# \[BIP-892\] Distribution of Rescued Funds from Balancer v2 November 3rd 2025 Attacks

**URL:** <https://forum.balancer.fi/t/bip-892-distribution-of-rescued-funds-from-balancer-v2-november-3rd-2025-attacks/6883>\
**Category:** General Proposal\
**Created:** [November 27, 2025, 1:27pm UTC](https://forum.balancer.fi/t/bip-892-distribution-of-rescued-funds-from-balancer-v2-november-3rd-2025-attacks/6883 "2025-11-27T13:27:25Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Xeonus](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.balancer.fi/xeonus/32/3621_2.png) [@Xeonus](https://forum.balancer.fi/u/Xeonus)\
**Post date:** [November 27, 2025, 1:27pm UTC](https://forum.balancer.fi/t/bip-892-distribution-of-rescued-funds-from-balancer-v2-november-3rd-2025-attacks/6883/1 "2025-11-27T13:27:25Z")

</div>

Author(s): @Xeonus, @0xDanko

## PR with Payloads

> <https://github.com/BalancerMaxis/multisig-ops/pull/2557>
>
> Mainnet (BIP-XXX-whitehat-bounty-mainnet.json)
> 
> Recipient: Bitfinding (snf) …- 0xc3C7ccE1962B7a744847933CC3abD50b67ff5402
> From: DAO Multisig 0x10A19e7eE7d7F8a52822f6817de8ea18204F2e4f
> 
> | Token | Refunded Amount | 10% Bounty | Wei Value |
> |--------|------------------------|------------------------|----------------------|
> | WETH | 136.000911728966261966 | 13.6000911728966261966 | 13600091172896626196 |
> | wstETH | 10.956795326731383128 | 1.0956795326731383128 | 1095679532673138312 |
> | weETH | 6.616522876650740387 | 0.6616522876650740387 | 661652287665074038 |
> | rETH | 6.225119272163926053 | 0.6225119272163926053 | 622511927216392605 |
> | osETH | 105.208208417525687999 | 10.5208208417525687999 | 10520820841752568799 |
> 
> Base (BIP-XXX-whitehat-bounty-base.json)
> 
> Recipient: Holy (MEV Bot) - 0xcab1e5cc8bda570d29d5e321ec15cde5b9f6e555
> From: DAO Multisig 0xC40DCFB13651e64C8551007aa57F9260827B6462
> 
> | Token | Refunded Amount | 10% Bounty | Wei Value |
> |-------|-----------------------|-----------------------|---------------------|
> | weETH | 0.062139952624026243 | 0.0062139952624026243 | 6213995262402624 |
> | WETH | 16.969986964242690963 | 1.6969986964242690963 | 1696998696424269096 |
> | rETH | 24.240356565725627712 | 2.4240356565725627712 | 2424035656572562771 |
> 
> Polygon (BIP-XXX-whitehat-bounty-polygon.json)
> 
> Recipient: dk - 0xCdef7f1e13b86CC1f9C0cF57bDC9A7db501CB680
> From: DAO Multisig 0xeE071f4B516F69a1603dA393CdE8e76C40E5Be85
> 
> | Token | Refunded Amount | 10% Bounty | Wei Value |
> |----------|------------------------------|-----------------------------|--------------------------|
> | MaticX | 6,802,355.942322614165675949 | 680,235.5942322614165675949 | 680235594232261416567594 |
> | WPOL | 8,007,431.872105445738945508 | 800,743.1872105445738945508 | 800743187210544573894550 |
> | stMatic | 72,412.221124654841037109 | 7,241.2221124654841037109 | 7241222112465484103710 |
> | TruMATIC | 2,865,690.0 | 286,569.0 | 286569000000000000000000 |
> 
> Excluded: StakeWise, Unknown, Whitehat2, and empty "Who" entries in internal GSheet

## Summary

Here, the DAO proposes a framework for distributing funds rescued during the Balancer v2 exploit in early November 2025.

Whitehat actors and internal rescue operations successfully recovered approximately $8M in user funds across multiple networks (with an additional ~$19.7M in osETH/osGNO handled separately by StakeWise). Users understand the inherent risks of DeFi and the community’s ongoing efforts to manage them through tools like the [Terms of Use,](https://balancer.fi/terms-of-use) [Risk Reminders](https://balancer.fi/risks) and adoption of the SEAL Safe Harbor Agreement ([BIP-726](https://forum.balancer.fi/t/bip-726-adopt-the-seal-safe-harbor-agreement/6087)). This proposal builds on that foundation by detailing the next steps in the risk management strategy including: (1) implementation of the previously approved whitehat reimbursement policy under[[BIP-726] Safe Harbor Agreement](https://forum.balancer.fi/t/bip-726-adopt-the-seal-safe-harbor-agreement/6087); (2) the breakdown of the funds recovered by network and whitehat contributors, and (3) the methodology for reimbursing LPs affected by the theft.

## Background

In early November 2025, Balancer v2 was actively attacked across multiple networks. In accordance with [[BIP-726]: Adopt the SEAL Safe Harbor Agreement](https://forum.balancer.fi/t/bip-726-adopt-the-seal-safe-harbor-agreement/6087), whitehat actors intervened to rescue funds at risk and qualified for “Predetermined rewards for successful whitehats that protect protocol funds”.

