Share this article

Hacker Drains $500K From DeFi Liquidity Provider Balancer

The sophisticated attack exploited a loophole that tricked the protocol into releasing $500,000 worth of tokens.

Updated Sep 14, 2021, 8:57 a.m. Published Jun 29, 2020, 11:12 a.m.

"We were not aware this specific type of attack was possible."

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

Decentralized finance (DeFi) liquidity provider Balancer Pool admitted early Monday morning it had fallen victim to a sophisticated hack that exploited a loophole, tricking the protocol into releasing $500,000 worth of tokens.

In a blog post, Balancer CTO Mike McDonald said the attacker had borrowed $23 million worth of WETH tokens, an ether-backed token suitable for DeFi trading, in a flash loan from dYdX. They then traded, against themselves, with Statera (STA), an investment token that uses a transfer fee model and burns 1% of its value every time it's traded.

The attacker went between WETH and STA 24 times, draining the STA liquidity pool until the balance was next to nothing. Because Balancer thought it had the same amount of STA, it released WETH that equated to the original balance, giving the attacker a larger margin for every trade completed.

As well as WETH, the attacker performed the same attack using WBTC, LINK and SNX, all against Statera tokens.

See also: Hacker Exploits Flaw in Decentralized Bitcoin Exchange Bisq to Steal $250K

The hacker's identity remains a mystery but analysts at 1inch exchange, a decentralized exchange aggregator, said the hacker had covered their tracks well: The ether used to pay transaction fees and deploy smart contracts was laundered through Tornado Cash, an Ethereum-based mixer service.

"The person behind this attack was [a] very sophisticated smart contract engineer with extensive knowledge and understanding of the leading DeFi protocols," 1inch said in its blog post on the breach.

For its part, the team behind Statera batted away accusations that the protocol had either failed or been designed intentionally for this sort of attack to take place.

"We deeply regret, apologize and sincerely extend our condolences to all the victims of this attack," Statera said in an official announcement.

The project added that it was not in a position to be able to refund the attacker's victims.

See also: DeFi Project bZx Exploited for Second Time in a Week, Loses $630K in Ether

Balancer Pool will now begin blacklisting all transfer fee tokens, including Statera, McDonald said. As well as another audit, McDonald said the team would do more research into how the hack happened and whether similar vulnerabilities exist with other listed tokens.

The attack could not have come at a worse time for Balancer, which only released its own "BAL" governance token last week.

At press time, CoinGecko data shows BAL tokens trading at the $11 mark, down about 5% in the past 24 hours.

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

Coinbase Sees Crypto Recovery Ahead as Liquidity Improves and Fed Rate Cut Odds Climb

Coinbase

The crypto exchange also took note of a so-called AI bubble that continues to go strong and a weaker U.S. dollar.

What to know:

  • Coinbase Institutional is seeing a potential December recovery in crypto, citing improving liquidity and a shift in macroeconomic conditions that could favor risk assets like bitcoin.
  • The firm's optimism is driven by rising odds of Federal Reserve rate cuts, with markets pricing in a 93% chance easing next week, and improving liquidity conditions.
  • Several recent institutional developments, including Vanguard's crypto ETF policy reversal and Bank of America's greenlighting of crypto allocations, have contributed to bitcoin's rebound from recent lows.