# \[BIP-904\] Balancer V3 Hypernative Pause Module Enablement

**URL:** <https://forum.balancer.fi/t/bip-904-balancer-v3-hypernative-pause-module-enablement/6932>\
**Category:** General Proposal\
**Created:** [January 6, 2026, 9:14pm UTC](https://forum.balancer.fi/t/bip-904-balancer-v3-hypernative-pause-module-enablement/6932 "2026-01-06T21:14:44Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ZenDragon](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.balancer.fi/zendragon/32/1542_2.png) [@ZenDragon](https://forum.balancer.fi/u/ZenDragon)\
**Post date:** [January 6, 2026, 9:14pm UTC](https://forum.balancer.fi/t/bip-904-balancer-v3-hypernative-pause-module-enablement/6932/1 "2026-01-06T21:14:44Z")

</div>

### Summary

Hypernative proposes for Balancer to enable a Gnosis Safe Module which we have deployed on each of Balancer V3’s networks in order to pause groups of pools based on our exploit detection logic. The logic consists of various machine learning models which are known to have detected potential exploits and prevented them in real time across the web3 space for roughly 4 years now. Furthermore the extended automated response will be able to pause groups of pools based on compromised rate providers, general exploits of pool types by leveraging their respective factories, and similarly pools with hooks in common. Reference [[BIP-775] Fund Hypernative Security Services - Renewal](https://forum.balancer.fi/t/bip-775-fund-hypernative-security-services-renewal/6329) & [[BIP-794] Enable Composable Stable Pool Pause functionality to Hypernative](https://forum.balancer.fi/t/bip-794-enable-composable-stable-pool-pause-functionality-to-hypernative/6306) for prior engagement details and configurations.

### Motivation

After the recent exploit event of Balancer V2 and our ability to make a large impact by pausing ComposableStablePool version 6, as permitted in our previous post; we think the value added to Balancer V3 is clear. We intend to be the last line of defense for any exploit vectors which the protocol can face going forward, and given the ability to pause individual pools, and the vault on each network in worst case scenarios Hypernative will have a much more comprehensive coverage window over V3 as a whole.

### Specification

The Balancer Emergency subDAO Safe on each network will install a safe Module to enable Hypernative to pause pools and vaults across respective networks. A Module is a smart contract that executes a predefined set of instructions on behalf of the Safe address, pre-approved by the Safe signers, and capable of executing these instructions automatically. In this case, the instruction is to call the pause method for each Balancer V3 pool or the V3 vault on each respective network. The module is attached via the Safe’s enableModule function.

The Safe Module is triggered by hacks or exploits detected in Balancer’s contracts by the Hypernative system as well as large deviations in rate providers outside of thresholds defined by Balancer Labs. Hypernative scans blockchains in real-time and detects hacks & exploits using its machine learning model, from the moment of a deployed malicious smart contract targeting Balancer’s contracts to executing malicious transactions.

The list of pools is automatically updated whenever the PoolCreated event is emitted on-chain, though the Balancer team can override this list if necessary.

Enabling the Safe Module will take place on these networks, with future networks to follow:

`Ethereum`, `Base`, `Optimism`, `Gnosis`, `Arbitrum`, `Avalanche`, `Plasma`, `HyperEVM`

Corresponding modules will be configured on the above chains. Later deployments will occur for X-Layer, Sonic, and any additional chains Balancer V3 deploys upon proper communication between the responsible Balancer DAO entity. Hyperactive must be given the corresponding vault and Emergency safe addresses prior to deploying the pause module on each network.

Sample Balancer Emergency subDAO Multisig payload:

_`0xA29F61256e948F3FB707b4b3B138C5cCb9EF9888`_ will interact with itself _`0xA29F61256e948F3FB707b4b3B138C5cCb9EF9888`_ and call the enableModule function passing the module address `0x7d171c6ef79a22340c6f931e8bd3833db8a8c620` on each network.

The Hypernative Safe Module is canonical and hence has the same address on all chains. This payload will be executed on all chains using the respective emergency multisigs.