The Safe Harbor Agreement, adopted by Balancer DAO, provides clear terms for whitehat interventions:

- Bounty: 10% of recovered funds
- Cap: $1,000,000 USD per rescue operation
- Retainable: False (funds must be returned to DAO recovery address; bounty paid separately)
- Identity: Full legal name required
- Compliance: KYC and global sanctions verification required

## 1. Whitehat Reimbursement Policy

### 1.1 Bounty Payment Denomination

Proposal: All whitehat bounties shall be paid in the same token as returned funds, calculated as 10% of recovered tokens as approved in BIP-726 and described in the section 2.2.

Rationale:

- The Safe Harbor Agreement specifies “Retainable: False,” meaning whitehats cannot retain bounties directly from recovered assets. This necessitates a separate bounty payment.
- Payment-in-kind (PIK) as recovered assets provides:
  - Clarity and consistency across different token types
  - No price volatility between bounty calculation and payment
  - Simplified accounting for the DAO and recipients
  - Operational efficiency for multi-network settlements

### 1.2 Eligibility Requirements

Per BIP-726 and the Safe Harbor Agreement, whitehats must complete:

1. Identity Verification: Provide full legal name
2. KYC: Complete Know Your Customer verification
3. Sanctions Screening: Clear OFAC, UK, and EU sanctions lists

The Foundation has cleared the compliance requirements for this proposal, and the identity of the whitehats will remain anonymous and preserved.

### 1.3 Mandate to Dispute Procedures

In the event of a dispute between Balancer DAO and the whitehat, the Treasury Council will be mandated to represent the DAO’s interests in such resolutions via the Balancer Foundation, according to the Safe Harbor Agreement.

## 2. External Whitehat Recoveries

The following table details all external whitehat recoveries, organized by whitehat and network.

### 2.1 Summary by Whitehat

| Whitehat | Network | Total Recovered (USD at the time of recovery) |
| --- | --- | --- |
| Anon #1 | Polygon | $2,681,321 |
| Bitfinding | Ethereum Mainnet | $963,832 |
| Anon #2 | Base | $161,274 |
| Unknown #1 | Arbitrum | $46,933 |
| Unknown #2 | Arbitrum | $1,862 |
| Unknown #3 | Arbitrum | $230 |
| TOTAL | | $3,855,452 |

Note: StakeWise rescued osETH (Ethereum) and osGNO (Gnosis) but will handle redistribution to affected users directly via their own mechanism. These funds are excluded from this proposal.

Note 2: Whitehat rescuers on Arbitrum have waived their bounty by not identifying themselves and/or refusing to KYC.

### 2.2 Detailed Recovery Breakdown and bounty targets

#### Anon #1 — Polygon

| Token | Amount | Bounty | Total (Net) | Refund Tx |
| --- | --- | --- | --- | --- |
| WPOL | 8,007,431.9 | 800,743.19 | 7,206,688.71 | [0x52f19146…](https://polygonscan.com/tx/0x52f19146219d61642d55a5ceb52e1d1ca6ddca4e4065ae18d3e3874a113dc7b7) |
| MaticX | 6,802,355.9 | 680,235.59 | 6,122,120.31 | [0x2c844233…](https://polygonscan.com/tx/0x2c84423345cd0308656ad59cfb9b5dae6bf5fc04f12ec10af60468221c5ab944) |
| TruMATIC | 2,865,691 | 286,569 | 2,579,122.26 | [0x3daae091…](https://polygonscan.com/tx/0x3daae091b7565200d12b6c7a506e362a35e1bb7a50eb2312efd75a4ce1d0e83a) |
| stMatic | 72,412.2 | 7,241.22 | 65,170.98 | [0xe3137b85…](https://polygonscan.com/tx/0xe3137b8565a63743efb549b6eaadfc9e7b1fba4ba85916ebb89734711cf11f01) |

Bounty shall be paid back to `0xCdef7f1e13b86CC1f9C0cF57bDC9A7db501CB680`

#### BitFinding — Ethereum Mainnet

| Token | Amount | Bounty | Total (Net) | Refund Tx |
| --- | --- | --- | --- | --- |
| WETH | 136.000 | 13.600 | 122.400 | [0x1c20be7a…](https://etherscan.io/tx/0x1c20be7a609b53011cc569fc33d04ace7a4616de6efbf1c7bc1a72cd4f2909c9) |
| osETH | 105.208 | 10.520 | 94.688 | [0x60687df4…](https://etherscan.io/tx/0x60687df48ac95b49e3952c6bb8a5f08b6d9959b26e6f56d24319c6499fd475ce) |
| wstETH | 10.956 | 1.095 | 9.859 | [0xf6e3db8f…](https://etherscan.io/tx/0xf6e3db8ff335aa3859ad2686a339920a718a5db64390cda1295f8f84fb7f7bed) |
| weETH | 6.616 | 0.661 | 5.955 | [0x4936c50c…](https://etherscan.io/tx/0x4936c50c99bc07d1023b095bd7158ee1100117b75c66b0a7523984e4618756a4) |
| rETH | 6.225 | 0.622 | 5.603 | [0x18fccc83…](https://etherscan.io/tx/0x18fccc83a078ab75ba671789a8d895a8342693e2e6905c45ab4b0be4ec0e973b) |

Bounty shall be paid back to `0xc3C7ccE1962B7a744847933CC3abD50b67ff5402 `

#### Anon #2 — Base

| Token | Amount | Bounty | Total (Net) | Refund Tx |
| --- | --- | --- | --- | --- |
| rETH | 24.240 | 2.424 | 21.816 | [0xb88c2119…](https://basescan.org/tx/0xb88c2119c3527cd47a2c37fbf6cbe93490598ebe2e416313603fd71f468ef263) |
| WETH | 16.969 | 1.696 | 15.273 | [0x33ea6ee0…](https://basescan.org/tx/0x33ea6ee04c0a2cc7ee04f9177cbefb8a17271ab5ca5f789d31253aca31e3bbaa) |
| weETH | 0.062 | 0.006 | 0.056 | [0x836a01a8…](https://basescan.org/tx/0x836a01a8a76cfb02b50d8a8d0a99426e1407d7317c436158c07b0d31baf5e43e) |

