- An attacker exploited a Balancer V1 pool, causing around $234,000 in losses through a rounding flaw after compressing WBTC reserves.
- It underscores the risks in other immutable Balancer V1 pools that still use the legacy joins and exits computations.
A hacker siphoned about $234,000 from a Balancer V1 liquidity pool due to an exploitation of a rounding flaw via WBTC. Cybersecurity firm SlowMist documented the vulnerability and classified the affected Balancer V1 contract as legacy code. First, the attacker would compress the pool’s supply of WBTC so that the calculations would be close to minimum. The vulnerability exploited the joinswapPoolAmountOut function, which calculates the token deposit required to mint pool tokens.
🚨SlowMist TI Alert🚨
— SlowMist (@SlowMist_Team) August 31, 2026
💸 @Balancer Loss: ~234k USD
🔍 Root Cause: Balancer V1 BPool `joinswapPoolAmountOut` lets caller specify BPT output while `calcSingleInGivenPoolOut` reverse-computes input via 18-decimal fixed-point math. After attacker compressed WBTC reserves to dust…
WBTC has an accuracy of eight decimal places, and there is a problem of accuracy issue problem when reserves become very low. SlowMist pointed out that the attacker depleted the reserves until the required deposit calculated to just one satoshi. Using this calculation, the attacker minted 4,408.8 BPT tokens for a mere one satoshi.
Flash Loans Were Useful in Reducing WBTC Balance
The hacker financed the attack through nested flash loans from Spark or Aave, Morpho, and Uniswap V3. The swaps made publicly ensured that the WBTC balance in the pool reached a dust state before the hacker implemented the vulnerable join formula. SlowMist mentioned the three missing features that would have helped mitigate the effect of this vulnerability. These include minimum effective input, minimum pool balance, and relative error validation checks. SlowMist noted that the contract uses the _MIN_BALANCE constant variable only during the bind and rebind functions.
SlowMist identified the attacker wallet as 0x338c7ec9befbb451d66fd8a468c32184f5689a41, the attack contract as 0x9caa8d0e44b22f50057d2f4ce0d1446529e11be3, and the vulnerable contract as 0x2257aaac34bcb27900291f7b84ee2565a6cbac57. The security firm also identified five transactions linked to the exploit. This event is different from the Balancer V2 hack of November 2025, which incurred losses amounting to $128 million. The former event occurred on Composable Stable Pools across six networks through different code, but both exploits favored callers through rounding calculations.
Immutable Contracts Exposed to a Broader Fork Threat
Balancer V1 is vulnerable due to the immutability of its contracts, which means that no upgrades can be applied to it. Instead, development focuses on Balancer V3. But the real threat here lies with forks of DeFi projects that have inherited from Balancer the BPool design and join/exit math. In June 2026, clones of Ocean Protocol BPool were targeted by an accounting hack attack on Polygon. According to SlowMist, there are two requirements for a vulnerability: tokens in the pool have to have fewer than 18 decimals, with WBTC and USDC being examples. Additionally, a publicly callable joinswapPoolAmountOut is required.
Highlighted Crypto News:
Kalshi Faces Fresh Legal Setback as Ninth Circuit Backs Nevada Sports-Betting Rules
