💥 Gate Square Event: #PostToWinTRUST 💥
Post original content on Gate Square related to TRUST or the CandyDrop campaign for a chance to share 13,333 TRUST in rewards!
📅 Event Period: Nov 6, 2025 – Nov 16, 2025, 16:00 (UTC)
📌 Related Campaign:
CandyDrop 👉 https://www.gate.com/announcements/article/47990
📌 How to Participate:
1️⃣ Post original content related to TRUST or the CandyDrop event.
2️⃣ Content must be at least 80 words.
3️⃣ Add the hashtag #PostToWinTRUST
4️⃣ Include a screenshot showing your CandyDrop participation.
🏆 Rewards (Total: 13,333 TRUST)
🥇 1st Prize (1 winner): 3,833
Uncovering the $116 million Balancer attack: pinpointing the "rounding function" vulnerability, a fresh warning for DeFi security
Decentralized Protocol Balancer Confirms that a recent incident, which resulted in the theft of over $116 million in assets, was fundamentally caused by a logical error involving rounding in the protocol’s internal “upscale” function. The attack affected multiple networks including Ethereum, Arbitrum, Base, and Polygon, leading to significant losses of assets such as WETH, osETH, and wstETH.
Although the impacted StakeWise protocol has successfully recovered approximately $19 million worth of osETH, security teams have immediately paused affected liquidity pools and are tracking all suspicious transactions. This highlights the urgency for cross-chain DeFi governance layers to respond swiftly to security threats.
In-Depth Analysis of the Technical Root of Balancer’s Loss
$116M stolen: From EVM Logic Flaws to Multi-Chain Arbitrage
The attack on Balancer on November 3, 2025, exemplifies a typical smart contract precision issue leading to disaster. According to the initial report from the project team, the core vulnerability lies in the rounding logic within the “upscale” function used during token swaps.
In DeFi protocols, precise mathematical calculations are critical in token pools. The attacker exploited how the code handles non-integer scaling factors, carefully constructing transactions to systematically manipulate pool balances. This allowed them to drain liquidity across multiple networks. The stealthiness of this attack stems from the attacker’s ability to covertly transfer assets within the protocol’s vaults before the large-scale value transfer was exposed.
The total stolen assets amount to approximately $116.6 million, with the heaviest losses including 6,587 WETH, 6,851 osETH, and 4,260 wstETH. This indicates that the attacker targeted complex staked tokens with yield-enhancement features, highlighting the compounded risks when integrating LST protocols with DEXs.
Collaborative Defense: How the Ecosystem Responds to Fund Losses
Notably, following the security incident, the DeFi ecosystem demonstrated rapid risk mitigation:
Recovery Roadmap and Industry Lessons
Asset Tracking and Final Report: Transparency as a Trust Builder
Balancer’s team is working closely with security experts to audit the incident and verify asset losses. The project commits to releasing a final report after validating all affected contracts and transactions, clarifying total losses and recovery status.
For DeFi developers and builders, this incident serves as a wake-up call:
Until all assets are fully reconciled, users are advised to avoid interacting with the affected contracts and to stay tuned to official channels for updates, to guard against phishing or scams.
Conclusion
The massive loss caused by a “rounding error” in Balancer underscores the high precision demands in DeFi code. While the $116 million loss is painful, the swift response—asset freezing, partial recovery—demonstrates growing resilience in DeFi infrastructure. Moving forward, the community should focus on how Balancer can improve audits and upgrade its core AMM logic to ensure robustness, which is essential for maintaining its market leadership.