Bounty shall be paid back to `0xcab1e5cc8bda570d29d5e321ec15cde5b9f6e555 `

#### Unknown — Arbitrum (waived bounty)

| Token | Amount | Bounty | Total (Net) | Refund Tx |
| --- | --- | --- | --- | --- |
| USDX | 117.3 | n/a | 117.3 | [0x284055aa…](https://arbiscan.io/tx/0x284055aa9a1a2f919ec7212c2f4a7f77dc8277e5f257b645e43b70c869c18c74) |
| sUSDX | 105.9 | n/a | 105.9 | [0xa025ecae…](https://arbiscan.io/tx/0xa025ecae0da00db7433662b17ffc0e10cbdbf9ee53a5b59fbecff6a4d609a97c) |
| ETH | 13.7 | n/a | 13.7 | [0x6cf102dd…](https://arbiscan.io/tx/0x6cf102dd26b3923d0bf49c0d664d21394bc4f1a39bd9e8309247dddfd73e9418) |
| rETH | 0.2 | n/a | 0.2 | [0x6c5cdbbf…](https://arbiscan.io/tx/0x6c5cdbbf421a6b313b5fc9ecdf0b177e3f8f1c70022749e2b096fc462c070061) |
| WETH | 0.2 | n/a | 0.2 | [0xce75a26a…](https://arbiscan.io/tx/0xce75a26aa77cf4dc749efde44621496a5e67d112614438c2aeffe9769f23161c) |
| ETH | 0.1 | n/a | 0.1 | [0xd84ed71a…](https://arbiscan.io/tx/0xd84ed71a14d65e89045d461e8ec4a787a60304dd7672136bfcc7ccb1b94fd715) |
| ezETH | 0.1 | n/a | 0.1 | [0xab5cdc56…](https://arbiscan.io/tx/0xab5cdc56ca4c36d4cb937cc917d0cac8ff37157b3b619c5305d17d567220e6d7) |
| weETH | ~0.0 | n/a | ~0.0 | [0xf9b4d356…](https://arbiscan.io/tx/0xf9b4d356cc0d6c4e3bb3b7b77cce923ed139a848705ac74c161526f551e97012) |
| wstETH | ~0.0 | n/a | ~0.0 | [0x370efc5b…](https://arbiscan.io/tx/0x370efc5b6486f23b90027406f6ce0f87ad995264a1689d2b373ab18cb551444e) |

## 3. Internal Rescue Operation (Certora — Metastable Pools)

In coordination with the Certora team, Balancer DAO executed an internal whitehat rescue operation targeting metastable pools [CSPv5] (including rETH and other correlated-asset pools) that were at risk but not yet exploited by external actors. This rescue effort is not covered under the SEAL Safe Harbor Agreement and its terms.

### 3.1 Treatment of Internal Rescue

Proposal: The internal Certora rescue operation is not eligible for the 10% Safe Harbor bounty for the following reasons:

1. Certora’s involvement was under an existing service relationship with Balancer
2. The Safe Harbor Agreement is designed to incentivize external actors to protect the protocol; internal coordinated responses fall outside this scope

### 3.2 Metastable Pool Recovery Details

The following tokens were rescued via the internal Certora-coordinated operation and returned to Balancer DAO multi-sig addresses:

#### Ethereum (0x10A19e7eE7d7F8a52822f6817de8ea18204F2e4f)

| Token | Amount |
| --- | --- |
| WETH | 510.37 |
| rETH | 320.12 |
| wstETH | 141.39 |
| StaFi rETH | 0.80 |
| Subtotal | |

#### Optimism (0x043f9687842771b3dF8852c1E9801DCAeED3f6bc)

| Token | Amount |
| --- | --- |
| rETH | 64.88 |
| WETH | 66.06 |
| wstETH | 1.86 |
| Subtotal | |

#### Arbitrum (0xaF23DC5983230E9eEAf93280e312e57539D098D0)

| Token | Amount |
| --- | --- |
| wstETH | 3.53 |
| WETH | 4.04 |
| Subtotal | |

#### Internal Rescue Total

| Network | Total Recovered (USD at the time of recovery) |
| --- | --- |
| Ethereum | $3,590,712.58 |
| Optimism | $488,327.39 |
| Arbitrum | $28,525.58 |
| TOTAL | $4,107,565.55 |

These funds are held in the respective DAO multi-sig addresses as internal balances in the Balancer v2 vault on the corresponding network. These will be claimed and distributed to affected metastable pool LPs according to the methodology outlined in Section 4.

Internal balances can be verified [here](https://dune.com/queries/6198411).

## 4. LP Reimbursement

### 4.1 Methodology

Proposal: Distribution of rescued funds to affected users shall be:

1. Non-socialized — Each affected pool’s rescued funds are distributed only to LPs of that specific pool and network
2. Pro-rata by BPT holdings — Distribution proportional to each holder’s share of the pool’s BPT at the snapshot block
3. Payment-in-Kind — LPs receive the same tokens that were rescued (e.g., WETH, wstETH, WPOL, etc.)

