Balancer; Reviewed & Scored | The Block Note
DEX Review · Updated August 2026

Balancer:
genuinely distinctive liquidity engineering, carrying the most severe security history in this series.

We tore apart Balancer, one of the longest-running Ethereum DEXs, credited with pioneering flexible, weighted, multi-token liquidity pools, across the same seven-category scorecard we've used throughout this series. From a genuinely distinctive V3 architecture separating token custody from pool logic, Boosted Pools that automatically route idle liquidity into Aave for lending yield, and disclosed, credible institutional backing since 2021, to what we can't set aside: on November 3, 2025, Balancer V2 was exploited for a reported $116-128 million, one of the largest DeFi hacks we've documented in this entire project, its third known security breach after earlier incidents in 2021 and 2023, in a component that had itself already been individually audited twice before the attack. We also found a fourth, smaller incident in August 2026, a severe, well-documented TVL collapse following the November hack, and a real, disclosed elimination of the platform's token-holder revenue share as of April 2026; and landed on a score the marketing page won't show you.

Type Decentralized Exchange (weighted/multi-token AMM) Platforms Web · Ethereum and other EVM chains Fees Variable by pool; 0% to token holders since Apr 2026 Discount Offer None
balancer
DEX
Four distinct incidents, 2021-2026
$770M → $345-422M TVL in one day

Our take, up front: Balancer is one of the longest-running Ethereum DEXs, credited with pioneering flexible, weighted, multi-token liquidity pools rather than the simple 50/50 pairs most AMMs use, backed since a disclosed 2021 funding round by investors including Blockchain Capital, Fenbushi Capital, and Longhash Ventures. Real, genuinely distinctive V3 architecture separating token custody and accounting from pool logic, alongside Boosted Pools that automatically route idle liquidity into Aave to earn lending interest, recalled via flash loans when a large swap needs it. Real, genuinely distinctive permissioned hooks, letting institutional, KYC-gated pools operate without compromising the core protocol's permissionless nature elsewhere. What we can't set aside: genuinely the most severe, most repeated security history of any DEX we've reviewed in this series. On November 3, 2025, Balancer V2 was exploited for a reported $116-128 million, one of the largest DeFi hacks we've documented in this entire project, via a flaw in how the protocol calculated pool prices during batch swaps within its Composable Stable Pool design, a specific component that had itself already been individually audited by two named firms in September 2022. This was Balancer's third known security breach, following earlier incidents in 2021 and 2023, and per independent data aggregation, a fourth, smaller incident occurred as recently as August 30, 2026, involving $234,000 classified as a rounding-error accounting issue. Real, genuinely severe, well-documented consequence: Balancer's TVL fell from roughly $770-776 million to $345-422 million within a single day, a 45-55% collapse. Real, honest, structural disclosure: Balancer stated it could not pause many of the affected pools because they had been live for several years and were outside the platform's pause window, a genuine governance limitation specific to legacy contracts. Real, the exploit was confirmed limited specifically to V2 Composable Stable Pools; V3 and other pool types were unaffected. Real, honest, significant, disclosed policy change: revenue-sharing to veBAL and BAL token holders was reduced from a disclosed 82.5% share to zero as of April 23, 2026, a real, material change to the platform's token economics. We weighted all of it below.

Real, genuinely extensive, historically well-documented audit program: 11 audits from four different named firms (OpenZeppelin, Trail of Bits, Certora, and ABDK). What we can't set aside: genuinely the most severe security history of any DEX we've reviewed in this series. On November 3, 2025, Balancer V2 was exploited for a reported $116-128 million, one of the largest DeFi hacks we've documented in this entire project, via a flaw in how the protocol calculated pool prices during batch swaps in its Composable Stable Pool design, a component that had itself already been individually audited by two of those same firms in September 2022. This was Balancer's third known security breach, following earlier incidents in 2021 and 2023, and per independent data aggregation, a fourth, smaller incident occurred as recently as August 30, 2026, involving $234,000 classified as a rounding-error accounting issue. Real, honest, structural disclosure: Balancer stated it could not pause many of the affected pools because they had been live for several years and were outside the pause window, a genuine governance limitation on legacy contracts. Real, the exploit was specifically confirmed limited to V2 Composable Stable Pools; V3 and other pool types were unaffected.

