In a recent turn of events, Balancer, the Ethereum automated market maker and decentralised finance (DeFi) protocol, found itself ensnared in an exploit that resulted in a staggering loss of nearly $900,000. The unsettling incident came to light through a statement posted on X (formerly Twitter) on 27 August. This breach occurred mere days after the protocol had publicly disclosed a vulnerability that had cast a shadow over multiple pools within the ecosystem.
A revelation from blockchain security authority Meier Dolev shed light on the alleged attacker behind the exploit. This expert in the realm of blockchain unveiled an Ethereum address purportedly linked to the assailant. The aftermath of the breach showcased a calculated sequence of events, with the said address encountering two transfers of Dai stablecoin. These transactions amounted to $636,812 and $257,527 respectively, orchestrating an intricate dance of funds that culminated in an accumulated balance soaring beyond $893,978.
Did Exposing the Vulnerability Led to the Exploit?
On 22 August, Balancer took a decisive step by unveiling a critical vulnerability https://forum.balancer.fi/t/vulnerability-found-in-some-pools/5102?u=endymionjkb that had infiltrated its boosted pools. A clarion call was issued to users, urging them to initiate the withdrawal of funds from their liquidity provider accounts. Concurrently, the platform proactively pressed the pause button on affected pools, a strategic move aimed at curbing potential ramifications.
This action was prompted by the understanding that a diverse array of assets, spanning Ethereum, Polygon, Arbitrum, Optimism, Avalanche, Gnosis, Fantom, and zkEVM, were held hostage by this vulnerability's clutches.
The vulnerability's exposure was initially limited in scale, with a mere 1.4% of Balancer's complete asset inventory hanging in the balance on the day of discovery. This calculated to a staggering sum exceeding $5 million — a substantial testament to the platform's considerable asset traction.
As events unfolded, the date shifted to 24 August, highlighting that even at this juncture, a notable exposure persisted. Specifically, the value at risk tallied to at least $2.8 million, equivalent to 0.42% of Balancer's comprehensive total value locked (TVL).
As of 25 August, over 99.7% of liquidity initially deemed vulnerable is now safe but 0.08% of TVL remains at risk.
In the aftermath of Balancer's initial revelation regarding the vulnerability, a noteworthy trend emerged as users swiftly orchestrated the withdrawal of substantial capital. This response, however, sparked inquiries among discerning market participants. The query looms: Why did the protocol opt to bring the issue into the limelight from the outset?
While a comprehensive post-mortem report detailing the intricacies of the vulnerability is still pending from the Balancer team, insights have emerged from Web3 audit firm Hacken. The firm has intimated that the fundamental trigger behind the vulnerability has been successfully pinpointed and that the Balancer team is actively engaged in remediation efforts.