### 4.2 Snapshot Blocks

#### 4.2.1 External White Hat Rescues

Distribution eligibility for external white hat rescued funds shall be determined by BPT holdings at the following blocks (last block before first exploit tx on each network):

| Network | Snapshot Block |
| --- | --- |
| Ethereum Mainnet | 23717626 |
| Base | 37683373 |
| Polygon | 78525618 |
| Arbitrum | 396293450 |

#### 4.2.2 Internal Rescue (Metastable Pools)

Distribution eligibility for internally rescued metastable pool funds shall be determined by BPT holdings at the following blocks, per pool:

Ethereum Mainnet

| Pool ID | Snapshot Block |
| --- | --- |
| 0x1e19cf2d73a72ef1332c882f20534b6519be0276000200000000000000000112 | 23785042 |
| 0x32296969ef14eb0c6d29669c550d4a0449130230000200000000000000000080 | 23785044 |
| 0x851523a36690bf267bbfec389c823072d82921a90002000000000000000001ed | 23785052 |
| 0xb08885e6026bab4333a80024ec25a1a3e1ff2b8a000200000000000000000445 | 23785057 |

Optimism

| Pool ID | Snapshot Block |
| --- | --- |
| 0x4fd63966879300cafafbb35d157dc5229278ed2300020000000000000000002b | 143687339 |
| 0x7b50775383d3d6f0215a8f290f2c9e2eebbeceb200020000000000000000008b | 143687377 |

Arbitrum

| Pool ID | Snapshot Block |
| --- | --- |
| 0x36bf227d6bac96e2ab1ebb5492ecec69c691943f000200000000000000000316 | 399567435 |

### 4.3 Net Distribution

The amount available for LP distribution is:

Net Distribution = Rescued Funds − Whitehat Bounties

For each pool, the net tokens (after deducting the 10% bounty in-kind) will be distributed to BPT holders.  
Note, that this will not apply to rescued funds from the internal white-hat operation as described in 4.2.2, meaning the full amount of recovered funds shall be returned to affected LPs from those pools.

### 4.4 Claim Mechanism

A claiming mechanism will be developed to facilitate the distribution of rescued funds to eligible LPs. The technical implementation details—including the specific smart contract architecture, claim interface, and operational procedures—will be finalized and communicated to the community prior to launch.

Key Principles:

- Acceptance Required: Claimants will be required to provide digital proof of consent to Balancer’s terms and conditions, explicitly agreeing to release Balancer Labs, Balancer DAO, Balancer Foundation and any affiliated parties and service providers from liabilities related to the exploit or any disputes.
- Smart Contract & Multi-Sig Handling: Smart contract accounts and multi-sig wallets may require case-by-case coordination. Affected parties can contact [admin@balancer.finance](mailto:admin@balancer.finance) for guidance.
- Claim Period: A reasonable claim window will be established. At the conclusion of this period, unclaimed assets will be declared dormant and their disposition may be reassessed by the community via a separate governance proposal.

## 5. Specification

If this proposal passes, the following actions will be executed:

1. **Execute White Hat Bounty Payments:** Distribute bounties to KYC-verified white hats as specified in Section 2.2, paid in-kind (10% of recovered tokens) to their designated addresses.
2. **Publish Claim Data for Community Review:** Release complete snapshot data including:
  - Per-pool BPT holder lists at specified snapshot blocks
  - Token allocation amounts per eligible address
  - Data verification scripts for community audit

3. **Deploy Claiming Mechanism:** The Balancer Foundation and Service Providers are mandated to develop and deploy the claim framework for affected LPs
4. **Execute LP Distributions:** Open the claim window for eligible LPs to retrieve their rescued funds according to the methodology in Section 4.
5. **Monitor and Support Claims:** Provide ongoing assistance to claimants, particularly for smart contract accounts and multi-sig wallets requiring case-by-case coordination (contact: [admin@balancer.finance](mailto:admin@balancer.finance)).
6. **Dormant Asset Management:** At the conclusion of the 180-day claim window, propose new allocation for unclaimed dormant assets via separate governance proposal.

* * *

## References

- [BIP-726: Adopt the SEAL Safe Harbor Agreement](https://forum.balancer.fi/t/bip-726-adopt-the-seal-safe-harbor-agreement/6087)
- [SEAL Safe Harbor Agreement (PDF)](https://github.com/security-alliance/safe-harbor/blob/main/documents/agreement.pdf)
- [Balancer DAO Accountability Guidelines](https://forum.balancer.fi/)
- [Terms of Use](https://balancer.fi/terms-of-use)
- [Risks Disclosures](https://balancer.fi/risks)

* * *

Edits:

- assign BIP ID and reformat as BIP
- add payload file for white hat repayments
- add white hat bounty payment information
- adjust section 4.3 to clarify external vs internal white hat token distributions
- adjust wording on proposal execution flow in section 5

---

<div class="post-metadata">

**Author:** ![crypto\_bull](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.balancer.fi/crypto_bull/32/3709_2.png) [@crypto\_bull](https://forum.balancer.fi/u/crypto_bull)\
**Post date:** [November 27, 2025, 7:13pm UTC](https://forum.balancer.fi/t/bip-892-distribution-of-rescued-funds-from-balancer-v2-november-3rd-2025-attacks/6883/2 "2025-11-27T19:13:23Z")

</div>

What is with bpt-sss ??? On Beets???

