Incident case file
Sign in to watchBalancer V1 Legacy BPool Rounding Exploit — $234K
Incident date Aug 29, 2026Last updated Sep 24, 2026
0 views
ContainedEthereumRounding error / precision exploitCluster: BALANCER-ETH-2026-08
Estimated loss
$234K
Affected users
Number of affected users is not confirmed
Group joining is coming soon.
Investigation
70%
Facts and investigation
Ledger
Attacker
0x338c7ec9befbb451d66fd8a468c32184f5689a41
Funds moved to
Extracted via repeated compression of WBTC pool reserves using flash-loaned capital from Spark, Aave, Morpho and Uniswap V3; no laundering path publicly documented.
Linked
Attacker: 0x338c7ec9befbb451d66fd8a468c32184f5689a41. Attack contract: 0x9caa8d0e44b22f50057d2f4ce0d1446529e11be3. Vulnerable contract: 0x2257aaac34bcb27900291f7b84ee2565a6cbac57.
Chronology
1 beatOn August 30-31, 2026, an attacker exploited a rounding flaw in the legacy Balancer V1 BPool's joinswapPoolAmountOut function on a DPI/USDC/WETH/WBTC pool. By repeatedly compressing the pool's WBTC reserves toward near-zero through a sequence of flash-loaned swaps (drawing on Spark, Aave, Morpho and Uniswap V3), the attacker was able to input roughly 1 satoshi of WBTC and mint 4,408.8 BPT tokens, extracting a total of $234,000. The contract is immutable and cannot be patched. A whitehat bounty deadline of September 8 passed with no funds returned.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)