Balancer Pool Hacked for $234K via Familiar Rounding-Error Exploit
A Balancer V1-style liquidity pool was hacked for $234,000 on August 31, according to Slowmist. This is the same category of bug that drained $116 million from Balancer's V2 pools last November.
The attacker compressed WBTC reserves down to dust, minting full BPT for a rounded-down 1-satoshi input. Balancer Labs shut down as a company in March 2026 after a similar bug drained $116 million.
According to Slowmist's technical breakdown, the attacker targeted the pool's joinswapPoolAmountOut function, which lets a caller specify how many BPT they want to receive while the contract works backward to calculate the required input. The reverse calculation, handled by calcSingleInGivenPoolOut, uses 18-decimal fixed-point math.