---

<div class="post-metadata">

**Author:** ![gosuto](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.balancer.fi/gosuto/32/2014_2.png) [@gosuto](https://forum.balancer.fi/u/gosuto)\
**Post date:** [November 28, 2025, 7:51am UTC](https://forum.balancer.fi/t/bip-892-distribution-of-rescued-funds-from-balancer-v2-november-3rd-2025-attacks/6883/3 "2025-11-28T07:51:31Z")

</div>

Personally I do not see any benefit to holding the recovered assets hostage until users “claim” them back. Once it is known how much of it belongs to whom, the assets can simply be airdropped directly back to their original owners.

First, acceptance of terms and conditions is already covered by the dapp, which already contains releases, in addition to the releases included in the adopted Safe Harbor Agreement. Why go through all that bureaucracy a third time? Is there really a scenario in which all these aforementioned acceptances of releases is not enough, but a third one is?

Secondly, calling assets “dormant” because someone did not “claim” back _their own assets_ within an arbitrary timeframe goes against the ethos of our ecosystem in my opinion. In no circumstance should it be up to the DAO to take ownership of any users’ assets, also not when they happened to be offline for 180 days.

Not to mention the overhead (and delay!) of building a smart contract system and GUI to facilitate all this. An active airdrop is by far the simplest and most effective way of distributing these assets, and prevents users from missing out on the fact that their assets were recovered.

What is there to say against an immediate airdrop?

* * *

 ![Screenshot 2025-11-28 at 08.05.04](https://canada1.discourse-cdn.com/flex027/uploads/balancer/original/2X/6/630c0fef99d43657e7025152a3dc778a04774358.png)

> […] you expressly waive and release Balancer from any and all liability, claims, causes of action, responsibility or damages arising from or in any way related to your use of the Site, the Application or the Smart Contracts.

ref: [https://balancer.fi/terms-of-use](https://balancer.fi/terms-of-use)

> The Protocol Community collectively and each Protocol Community Member individually, hereby, to the extent permitted at law, irrevocably, unconditionally, and completely exculpates, releases, acquits and forever discharges the Protocol Community and each Protocol Community Member from, and hereby irrevocably, unconditionally, and completely waives and relinquishes, every Claim, that any Protocol Community or Protocol Community Member may have had in the past, may now have, or may have in the future against the Protocol Community or any Protocol Community Member, relating to or arising out of this Agreement or any Eligible Funds Rescue attempted or effected in connection herewith or any of the other matters contemplated hereby.

ref: [safe-harbor/documents/agreement.pdf at main · security-alliance/safe-harbor · GitHub](https://github.com/security-alliance/safe-harbor/blob/main/documents/agreement.pdf)

---

<div class="post-metadata">

**Author:** ![0xDanko](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.balancer.fi/0xdanko/32/1376_2.png) [@0xDanko](https://forum.balancer.fi/u/0xDanko)\
**Post date:** [November 28, 2025, 9:26pm UTC](https://forum.balancer.fi/t/bip-892-distribution-of-rescued-funds-from-balancer-v2-november-3rd-2025-attacks/6883/4 "2025-11-28T21:26:01Z")

</div>

> [@gosuto](#):
>
> What is there to say against an immediate airdrop?

_Disclosure: this is not part of the proposal, just personal opinion, but we want to signal this to the community for consideration._

Afaik, claiming mechanics are pretty standard and shouldn’t cause too much of a burden to Balancer’s technical teams.

When drafting this RFC, my thought was there’s a good chance that a big chunk of these funds will never be claimed. Being the affected pool are so old, it could very well be that there’s a lot of dead liquidity in here, especially in the meta stable pools recovered.

Once this claim window is over (180 days) and we have clear numbers, the community could propose to governance that the dormant funds are socialized between all the affected wallets, hence making a higher number of victims whole (i.e. holding Treasury assets as collateral). Considering a basic Pareto rule, a more significant number of wallets will carry a lesser portion of the total affected funds. It’s a valid approach to be considered and could potentially reach hundreds (or thousands) of people.

However this is not under scope of this proposal, and I believe this discussion is premature, that’s why I’m against simply airdropping funds and shutting down the debate forever.

As burdensome as the technicalities might be, and the resources needed to be spent to put this together, I think they might be well worth it given the number of users impacted.

---

<div class="post-metadata">

**Author:** ![anarchychains](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.balancer.fi/anarchychains/32/3711_2.png) [@anarchychains](https://forum.balancer.fi/u/anarchychains)\
**Post date:** [November 29, 2025, 10:23am UTC](https://forum.balancer.fi/t/bip-892-distribution-of-rescued-funds-from-balancer-v2-november-3rd-2025-attacks/6883/5 "2025-11-29T10:23:34Z")

</div>

KYC for whitehats?  
What is the message you are saying for the future, if necessary help from whitehats again?

---

<div class="post-metadata">

**Author:** ![Bip](https://avatars.discourse-cdn.com/v4/letter/b/e0b2c6/32.png) [@Bip](https://forum.balancer.fi/u/Bip)\
**Post date:** [November 30, 2025, 8:43am UTC](https://forum.balancer.fi/t/bip-892-distribution-of-rescued-funds-from-balancer-v2-november-3rd-2025-attacks/6883/6 "2025-11-30T08:43:24Z")

</div>

These funds were \*stolen\*, This should not be taken as an opportunity to see which wallets are active and which aren’t. That I need to deliver proof hella over complicates something that could be easily solved by distributing the funds back into the pool as they are meant to be with every single pool. If I was more involved into this community and was able to vote I would definitely vote against this. Which reminds me that I was banned from the Balancer discord for warning people over a scam and sharing the scammers account information so even if I wanted to be more involved I can’t.

They kicked me out like I was nothing and seemingly to protect scammers which instantly flocked to me when I joined the server there by tricking me.

This will guaranteed result in living wallets not get the money back that is rightfully theirs.

