SlowMist alert indicates that an precision calculation vulnerability exploited Balancer's legacy V1 pools: the attacker used nested flash loans to compress WBTC reserves down to just 1 satoshi, enabling the minting of large amounts of BPT and ultimately draining the pool’s assets, resulting in losses of approximately $234,000.
(Prior context: Historical Hacking Incidents of the Established DeFi Protocol Balancer: Six Security Breaches in Five Years, Resulting in Losses of Over $100 Million)
(Background: Balancer releases official report: $125 million lost due to rounding function bug)
Hackers have set their sights on Balancer again—this time targeting the nearly forgotten V1 liquidity pool, not the V2 version that suffered losses of hundreds of millions of dollars last year. Chain security firm SlowMist issued an alert, reporting that a Balancer V1 liquidity pool composed of DPI, USDC, WETH, and WBTC was exploited via a precision calculation vulnerability, resulting in losses of approximately $234,000.
🚨SlowMist TI Alert🚨
💸 @Balancer Loss: ~234k USD
🔍 Root Cause: Balancer V1 BPool `joinswapPoolAmountOut` allows the caller to specify BPT output, while `calcSingleInGivenPoolOut` reverse-computes the input using 18-decimal fixed-point math. After the attacker compressed WBTC reserves to dust…
— SlowMist (@SlowMist_Team) August 31, 2026
Vulnerability principle: 1 satoshi of WBTC calculated using the discard method
According to SlowMist’s technical analysis, the issue lies in the joinswapPoolAmountOut function of the Balancer V1 pool. This function allows users to specify the amount of BPT (pool share tokens) they wish to receive, after which the calcSingleInGivenPoolOut function uses 18-decimal fixed-point mathematics to retroactively calculate how much WBTC must be deposited.
The attacker first executed a series of public swaps to compress the WBTC reserve in the liquidity pool to nearly zero. After draining the reserve, under truncated arithmetic in the reverse calculation, it was determined that only 1 satoshi (0.00000001 WBTC) was needed to join the pool—yet the attacker received 4,408.8 BPT, equivalent to what a normal participant would receive.
SlowMist noted that Balancer V1 never implemented three safeguards for deposited funds: a minimum effective deposit amount, a minimum pool balance, or relative error validation. The MIN_BALANCE threshold only takes effect during the pool's bind and rebind phases, with no oversight during normal pool operations.
Complete Record of Nested Flash Loan Attack
After acquiring a large amount of BPT, the attacker proportionally exchanged their shares back for the original assets locked in the pool—DPI, USDC, WETH, and WBTC—effectively swapping nearly zero-cost WBTC for the entire pool’s real assets. The funding enabling this entire operation came from a nested flash loan structure layered across three lending and trading protocols: Spark (Aave ecosystem), Morpho, and Uniswap V3. The attacker used funds borrowed from these protocols to repeatedly buy and sell, compressing the WBTC reserve within the pool, all without using any of their own capital.
SlowMist’s published data shows that the attacker’s wallet address is 0x338c7ec9befbb451d66fd8a468c32184f5689a41, the attack contract is 0x9caa8d0e44b22f50057d2f4ce0d1446529e11be3, and the locked liquidity pool contract is 0x2257aaac34bcb27900291f7b84ee2565a6cbac57, with on-chain data confirming it as Balancer V1’s “DPI/USDC/ETH/WBTC 25/25/25/25” pool.
Balancer's Unpatched Old Contract: Company Dissolved, Risks Remain
A loss of $234,000 is two orders of magnitude smaller than the hundreds-of-millions-of-dollars hack last November on Balancer’s V2 Composable Stable Pools, but the context of this incident is more intriguing.
Earlier today, Dòng Qū reported that Balancer Labs co-founder Fernando Martinelli announced in March the dissolution of the development company, acknowledging that the company had become a liability rather than an asset to the protocol, with future operations to be taken over by the Balancer Foundation and DAO; at the time, TVL had declined from a peak of $3.3 billion to $158 million.
The company has dissolved, but the smart contract can’t be shut down. Old, outdated, low-volume contracts like V1 liquidity pools continue to lock up real money and remain prime targets for attackers. With the development team gone, no one has taken responsibility for maintaining these “zombie contracts”—this is unlikely to be the last time Balancer bleeds money due to legacy versions, nor the only instance in DeFi of an abandoned contract still holding locked assets.
📍Related Reports📍
Less than 24 hours! Balancer suffers another flash loan attack, this time losing COMP (DeFi)



