Balancer V1 Pool Hit For $234K In Rounding‑Error Exploit

TL;DR:
- An attacker drained approximately $234,000 from a legacy Balancer V1 liquidity pool on August 31, 2026.
- The vulnerability allowed the minting of 4,408.8 BPT tokens by depositing just a single satoshi after compressing WBTC reserves.
- The attack utilized nested flash loans from platforms such as Aave, Spark, Morpho, and Uniswap V3.
The week kicks off with Balancer V1 losing $234,000 after being breached through a mathematical calculation flaw. The anomaly in the smart contract’s deposit function was identified by security firm SlowMist.
SlowMist TI Alert
@Balancer Loss: ~234k USD
Root Cause: Balancer V1 BPool `joinswapPoolAmountOut` lets caller specify BPT output while `calcSingleInGivenPoolOut` reverse-computes input via 18-decimal fixed-point math. After attacker compressed WBTC reserves to dust…
- SlowMist (@SlowMist_Team) August 31, 2026
The affected pool held reserves denominated in DeFi Pulse Index (DPI), USD Coin (USDC), Wrapped Ethereum (WETH), and Wrapped Bitcoin (WBTC).
… Continue reading the full article at the original source below.

