this is insane and super crazy if the vulnerability was 5years old
Here is what we know so far about the @balancer exploit:
1. The vulnerability has likely existed for nearly 5 years since the protocol's launch, evading detection despite audits
2. The root cause seems to stem from from improper authorization and callback handling during pool initialization
This enabled attackers to deploy malicious contracts that manipulate vault calls and perform unauthorized swaps or balance drains across interconnected pools
3. There are speculations that the attackers are the same group behind the KyberSwap hack
this is based on similarities in transaction log styles
4. Most stolen assets are derivative tokens (e.g., LSTs like osETH, wstETH + sts) giving some protocol teams to intervene by blacklisting addresses, pausing redemptions, or taking emergency actions before the hacker converts them to ETH (or the native asset)
The hacker did seem to manage to convert STS to S across various wallets (not just the one wallet circulated around)
5. @berachain validator intentionally halted the network and executed a successful emergency hard fork to recover ~$12M in user funds from their BEX
decentralization â
user protection â
im sure no one was complaining there
6. the ramifications of this incident are deep
it's a "trust collapse" in DeFi. even a battle-tested protocol from 2020 can suffer near-total TVL loss, potentially deterring serious capital and setting back adoption
7. let's not forget that CertiK had given Balancer a security score of 86 prior to the hack
This raises questions about the effectiveness of audits
8. The wallets were funded by tornado cash

1,19Â k
4
Le contenu de cette page est fourni par des tiers. Sauf indication contraire, OKX nâest pas lâauteur du ou des articles citĂ©s et ne revendique aucun droit dâauteur sur le contenu. Le contenu est fourni Ă titre dâinformation uniquement et ne reprĂ©sente pas les opinions dâOKX. Il ne sâagit pas dâune approbation de quelque nature que ce soit et ne doit pas ĂȘtre considĂ©rĂ© comme un conseil en investissement ou une sollicitation dâachat ou de vente dâactifs numĂ©riques. Dans la mesure oĂč lâIA gĂ©nĂ©rative est utilisĂ©e pour fournir des rĂ©sumĂ©s ou dâautres informations, ce contenu gĂ©nĂ©rĂ© par IA peut ĂȘtre inexact ou incohĂ©rent. Veuillez lire lâarticle associĂ© pour obtenir davantage de dĂ©tails et dâinformations. OKX nâest pas responsable du contenu hĂ©bergĂ© sur des sites tiers. La dĂ©tention dâactifs numĂ©riques, y compris les stablecoins et les NFT, implique un niveau de risque Ă©levĂ© et leur valeur peut considĂ©rablement fluctuer. Examinez soigneusement votre situation financiĂšre pour dĂ©terminer si le trading ou la dĂ©tention dâactifs numĂ©riques vous convient.