Any time any info is shared to the public there are bound to be a lot of people that either will not come across the message or won’t understand how to claim their assets back in this case.

Give me back my money and I’m out of here.

---

<div class="post-metadata">

**Author:** ![Bip](https://avatars.discourse-cdn.com/v4/letter/b/e0b2c6/32.png) [@Bip](https://forum.balancer.fi/u/Bip)\
**Post date:** [November 30, 2025, 8:49am UTC](https://forum.balancer.fi/t/bip-892-distribution-of-rescued-funds-from-balancer-v2-november-3rd-2025-attacks/6883/7 "2025-11-30T08:49:34Z")

</div>

The message to me sounds like ‘don’t bother unless you’re willing to give up countless personal details that will put you at risk.’. A person that stole money back from criminals is at extra risk if the personal info leaks. And i wouldn’t trust them either, especially after being banned from their discord over warning people of a scam.

Even if they were trustworthy there is an inherent risk to sharing personal information.

---

<div class="post-metadata">

**Author:** ![0xDanko](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.balancer.fi/0xdanko/32/1376_2.png) [@0xDanko](https://forum.balancer.fi/u/0xDanko)\
**Post date:** [November 30, 2025, 2:00pm UTC](https://forum.balancer.fi/t/bip-892-distribution-of-rescued-funds-from-balancer-v2-november-3rd-2025-attacks/6883/8 "2025-11-30T14:00:14Z")

</div>

There’s a clear misunderstanding here that claiming the assets and singing the acceptance would require KYC and personal information, which is certainly not the case.

---

<div class="post-metadata">

**Author:** ![Bip](https://avatars.discourse-cdn.com/v4/letter/b/e0b2c6/32.png) [@Bip](https://forum.balancer.fi/u/Bip)\
**Post date:** [November 30, 2025, 2:41pm UTC](https://forum.balancer.fi/t/bip-892-distribution-of-rescued-funds-from-balancer-v2-november-3rd-2025-attacks/6883/9 "2025-11-30T14:41:40Z")

</div>

That’s true, I meant for the white hat hackers requiring KYC to get the bounty they deserve.

---

<div class="post-metadata">

**Author:** ![0xDanko](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.balancer.fi/0xdanko/32/1376_2.png) [@0xDanko](https://forum.balancer.fi/u/0xDanko)\
**Post date:** [December 2, 2025, 6:06pm UTC](https://forum.balancer.fi/t/bip-892-distribution-of-rescued-funds-from-balancer-v2-november-3rd-2025-attacks/6883/10 "2025-12-02T18:06:18Z")

</div>

Update: all identified whitehats have cleared compliance checks via Balancer Foundation. We will edit the proposal accordingly.

---

<div class="post-metadata">

**Author:** ![0x\_wee](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.balancer.fi/0x_wee/32/3716_2.png) [@0x\_wee](https://forum.balancer.fi/u/0x_wee)\
**Post date:** [December 4, 2025, 12:57pm UTC](https://forum.balancer.fi/t/bip-892-distribution-of-rescued-funds-from-balancer-v2-november-3rd-2025-attacks/6883/11 "2025-12-04T12:57:50Z")

</div>

One point I want to flag for consideration regarding the snapshot and claim design:

At the time of the exploit, a significant portion of affected BPT was held by intermediary smart contracts (e.g. Aura gauges / vaults), rather than end-user EOAs. From a user perspective, many LPs are economically exposed via these wrappers, even though the BPT itself sits at a vault address.

It would be great to have clarity (or explicit guarantees) that:

1. the snapshot accurately captures these vault-held BPT positions, and

2. the claim mechanism does not require vault contracts to manually claim on behalf of users, unless absolutely necessary.

Ideally, the recovery flow should allow fair attribution to underlying LPs without forcing coordination or trust assumptions at the wrapper-protocol level.

Speaking as an LP who was affected while having BPT staked via Aura, my personal preference would be a flow where I can first withdraw my BPT from Aura and then independently claim based on my BPT balance, rather than having to rely on a third-party vault or wrapper protocol to coordinate claims on my behalf.

Appreciate the work that’s gone into the proposal so far — just wanted to raise this for consideration early to help avoid potential UX or distribution issues later in the process.

---

<div class="post-metadata">

**Author:** ![maxyz.xyz](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.balancer.fi/maxyz.xyz/32/3806_2.png) [@maxyz.xyz](https://forum.balancer.fi/u/maxyz.xyz)\
**Post date:** [December 5, 2025, 4:33pm UTC](https://forum.balancer.fi/t/bip-892-distribution-of-rescued-funds-from-balancer-v2-november-3rd-2025-attacks/6883/12 "2025-12-05T16:33:34Z")

</div>

Following the same methodology as for the [assets recovered by StakeWise](https://forum.stakewise.io/t/proposal-approve-distribution-of-recovered-funds-to-lps-affected-by-balancer-v2-exploit/1996), we have generated a list of all users for which assets were recovered by the whitehats.

The complete CSV can be found here: [balancer-upscale-exploit-shares/output/shares\_whitehats\_filtered.csv at main · maxyz-xyz/balancer-upscale-exploit-shares · GitHub](https://github.com/maxyz-xyz/balancer-upscale-exploit-shares/blob/main/output/shares_whitehats_filtered.csv).

Users for which assets have been recovered that are worth less that 1 $USD are currently filtered out. The `token` column is the token that has been recovered, `user_amount_recovered` is how many of those tokens will be returned to the user. Note that `user_amount_recovered_usd` is based on the USD price of the asset _on the day of the hack_.

