Blog
Nov 13, 2025
Balancer V2 Exploit Explained: Inside the Smart Contract Rounding Error That Cost $120M
Balancer V2’s Composable Stable Pools, modeled after Curve’s StableSwap, use math-driven invariants to minimize slippage in like-valued token swaps. However, a persistent rounding-down behavior in the _upscale function—introduced in 2021—created a precision loss that attackers exploited in low-liquidity states, draining over $120 million. The incident underscores the need for continuous, holistic security partnerships and evolving audit frameworks in the DeFi ecosystem, rather than isolated, one-off reviews.
Source: HackerNoon →