Balancer:
genuinely distinctive liquidity engineering, carrying the most severe security history in this series.
We tore apart Balancer, one of the longest-running Ethereum DEXs, credited with pioneering flexible, weighted, multi-token liquidity pools, across the same seven-category scorecard we've used throughout this series. From a genuinely distinctive V3 architecture separating token custody from pool logic, Boosted Pools that automatically route idle liquidity into Aave for lending yield, and disclosed, credible institutional backing since 2021, to what we can't set aside: on November 3, 2025, Balancer V2 was exploited for a reported $116-128 million, one of the largest DeFi hacks we've documented in this entire project, its third known security breach after earlier incidents in 2021 and 2023, in a component that had itself already been individually audited twice before the attack. We also found a fourth, smaller incident in August 2026, a severe, well-documented TVL collapse following the November hack, and a real, disclosed elimination of the platform's token-holder revenue share as of April 2026; and landed on a score the marketing page won't show you.
Our take, up front: Balancer is one of the longest-running Ethereum DEXs, credited with pioneering flexible, weighted, multi-token liquidity pools rather than the simple 50/50 pairs most AMMs use, backed since a disclosed 2021 funding round by investors including Blockchain Capital, Fenbushi Capital, and Longhash Ventures. Real, genuinely distinctive V3 architecture separating token custody and accounting from pool logic, alongside Boosted Pools that automatically route idle liquidity into Aave to earn lending interest, recalled via flash loans when a large swap needs it. Real, genuinely distinctive permissioned hooks, letting institutional, KYC-gated pools operate without compromising the core protocol's permissionless nature elsewhere. What we can't set aside: genuinely the most severe, most repeated security history of any DEX we've reviewed in this series. On November 3, 2025, Balancer V2 was exploited for a reported $116-128 million, one of the largest DeFi hacks we've documented in this entire project, via a flaw in how the protocol calculated pool prices during batch swaps within its Composable Stable Pool design, a specific component that had itself already been individually audited by two named firms in September 2022. This was Balancer's third known security breach, following earlier incidents in 2021 and 2023, and per independent data aggregation, a fourth, smaller incident occurred as recently as August 30, 2026, involving $234,000 classified as a rounding-error accounting issue. Real, genuinely severe, well-documented consequence: Balancer's TVL fell from roughly $770-776 million to $345-422 million within a single day, a 45-55% collapse. Real, honest, structural disclosure: Balancer stated it could not pause many of the affected pools because they had been live for several years and were outside the platform's pause window, a genuine governance limitation specific to legacy contracts. Real, the exploit was confirmed limited specifically to V2 Composable Stable Pools; V3 and other pool types were unaffected. Real, honest, significant, disclosed policy change: revenue-sharing to veBAL and BAL token holders was reduced from a disclosed 82.5% share to zero as of April 23, 2026, a real, material change to the platform's token economics. We weighted all of it below.
Real, genuinely extensive, historically well-documented audit program: 11 audits from four different named firms (OpenZeppelin, Trail of Bits, Certora, and ABDK). What we can't set aside: genuinely the most severe security history of any DEX we've reviewed in this series. On November 3, 2025, Balancer V2 was exploited for a reported $116-128 million, one of the largest DeFi hacks we've documented in this entire project, via a flaw in how the protocol calculated pool prices during batch swaps in its Composable Stable Pool design, a component that had itself already been individually audited by two of those same firms in September 2022. This was Balancer's third known security breach, following earlier incidents in 2021 and 2023, and per independent data aggregation, a fourth, smaller incident occurred as recently as August 30, 2026, involving $234,000 classified as a rounding-error accounting issue. Real, honest, structural disclosure: Balancer stated it could not pause many of the affected pools because they had been live for several years and were outside the pause window, a genuine governance limitation on legacy contracts. Real, the exploit was specifically confirmed limited to V2 Composable Stable Pools; V3 and other pool types were unaffected.
Pros
- 11 audits from four named firms (OpenZeppelin, Trail of Bits, Certora, ABDK)
- The November 2025 exploit was confirmed limited to V2 Composable Stable Pools specifically
Cons
- $116-128M exploit (Nov 2025), the third of four known distinct security incidents
- The exploited component had already been individually audited twice before the attack
- Legacy pools were outside the platform's own pause window during the exploit
Real, genuinely severe, well-documented TVL collapse directly tied to the November 2025 exploit: from approximately $770-776 million to $345-422 million in a single day, a 45-55% decline. Real, described historically as a battle-tested, long-running platform with a genuine multi-cycle track record, though that framing now sits alongside a real, recent, severe trust event.
Pros
- Long, multi-cycle operating history predating the 2025 collapse
Cons
- TVL fell 45-55% in a single day following the November 2025 exploit
Real, genuinely non-custodial architecture with on-chain, transparent pool contracts and community governance. Real, disclosed, credible institutional backing from its 2021 funding round, including Blockchain Capital and Fenbushi Capital. Real, honest, significant, disclosed policy change: revenue-sharing to veBAL and BAL token holders was reduced to zero as of April 23, 2026, down from a disclosed 82.5% share previously, a real, material change to the platform's token economics.
