Stand Up for Investors' Right to Know – Say No to Dumping Sell-Offs! [RootData Bounty Campaign]
API Download the RootData App

Security Agency: The Balancer attacker conducted an invariant attack on BPT price calculation or is the main reason for asset theft

Nov 03, 2025 22:33:07

Share to

The on-chain tracking platform BlockSec Phalcon, under the security agency BlockSec, stated on platform X that "Balancer and several of its fork projects were attacked a few hours ago, resulting in losses of over $120 million across multiple chains. This was an extremely complex attack. Preliminary analysis indicates that the root cause was the attacker's manipulation of the invariant in the BPT price calculation, distorting the BPT price calculation and allowing the attacker to profit from a single batch transaction from a specific stablecoin pool.

Taking the attack transaction on Arbitrum as an example, the batch swap operation can be broken down into three stages: 1. The attacker exchanges BPT for the underlying asset to precisely adjust the balance of one token (cbETH) to be close to the rounding boundary (amount = 9). This creates conditions for precision loss in the next step; 2. The attacker then uses a pre-constructed amount (= 8) to swap between another underlying token (wstETH) and cbETH. Due to the rounding down of token amounts during scaling, the calculated Δx slightly decreases (from 8.0.918 to 8), resulting in an underestimated Δy, which causes the invariant (D) in Curve's StableSwap model to also decrease. Since BPT price = D / total supply, the BPT price is artificially suppressed; 3. The attacker then reverses the exchange of the underlying asset back to BPT, restoring the balance while profiting from the drop in BPT price.

Related Projects

Latest News

Test 1230

链捕手

Dec 11, 2025 12:30:29

Test News 1211

链捕手

Dec 11, 2025 11:53:55

Test article 1730

ChainCatcher

Dec 10, 2025 17:31:22

Test News 1716

链捕手

Dec 10, 2025 17:16:52

Recent Fundraising

More
$7M Dec 26
$9M Dec 08
-- Sep 23

New Tokens

More
Nov 13
Nov 11
Nov 10

Latest Updates on 𝕏

More