Balancer V1 Pool Hit by Calculation Error Exploit Worth $234K
A security breach at Balancer's V1 pool resulted in the loss of approximately $234,000 from a BPool.
The attack exploited a calculation error in the `joinswapPoolAmountOut` function, which calculates the amount of tokens required to mint pool tokens. By manipulating the function, the attacker was able to drain assets with minimal input.
The exploit targeted a vulnerability stemming from a lack of validation checks and minimum thresholds in the pool's logic. The attacker used public swaps to reduce the pool's WBTC balance to near zero, then manipulated the `joinswapPoolAmountOut` function to calculate the required WBTC input as roughly one satoshi.
The attack was funded through flash loans sourced from multiple DeFi platforms, including Spark, Aave, Morpho, and Uniswap V3. This highlights the importance of robust security measures in DeFi protocols, especially those handling significant liquidity.