Pros
- Genuinely non-custodial; disclosed, credible institutional backing since 2021
Cons
- Token-holder revenue share cut from 82.5% to 0% as of April 2026
- Repeated security failures raise real, broader governance and oversight questions
Real, genuinely distinctive, flexible pool architecture: weighted pools supporting multiple tokens and customizable ratios, alongside stable pools and specialized launch and structured-liquidity pool types. Real, genuinely distinctive V3 Boosted Pools, automatically routing idle liquidity to Aave for lending yield while remaining available for large swaps via flash loans.
Pros
- Genuinely flexible weighted, multi-token pool architecture
- Distinctive V3 Boosted Pools with Aave-integrated lending yield
Cons
- Greater architectural flexibility has also meant a broader, more complex attack surface
Real, a genuinely capable dashboard consolidating pool analytics, live TVL, and impermanent-loss modeling, described as suited to traders, researchers, and fund managers. Real, honest, structural complexity: the platform's own flexibility, weights, invariants, and hooks-gated pools, means genuinely more configuration and risk assessment than a simple swap interface.
Pros
- Capable analytics dashboard with live TVL and impermanent-loss modeling
Cons
- Genuine complexity in weights, invariants, and hooks relative to a simple swap
Real, disclosed, functioning fee model across pool types, historically including a meaningful revenue share to token holders. Real, honest, significant recent change: that revenue share to veBAL/BAL holders was reduced to zero as of April 2026, a real, material reduction in value returned to token holders specifically, separate from the swap fees LPs still earn.
Pros
- Disclosed, functioning swap-fee model for liquidity providers
Cons
- Token-holder revenue share reduced from 82.5% to 0% as of April 2026
Real, genuinely distinctive V3 architecture separating token custody from pool logic. Real, genuinely distinctive permissioned hooks enabling institutional, KYC-gated pools without compromising the core protocol's permissionless nature. Real, honest, direct risk observation from at least one detailed source: hooks increase programmability, which increases the importance of careful auditing and threat modeling specifically.
Pros
- Distinctive V3 vault architecture; permissioned hooks for institutional pools
Cons
- Increased programmability honestly raises the stakes of getting security review right
Access only through Balancer's official app, and avoid older, legacy V2 pools specifically given their history.
Given the real, confirmed exploit history tied specifically to V2 Composable Stable Pools, prefer V3 pools where possible, and size any position with the platform's repeated incident history genuinely factored into your own risk tolerance.
Genuinely important DeFi infrastructure, carrying the most severe security record we've documented in this entire project.
We want to give Balancer real credit for what it pioneered: flexible, weighted, multi-token liquidity pools are a genuine, lasting contribution to how AMMs work, and its V3 architecture remains technically sophisticated. But we don't think it would be honest to let that historical significance soften what the evidence actually shows. Four distinct security incidents since 2021, including a $116-128 million exploit in November 2025 that hit a component already audited twice before the attack, is a genuinely different order of magnitude than a single past incident, even a serious one. One industry analyst's blunt post-hack observation, that being "audited by X" provides little real assurance on its own, reflects a real, widely shared sentiment we think is fair to take seriously here specifically. Combined with a real, disclosed elimination of the token-holder revenue share, the fair picture is a technically important but genuinely high-risk platform, deserving of real caution regardless of its pedigree.
The scorecard above is deliberately general. Whether Balancer is right for you depends heavily on which of these you already are.
The sophisticated DeFi user who specifically needs weighted, multi-token pool architecture unavailable elsewhere
This genuine architectural flexibility remains one of Balancer's real, durable strengths.
The user willing to stick specifically to newer V3 pools rather than legacy V2 Composable Stable Pools
Given the real, confirmed exploit history tied to that specific older pool type, this distinction genuinely matters.
The institutional user interested in permissioned, KYC-gated hooks-based pools specifically
This is a genuinely distinctive, real capability, best approached with full awareness of the platform's history.
Risk-averse users, or anyone prioritizing a clean, recent security record above architectural flexibility
Given the severity and recency of the platform's incident history, this is a real, honest consideration.
The scorecard covers the headline judgment calls. These four tables cover the specifics we didn't want to bury in prose; all four security incidents timelined, the "11 audits still failed" narrative explained precisely, the token-holder revenue elimination detailed, and Balancer against the full field.
Four distinct incidents, 2021-2026
| When | What happened |
|---|---|
| 2021 | An earlier, distinct security incident (first known breach) |
| 2023 | A second, distinct security incident |
| November 3, 2025 | $116-128 million exploit via a price-calculation flaw in V2 Composable Stable Pools |
| August 30, 2026 | $234,000, classified as a rounding-error token and share accounting issue |
Four distinct, confirmed incidents across five years is more than any other DEX we've reviewed in this series; even accounting for Balancer's genuinely long operating history, this is a real, well-documented pattern rather than a single isolated event.