> [@0x\_wee](#):
>
> It would be great to have clarity (or explicit guarantees) that:
> 
> 1. the snapshot accurately captures these vault-held BPT positions, and

We considered the following positions and aggregated them accordingly:

- regular balance of the Balancer Pool Token (BPT)
- stakes in the corresponding Balancer gauge
- stakes in the corresponding Aura gauge
- deposits in the corresponding Beefy vault

Extensive double checks were performed on the total supply of the BPT onchain at the time of the hack and the sum of user snapshots. For a more detailed description of the calculations, please see the repo’s readme and/or source code: [GitHub - maxyz-xyz/balancer-upscale-exploit-shares](https://github.com/maxyz-xyz/balancer-upscale-exploit-shares)

We encourage all users to verify their data on the CSV if they were a liquidity provider (directly or indirectly) for the following pools ([ref](https://github.com/maxyz-xyz/balancer-upscale-exploit-shares/blob/main/input/recovered_whitehats.csv)):

| Pool ID | Symbol | Chain |
| --- | --- | --- |
| `0x05ff47afada98a98982113758878f9a8b9fdda0a000000000000000000000645` | weETH/rETH | Ethereum |
| `0x58aadfb1afac0ad7fca1148f3cde6aedf5236b6d00000000000000000000067f` | rsETH/WETH | Ethereum |
| `0x93d199263632a4ef4bb438f1feb99e57b4b5f0bd0000000000000000000005c2` | wstETH-WETH-BPT | Ethereum |
| `0xdacf5fa19b1f720111609043ac67a9818262850c000000000000000000000635` | osETH/wETH-BPT | Ethereum |
| `0x8159462d255c1d24915cb51ec361f700174cd99400000000000000000000075d` | B-stMATIC-Stable | Polygon POS |
| `0x951d84e358dd8ad6b3ae6220981bcfc4baf95c84000000000000000000000d62` | TruMATIC-WMATIC | Polygon POS |
| `0xcd78a20c597e367a4e478a2411ceb790604d7c8f000000000000000000000c22` | maticX-WMATIC-BPT | Polygon POS |
| `0xab99a3e856deb448ed99713dfce62f937e2d4d74000000000000000000000118` | weETH/wETH | Base |
| `0xc771c1a5905420daec317b154eb13e4198ba97d0000000000000000000000023` | rETH-WETH-BPT | Base |

---

<div class="post-metadata">

**Author:** ![maxyz.xyz](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.balancer.fi/maxyz.xyz/32/3806_2.png) [@maxyz.xyz](https://forum.balancer.fi/u/maxyz.xyz)\
**Post date:** [December 9, 2025, 6:34am UTC](https://forum.balancer.fi/t/bip-892-distribution-of-rescued-funds-from-balancer-v2-november-3rd-2025-attacks/6883/14 "2025-12-09T06:34:23Z")

</div>

We now also added the recovered assets on Arbitrum One: [feat: add arb1 whitehat recovered assets (#2) · maxyz-xyz/balancer-upscale-exploit-shares@0d2d1c0 · GitHub](https://github.com/maxyz-xyz/balancer-upscale-exploit-shares/commit/0d2d1c03be6aff4edc1208dc806714965225bd80)

| Pool ID | Symbol | Chain |
| --- | --- | --- |
| `0x3fd4954a851ead144c2ff72b1f5a38ea5976bd54000000000000000000000480` | ankrETH/wstETH-BPT | Arbitrum |
| `0x4a2f6ae7f3e5d715689530873ec35593dc28951b000000000000000000000481` | wstETH/rETH/cbETH | Arbitrum |
| `0x7b54c44fbe6db6d97fd22b8756f89c0af16202cc00000000000000000000053c` | ETHx/wstETH | Arbitrum |
| `0x90e6cb5249f5e1572afbf8a96d8a1ca6acffd73900000000000000000000055c` | rsETH/wETH | Arbitrum |
| `0xb3047330c1cb5eb1a3670fabfb99bdc106d631eb0000000000000000000005e4` | sUSDX/USDX | Arbitrum |
| `0xb61371ab661b1acec81c699854d2f911070c059e000000000000000000000516` | ezETH/wstETH | Arbitrum |
| `0xc2598280bfea1fe18dfcabd21c7165c40c6859d30000000000000000000004f3` | wstETH/sfrxETH | Arbitrum |
| `0xd0ec47c54ca5e20aaae4616c25c825c7f48d40690000000000000000000004ef` | rETH/wETH BPT | Arbitrum |
| `0xf13758d6edd1937dcb3f4fe75889b579d400299a000000000000000000000595` | weETH/wETH | Arbitrum |

---

<div class="post-metadata">

**Author:** ![zekraken](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.balancer.fi/zekraken/32/823_2.png) [@zekraken](https://forum.balancer.fi/u/zekraken)\
**Post date:** [December 12, 2025, 12:52pm UTC](https://forum.balancer.fi/t/bip-892-distribution-of-rescued-funds-from-balancer-v2-november-3rd-2025-attacks/6883/15 "2025-12-12T12:52:34Z")

</div>

[https://snapshot.box/#/s:balancer.eth/proposal/0x79d4abf2838eead8f153f409ee200ebafa83a1499a7b5c586497d68562209657](https://snapshot.box/#/s:balancer.eth/proposal/0x79d4abf2838eead8f153f409ee200ebafa83a1499a7b5c586497d68562209657)

---

<div class="post-metadata">

**Author:** ![arxcjk36](https://avatars.discourse-cdn.com/v4/letter/a/e9bcb4/32.png) [@arxcjk36](https://forum.balancer.fi/u/arxcjk36)\
**Post date:** [December 14, 2025, 4:50am UTC](https://forum.balancer.fi/t/bip-892-distribution-of-rescued-funds-from-balancer-v2-november-3rd-2025-attacks/6883/16 "2025-12-14T04:50:51Z")

</div>

Why is there no recovery for wstETH-rETH-sfrxETH-BPT pool on Ethereum chain: 0x42ed016f826165c2e5976fe5bc3df540c5ad0af700000000000000000000058b ?