| Chain | Emergency Safe Address | Module Address |
| --- | --- | --- |
| Ethereum | 0xA29F61256e948F3FB707b4b3B138C5cCb9EF9888 | [0x7d171c6ef79a22340c6f931e8bd3833db8a8c620](https://etherscan.io/address/0x7d171C6Ef79A22340C6F931E8bD3833Db8A8C620#code) |
| Plasma | 0x0d3319A8057A0C8afd87dFEEA252541A76d56Ebf | [0x7d171c6ef79a22340c6f931e8bd3833db8a8c620](https://plasmascan.to/address/0x7d171C6Ef79A22340C6F931E8bD3833Db8A8C620#code) |
| Arbitrum | 0xf404C5a0c02397f0908A3524fc5eb84e68Bbe60D | [0x7d171c6ef79a22340c6f931e8bd3833db8a8c620](https://arbiscan.io/address/0x7d171c6ef79a22340c6f931e8bd3833db8a8c620#code) |
| Gnosis | 0xd6110A7756080a4e3BCF4e7EBBCA8E8aDFBC9962 | [0x7d171c6ef79a22340c6f931e8bd3833db8a8c620](https://gnosisscan.io/address/0x7d171c6ef79a22340c6f931e8bd3833db8a8c620#code) |
| Base | 0x183C55A0dc7A7Da0f3581997e764D85Fd9E9f63a | [0x7d171c6ef79a22340c6f931e8bd3833db8a8c620](https://basescan.org/address/0x7d171c6ef79a22340c6f931e8bd3833db8a8c620#code) |
| Avalanche | 0x308f8d3536261C32c97D2f85ddc357f5cCdF33F0 | [0x7d171c6ef79a22340c6f931e8bd3833db8a8c620](https://snowscan.xyz/address/0x7d171c6ef79a22340c6f931e8bd3833db8a8c620#code) |
| HyperEVM | 0x44613a28347206F5E26C1B8Db7Dc73f450219746 | [0x7d171c6ef79a22340c6f931e8bd3833db8a8c620](https://hyperevmscan.io/address/0x7d171c6ef79a22340c6f931e8bd3833db8a8c620#code) |
| Optimism | 0xd4c87b33afcE39F1E3F4aF1ce8fFFF7241d9128B | [0x7d171c6ef79a22340c6f931e8bd3833db8a8c620](https://optimistic.etherscan.io/address/0x7d171C6Ef79A22340C6F931E8bD3833Db8A8C620#code) |

### Risk Assessment and Testing

[Module Audit Report by Certora](https://drive.google.com/file/d/1wwWkD7uEIwH8jvr1xAtqN6Y-bTLXp-Xs/view?usp=sharing)

**Audit Summary:** 4 Informational Findings Only

Before coming forward with this proposal, a rigorous test plan has been developed which will take place on the Optimism network in production.

**Key Components of the Test:**

**Test Environment:** The tests will take place on Optimism and occur in two pillars; in no specific order.

**Emergency Pausing Mechanism:** An integration via extended onchain response to pause all vaults and pools will be integrated into the Hypernative system. For the demonstration, the module contracts can be seen in the tables above which will have and the functionality to pause pools and vaults via Balancer’s multisig(s), enabling centralized oversight and triggering during emergencies.

_ **Pillar 1 - Pool factory monitoring** _

_Watchlist Creation: Together Balancer & Hypernative created a watchlist to monitor for hacks and exploits targeting Balancer’s core contracts, associated vaults, and individual pool types. This watchlist is dynamic, automatically updating with each new contract is created._

_Pool Monitoring: Hypernative’s system automatically adds new vaults to the watchlist by monitoring transactions where new pools are added. For the scope of the test Hypernative will trigger a test to pause all ReCLAMM pools on Optimism, given there is no production use of the pool type on the chain at this time; limiting any potential down side or delays in revenue generating trades. [https://balancer.fi/pools?networks=OPTIMISM&poolTypes=RECLAMM](https://balancer.fi/pools?networks=OPTIMISM&poolTypes=RECLAMM)_

_ **Pillar 2 - Rate Provider Deviation monitoring** _

_Custom Agents will be utilized to monitor rate provider contracts for large % deviations and trigger pauses of all corresponding pools exposed to that rate provider in the case of rate manipulation. This will also be tested on Optimism with a pool set which will be shared after execution in the post comments section._

_ **Outcome:** _

Summary of the testing and transaction links will be shared upon test execution in production after the permissions are granted to the modules below.

### Onchain Payloads:

On Base: DAO emergency multisig `0x183C55A0dc7A7Da0f3581997e764D85Fd9E9f63a` on Base will call `enableModule(0x7d171c6ef79a22340c6f931e8bd3833db8a8c620)` on itself

On Ethereum: DAO emergency multisig `0xA29F61256e948F3FB707b4b3B138C5cCb9EF9888` on Ethereum will call `enableModule(0x7d171c6ef79a22340c6f931e8bd3833db8a8c620)` on itself

On Avalanche: DAO emergency multisig `0x308f8d3536261C32c97D2f85ddc357f5cCdF33F0` on Polygon will call `enableModule(0x7d171c6ef79a22340c6f931e8bd3833db8a8c620)` on itself

On Arbitrum: DAO emergency multisig `0xf404C5a0c02397f0908A3524fc5eb84e68Bbe60D` on Arbitrum will call `enableModule(0x7d171c6ef79a22340c6f931e8bd3833db8a8c620)` on itself

