Balancer V1 Pool Drained $234K via Calculation Error Exploit
A security breach in Balancer's V1 BPool resulted in a loss of approximately $234,000. The exploit was detailed by blockchain security firm SlowMist and targeted a calculation error in the pool's logic.
The attacker manipulated the `joinswapPoolAmountOut` function to compute the required WBTC input as roughly one satoshi, allowing them to mint 4,408.8 BPT tokens with a negligible deposit. These tokens were then used to withdraw DPI, USDC, WETH, and WBTC from the pool.
The attack was funded through flash loans sourced from multiple DeFi platforms, including Spark, Aave, Morpho, and Uniswap V3. Flash loans allow users to borrow large sums without collateral, provided the loan is repaid within the same transaction.