Balancer V1 Pool Exploited for $234K Through Calculation Error
A vulnerability in Balancer's V1 BPool protocol allowed an attacker to drain nearly $234,000 from the pool. The exploit targeted a calculation error in the `joinswapPoolAmountOut` function, which calculates the amount of tokens required to mint pool tokens.
The attacker repeatedly used public swaps to reduce the WBTC balance in the pool to near zero. They then manipulated the `joinswapPoolAmountOut` function to compute the required WBTC input as roughly one satoshi, allowing them to mint BPT (Balancer Pool Tokens) with a negligible deposit.
The attack was funded through flash loans sourced from multiple DeFi platforms, including Spark, Aave, Morpho, and Uniswap V3. The use of flash loans enabled the attacker to execute the exploit without significant upfront capital.