On Optimism: DAO emergency multisig `0xd4c87b33afcE39F1E3F4aF1ce8fFFF7241d9128B` on Optimism will call `enableModule(0x7d171c6ef79a22340c6f931e8bd3833db8a8c620)` on itself

On HyperEVM: DAO emergency multisig `0x44613a28347206F5E26C1B8Db7Dc73f450219746` on zkEVM will call `enableModule(0x7d171c6ef79a22340c6f931e8bd3833db8a8c620)` on itself

On Plasma: DAO emergency multisig `0x0d3319A8057A0C8afd87dFEEA252541A76d56Ebf` on Avalanche will call `enableModule(0x7d171c6ef79a22340c6f931e8bd3833db8a8c620)` on itself

On Gnosis: DAO emergency multisig `0xd6110A7756080a4e3BCF4e7EBBCA8E8aDFBC9962` on Gnosis will call `enableModule(0x7d171c6ef79a22340c6f931e8bd3833db8a8c620)` on itself

---

<div class="post-metadata">

**Author:** ![Xeonus](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.balancer.fi/xeonus/32/3621_2.png) [@Xeonus](https://forum.balancer.fi/u/Xeonus)\
**Post date:** [January 7, 2026, 7:32am UTC](https://forum.balancer.fi/t/bip-904-balancer-v3-hypernative-pause-module-enablement/6932/2 "2026-01-07T07:32:36Z")

</div>

The Hypernative pause module infrastructure is crucial for securing the protocol. Its use in the most recent v2 exploit that saved more than 19mln in assets is a clear testament to why this is an essential piece of infrastructure for protocol security. Partners are also waiting on its go-live before deploying more capital in Balancer v3 again.  
In essence, this is a must have and I am glad the @maxyz.xyz could advise and coordinate with HN to get this shipped.

---

<div class="post-metadata">

**Author:** ![maxyz.xyz](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.balancer.fi/maxyz.xyz/32/3806_2.png) [@maxyz.xyz](https://forum.balancer.fi/u/maxyz.xyz)\
**Post date:** [January 8, 2026, 3:33pm UTC](https://forum.balancer.fi/t/bip-904-balancer-v3-hypernative-pause-module-enablement/6932/3 "2026-01-08T15:33:02Z")

</div>

[https://snapshot.org/#/s:balancer.eth/proposal/0x014b9192b3963d60a8fb123fd5ebf0c372ba73424d601753575c1c67dac0184a](https://snapshot.org/#/s:balancer.eth/proposal/0x014b9192b3963d60a8fb123fd5ebf0c372ba73424d601753575c1c67dac0184a)

---

<div class="post-metadata">

**Author:** ![ZenDragon](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.balancer.fi/zendragon/32/1542_2.png) [@ZenDragon](https://forum.balancer.fi/u/ZenDragon)\
**Post date:** [February 17, 2026, 12:15am UTC](https://forum.balancer.fi/t/bip-904-balancer-v3-hypernative-pause-module-enablement/6932/4 "2026-02-17T00:15:16Z")

</div>

To close the loop on testing portion of the proposal, Hypernative in coordination with the @maxyz.xyz , Balancer Labs, and Emergency multisig teams was able to trigger the test transactions outlined above.

1. Pool factory monitoring testing was executed on Optimism ReCLAMMs due to their lack of adoption on the chain currently. The logic is triggering an alert on any one of the pools, and upon receipt pausing all pools from that factory. The trigger event was a transfer monitor which has since been disabled.

- This event was detected: [OP Mainnet Transaction Hash: 0xeb14388968... | OP Mainnet Etherscan](https://optimistic.etherscan.io/tx/0xeb143889687bcb5cc70c1c9e30317784fcd724b47acaf61d39e7f814f0bc1ed6)
- This transaction was executed as a result: [OP Mainnet Transaction Hash: 0x82317e1eea... | OP Mainnet Etherscan](https://optimistic.etherscan.io/tx/0x82317e1eea2ce49b0b89687156ea45431d3848e4d2c1f5cefb29af1acba3d07e#eventlog)

1. Rate provider testing was done to pause all pools which met a specific deviation threshold.

- This event cannot be specified as it was based on small price deviation on an ETH pricing oracle. The monitor has since been disabled.
- This transaction was executed as a result: [OP Mainnet Transaction Hash: 0xeee2e6f0b5... | OP Mainnet Etherscan](https://optimistic.etherscan.io/tx/0xeee2e6f0b54f31e8daa3212758cce13075d3a4bd0f39f289d588f378df86ec3b#eventlog)

Testing is concluded on the V3 integration and integration has been actively deployed. This is occurring on an automated and ongoing basis.