This pool is exploited and has a share of wstETH and rETH.

---

<div class="post-metadata">

**Author:** ![m2k115768](https://avatars.discourse-cdn.com/v4/letter/m/ccd318/32.png) [@m2k115768](https://forum.balancer.fi/u/m2k115768)\
**Post date:** [December 14, 2025, 1:54pm UTC](https://forum.balancer.fi/t/bip-892-distribution-of-rescued-funds-from-balancer-v2-november-3rd-2025-attacks/6883/17 "2025-12-14T13:54:09Z")

</div>

Same question as as arxcjk36 asked, but in relation to said pool in Optimism Chain: 0x9236cd1Cb2df141E842F825B95f51742CC930814

This pool is exploited and has a share of wstETH and rETH

---

<div class="post-metadata">

**Author:** ![maxyz.xyz](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.balancer.fi/maxyz.xyz/32/3806_2.png) [@maxyz.xyz](https://forum.balancer.fi/u/maxyz.xyz)\
**Post date:** [December 15, 2025, 5:25am UTC](https://forum.balancer.fi/t/bip-892-distribution-of-rescued-funds-from-balancer-v2-november-3rd-2025-attacks/6883/18 "2025-12-15T05:25:03Z")

</div>

For every recovery transaction so far (whether it be StakeWise, whitehats or the internal rescue) it is possible to deduce to which exact pool the recovered assets belong. Neither for pool `0x42ed016f826165c2e5976fe5bc3df540c5ad0af700000000000000000000058b` (Ethereum) nor `0x5f8893506ddc4c271837187d14a9c87964a074dc000000000000000000000106` (Optimism, which is the `want` pool of the Beefy vault you mention @m2k115768) have we seen any recovery transactions unfortunately.

---

<div class="post-metadata">

**Author:** ![maxyz.xyz](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.balancer.fi/maxyz.xyz/32/3806_2.png) [@maxyz.xyz](https://forum.balancer.fi/u/maxyz.xyz)\
**Post date:** [December 15, 2025, 7:44am UTC](https://forum.balancer.fi/t/bip-892-distribution-of-rescued-funds-from-balancer-v2-november-3rd-2025-attacks/6883/19 "2025-12-15T07:44:06Z")

</div>

The recoveries for the meta stable pools have also been published and can be found at [balancer-upscale-exploit-shares/output/shares\_meta\_filtered.csv at main · maxyz-xyz/balancer-upscale-exploit-shares · GitHub](https://github.com/maxyz-xyz/balancer-upscale-exploit-shares/blob/main/output/shares_meta_filtered.csv)

| Pool ID | Symbol | Chain |
| --- | --- | --- |
| `0x1e19cf2d73a72ef1332c882f20534b6519be0276000200000000000000000112` | B-rETH-STABLE | Ethereum |
| `0x32296969ef14eb0c6d29669c550d4a0449130230000200000000000000000080` | B-stETH-STABLE | Ethereum |
| `0x851523a36690bf267bbfec389c823072d82921a90002000000000000000001ed` | B-wstETH-STABLE-C | Ethereum |
| `0xb08885e6026bab4333a80024ec25a1a3e1ff2b8a000200000000000000000445` | B-staFiETH-WETH-Stable | Ethereum |
| `0x4fd63966879300cafafbb35d157dc5229278ed2300020000000000000000002b` | BPT-rETH-ETH | Optimism |
| `0x7b50775383d3d6f0215a8f290f2c9e2eebbeceb200020000000000000000008b` | BPT-WSTETH-WETH | Optimism |
| `0x36bf227d6bac96e2ab1ebb5492ecec69c691943f000200000000000000000316` | B-wstETH-WETH-Stable | Arbitrum |

---

<div class="post-metadata">

**Author:** ![dunactblur](https://avatars.discourse-cdn.com/v4/letter/d/ee59a6/32.png) [@dunactblur](https://forum.balancer.fi/u/dunactblur)\
**Post date:** [January 6, 2026, 3:02am UTC](https://forum.balancer.fi/t/bip-892-distribution-of-rescued-funds-from-balancer-v2-november-3rd-2025-attacks/6883/20 "2026-01-06T03:02:35Z")

</div>

to get full refund, we need to do full KYC?

---

<div class="post-metadata">

**Author:** ![Xeonus](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.balancer.fi/xeonus/32/3621_2.png) [@Xeonus](https://forum.balancer.fi/u/Xeonus)\
**Post date:** [January 6, 2026, 8:16am UTC](https://forum.balancer.fi/t/bip-892-distribution-of-rescued-funds-from-balancer-v2-november-3rd-2025-attacks/6883/21 "2026-01-06T08:16:01Z")

</div>

Hi there, no. The KYC requirement was for the white hats only. Affected users will be able to claim their rescued tokens with their wallet (likely after signing a message, technical details still tbd).

[Next page](https://forum.balancer.fi/t/bip-892-distribution-of-rescued-funds-from-balancer-v2-november-3rd-2025-attacks/6883.md?page=2)
