records indicate that the decentralized exchange and automated market
The breach, which happened on Nov. 3, 2025, is Balancer’s third significant security incident since 2020 and stands as one of the most substantial DeFi hacks this year. The attackers emptied several liquidity pools in
This is not the protocol’s first encounter with a security breach. In September 2025, Balancer experienced a domain name system (DNS) attack on its main website, redirecting visitors to a phishing page that stole $238,000 in crypto assets. The previous month, the protocol revealed a $1 million stablecoin exploit after discovering a “critical vulnerability” in its liquidity pools. These repeated incidents have sparked debate over the security of DeFi systems, especially since Balancer reportedly manages over $750 million in total value locked, according to
Following the exploit, Balancer’s governance token BAL fell by more than 5%, highlighting investor anxiety. Experts have advised users to steer clear of Balancer pools until the root cause of the exploit is identified. Security analysts are examining whether the breach was due to a vulnerability in the platform’s swap mechanism or in the way it manages pool balances.
Balancer’s track record includes a 2020 exploit involving deflationary tokens, which resulted in $500,000 in losses, and a 2023 incident in “boosted pools” that caused $900,000 in damages. This most recent attack far exceeds previous breaches and highlights the persistent security challenges DeFi protocols encounter when safeguarding intricate smart contracts.
With the investigation ongoing, the DeFi sector remains uneasy. The absence of clear communication from Balancer’s team has intensified concerns that further vulnerabilities may be present. Meanwhile, the attacker’s wallet is still active on