Summary
Here, the DAO proposes the distribution of funds recovered following the Balancer V1 exploit of August 31st, 2026.
Context: a bug was found on legacy Balancer V1 pools allowing them to be drained. Whitehat actors intervened during the event, and the main exploiter was identified as a greyhat, partially returning funds to the Balancer DAO Multisig on Ethereum Mainnet. Although, many copycat transactions remain annonymous with proceedings going into mixers.
As of the latest report, $1,393,694.67 worth of tokens were drained from v1 pools (priced at the time of the attack).
This proposal follows the framework established in BIP-892 (distribution of rescued funds from the v2 November 2025 attacks) and details the methodology for reimbursing LPs of the affected V1 pools.
Background
Balancer V1 (deployed 2020) is legacy, immutable, unmaintained code with no pause mechanism. On August 31, 2026 at 02:23 UTC (block 25872249), an attacker began exploiting a fixed-point rounding deficiency in the single-sided join flow (joinswapPoolAmountOut / calcSingleInGivenPoolOut): with a low-decimals token’s reserves compressed to dust via flash-loan-funded swaps, the required input amount truncated to a negligible value while minting full pool tokens, which were then exited proportionally against the pool’s reserves.
Following the initial exploit, the technique was replicated by copycat actors across the long tail of remaining V1 pools. In parallel, whitehat actors front-ran copycat extractions and intercepted at-risk funds ahead of malicious actors.
The interception race was won through block-builder payments. At the time of writing, approximately $169K was consumed by builder payments at execution time. Recovery to the DAO therefore came both from grey/whitehat returns and from subsequent returns by other parties, as detailed in Section 2.
1. Whitehat Bounty
The Safe Harbor Agreement (BIP-726) does not cover legacy v1 pools, but provides the 10% bouty terms for whitehat interventions.
In this case, funds were retained by the whitehats and no KYC was applied.
Bounties were calculated as 10% of the returned by each eligible party. Since all recoveries in this incident were consolidated and returned in ETH (see Section 2), payment-in-kind is equivalent to payment in ETH, preserving the consistency, volatility-neutrality, and accounting simplicity.
2. Recovered Funds
All recoveries were returned in ETH to the Balancer DAO Multisig on Ethereum Mainnet (0x10A19e7eE7d7F8a52822f6817de8ea18204F2e4f).
| # | Date (UTC) | Returning party | Amount (ETH) | Return Tx |
|---|---|---|---|---|
| 1 | Sep 8, 2026 16:35 | Main exploiter [greyhat] | 120.000000 | 0xfe490a9f… |
| 2 | Sep 10, 2026 19:12 | Anon Whitehat #1 | 52.061000 | 0x83fb01e5… |
| 3 | Sep 10, 2026 20:15 | Anon Whitehat #2 | 100.219105 | 0x81abd68e… |
| 4 | Sep 10, 2026 20:22 | Anon Whitehat #3 | 15.948000 | 0x13e45df4… |
| 5 | Sep 16, 2026 09:08 | Ultrasound.money [blockbuilder] | 8.173606 | 0xc3a08bbf… |
| TOTAL | 296.401711 |
3. LP Reimbursement
3.1 Methodology
Distribution of recovered funds to affected users shall be:
- Non-socialized across pools — Each affected V1 pool is allocated a share of the net recovered ETH proportional to that pool’s share of the total USD value drained (at attack-time prices, per the incident dataset). No cross-subsidization beyond the pro-rata coverage ratio, which applies uniformly to all pools.
- Pro-rata by pool token holdings — Within each pool, distribution is proportional to each holder’s share of the pool’s supply at the attack snapshot block.
- Paid in ETH — Since recoveries were returned consolidated in ETH, LPs receive ETH equivalent to their pro-rata share of their pool’s allocation.
Eligibility shall be determined by V1 pool token holdings at block 25872248 (Ethereum Mainnet) — the last block before the first exploit transaction (block 25872249, Aug 31, 2026 02:23:23 UTC). A single snapshot block covers all 120 affected pools, since it precedes the entire exploit window including copycat activity.
3.2 Claim Mechanism
A claiming mechanism will be developed to facilitate distribution to eligible LPs, mirroring the BIP-892 framework:
- Acceptance Required: Claimants provide digital proof of consent to Balancer’s terms, releasing Balancer Labs, Balancer DAO, Balancer Foundation, and affiliated parties and service providers from liabilities related to the exploit.
- Smart Contract & Multi-Sig Handling: Case-by-case coordination available via admin@balancer.finance.
- Claim Period: The claim window will match [BIP-923] so it doesn’t interfere with the protocol winddown proposal. Given the dormant state of v1, this should be enough for affected users to find their claim. At its conclusion, unclaimed assets are declared dormant and their disposition reassessed via a separate governance proposal.
4. Specification
If this proposal passes, the following actions will be executed:
- Publish claim data for community review: per-pool allocation table, pool-token holder lists at block 25872248, per-address claim amounts, and verification scripts.
- Deploy the claiming mechanism: the Balancer Foundation and Service Providers are mandated to develop and deploy the claim framework.
- Open the claim window for eligible LPs per Section 3.
- Monitor and support claims, including case-by-case handling of contract accounts (admin@balancer.finance).
- Dormant asset management: after the claim window, propose allocation of unclaimed assets via a separate governance proposal.
References
- BIP-726: Adopt the SEAL Safe Harbor Agreement
- BIP-892: Distribution of Rescued Funds from Balancer v2 November 3rd 2025 Attacks
- [BIP-923] Next Phase Decision for Rescued Funds Distribution from Balancer v2 November 2025 Attacks
- SEAL Safe Harbor Agreement (PDF)
- Terms of Use · Risk Disclosures
- Return transactions: Tx 1 · Tx 2 · Tx 3 · Tx 4 · Tx 5