How 11 audits still missed it
| Detail | |
|---|---|
| Total V2 audits | 11, across four named firms (OpenZeppelin, Trail of Bits, Certora, ABDK) |
| Exploited component | Composable Stable Pool |
| That component's own audit history | Individually audited by Certora and Trail of Bits in September 2022 |
| Root cause | A flaw in how pool prices were calculated during batch swaps |
| Pause capability | Many affected pools were outside the pause window due to their age |
This is a genuinely stark illustration of a lesson we've raised elsewhere in this series (with GMX and Curve): an audit reflects a snapshot in time, and even a specifically-targeted, twice-audited component can still contain an undiscovered flaw.
The token-holder revenue elimination, precisely
| Period | veBAL/BAL holder revenue share |
|---|---|
| Before April 23, 2026 | 82.5% of protocol revenue |
| After April 23, 2026 | 0% |
Our sources don't establish a direct causal link between this policy change and the November 2025 exploit; we're presenting it as a separate, real, disclosed fact about the platform's current tokenomics.
Balancer against the full field
| DEX | Confirmed security incidents |
|---|---|
| Balancer | Four (2021, 2023, 2025, 2026) |
| Curve | Three (2023, 2025, 2026) |
| Raydium / dYdX / GMX | Two each |
| Uniswap / Aerodrome / Meteora | One each |
| Orca / PancakeSwap / Hyperliquid / Injective / Osmosis | None found in our research |
Balancer now holds the most confirmed security incidents of any DEX we've reviewed across this entire series, and its November 2025 exploit alone is larger in dollar terms than several other platforms' entire combined incident histories.
We don't just want to hand you our number; we want to show you how it sits next to what other review desks and comparison sites have published. Several of our sources are incident-specific hack postmortems rather than general platform reviews, so we've excluded those from this comparison and used only genuine overall-assessment sources below. We've also excluded one source (a site at an unusual domain resembling a copycat URL) that we could not verify as a legitimate, independent publisher.
Our score lands substantially below the aggregated industry average, one of the largest gaps we've found in this series; some general "best DEX" roundup content published after the November 2025 exploit still describes Balancer in terms of its historical "battle-tested" reputation without fully re-pricing that reputation against the severity of what actually happened.
| Source | Score | Type |
|---|
Scores compiled by our editorial team from publicly available reviews as of August 2026. "Editorial estimate" means the outlet didn't publish a single numeric score, so we converted their published verdict and sentiment into a comparable 100-point figure. Verify current figures directly with each source before citing them elsewhere.
Yes, four times: incidents in 2021 and 2023, a major $116-128 million exploit on November 3, 2025, and a smaller $234,000 incident on August 30, 2026. This is the most confirmed security incidents of any DEX we've reviewed in this series.
An attacker exploited a flaw in how Balancer V2's Composable Stable Pools calculated prices during batch swaps, stealing $116-128 million. The exploited component had itself already been individually audited twice before the attack. V3 and other pool types were unaffected.
Audits reflect a snapshot in time and can't guarantee a flaw won't be found later, even in specifically-targeted, twice-reviewed code. This is a genuinely stark example of that limitation, one that's come up elsewhere in this series with GMX and Curve as well.
Balancer stated that many affected pools had been live on-chain for several years and were outside the platform's pause window, a real, disclosed governance limitation specific to older, legacy contracts.
No, not as of April 23, 2026. The revenue share to veBAL and BAL holders was reduced from a disclosed 82.5% to 0%, a real, material change to the platform's token economics.
A pool holding multiple tokens at customizable ratios rather than the standard 50/50 split most AMMs use, something Balancer pioneered and that Osmosis, reviewed earlier in this series, later adapted a similar option for.
The exploited V2 Composable Stable Pool type carries genuine, elevated historical risk; newer V3 pools were unaffected by the November 2025 exploit. We'd recommend real caution and preferring V3 pools specifically given this history.
A V3 feature allowing permissioned, KYC-gated pools for institutional use without compromising the core protocol's permissionless nature elsewhere, though at least one source notes this added programmability also raises the stakes of getting security review right.
More Reviews
THORChain – DEX Review
Score: 46/100. Unmatched native cross-chain swaps, carrying 2021 hacks, a $200M 2025 crisis, and use as a laundering conduit.
Read MoreHyperliquid – DEX Review
Score: 73/100. Dominant perp DEX, but closed-source code and the JELLY delisting controversy are real, unresolved trust questions.
Read MoreVertex – DEX Review
Score: 62/100. Sophisticated cross-margin trading, reviewed mid-migration to a new chain with conflicting founder accounts.
Read MoreRaydium – DEX Review
Score: 68/100. Solana's liquidity leader, carrying two confirmed incidents and a real, wide gap in third-party security ratings.
Read More