Why this scores among the lowest Security ratings we've given in this entire project: genuinely extensive audit investment couldn't prevent what is now a well-documented pattern of repeated, serious security failures, including one of the largest exploits we've found in this project, a real and severe pattern that outweighs the audit investment itself.

Pros

  • 11 audits from four named firms (OpenZeppelin, Trail of Bits, Certora, ABDK)
  • The November 2025 exploit was confirmed limited to V2 Composable Stable Pools specifically

Cons

  • $116-128M exploit (Nov 2025), the third of four known distinct security incidents
  • The exploited component had already been individually audited twice before the attack
  • Legacy pools were outside the platform's own pause window during the exploit

Real, genuinely severe, well-documented TVL collapse directly tied to the November 2025 exploit: from approximately $770-776 million to $345-422 million in a single day, a 45-55% decline. Real, described historically as a battle-tested, long-running platform with a genuine multi-cycle track record, though that framing now sits alongside a real, recent, severe trust event.

Why this scores below the midpoint: a genuinely severe, well-documented liquidity collapse directly following a major exploit is a real, substantial factor, even accounting for the platform's long operating history.

Pros

  • Long, multi-cycle operating history predating the 2025 collapse

Cons

  • TVL fell 45-55% in a single day following the November 2025 exploit

Real, genuinely non-custodial architecture with on-chain, transparent pool contracts and community governance. Real, disclosed, credible institutional backing from its 2021 funding round, including Blockchain Capital and Fenbushi Capital. Real, honest, significant, disclosed policy change: revenue-sharing to veBAL and BAL token holders was reduced to zero as of April 23, 2026, down from a disclosed 82.5% share previously, a real, material change to the platform's token economics.

Why this scores at the midpoint: genuinely non-custodial architecture and disclosed backing are real positives, tempered by a real, disclosed elimination of token-holder revenue share and the broader governance questions raised by the platform's repeated security failures.

Pros

  • Genuinely non-custodial; disclosed, credible institutional backing since 2021

Cons

  • Token-holder revenue share cut from 82.5% to 0% as of April 2026
  • Repeated security failures raise real, broader governance and oversight questions

Real, genuinely distinctive, flexible pool architecture: weighted pools supporting multiple tokens and customizable ratios, alongside stable pools and specialized launch and structured-liquidity pool types. Real, genuinely distinctive V3 Boosted Pools, automatically routing idle liquidity to Aave for lending yield while remaining available for large swaps via flash loans.

Why this scores well: a genuinely distinctive, flexible multi-pool architecture remains one of Balancer's real, durable strengths regardless of its security history.

Pros

  • Genuinely flexible weighted, multi-token pool architecture
  • Distinctive V3 Boosted Pools with Aave-integrated lending yield

Cons

  • Greater architectural flexibility has also meant a broader, more complex attack surface

Real, a genuinely capable dashboard consolidating pool analytics, live TVL, and impermanent-loss modeling, described as suited to traders, researchers, and fund managers. Real, honest, structural complexity: the platform's own flexibility, weights, invariants, and hooks-gated pools, means genuinely more configuration and risk assessment than a simple swap interface.

Why this scores above the midpoint: a genuinely capable analytics-forward interface for sophisticated users, tempered by real, honest complexity relative to a simple swap experience.

Pros

  • Capable analytics dashboard with live TVL and impermanent-loss modeling

Cons

  • Genuine complexity in weights, invariants, and hooks relative to a simple swap

Real, disclosed, functioning fee model across pool types, historically including a meaningful revenue share to token holders. Real, honest, significant recent change: that revenue share to veBAL/BAL holders was reduced to zero as of April 2026, a real, material reduction in value returned to token holders specifically, separate from the swap fees LPs still earn.

Why this scores at the midpoint: a functioning, disclosed fee model for liquidity providers, tempered by a real, recent elimination of the token-holder revenue share specifically.

Pros

  • Disclosed, functioning swap-fee model for liquidity providers

Cons

  • Token-holder revenue share reduced from 82.5% to 0% as of April 2026

Real, genuinely distinctive V3 architecture separating token custody from pool logic. Real, genuinely distinctive permissioned hooks enabling institutional, KYC-gated pools without compromising the core protocol's permissionless nature. Real, honest, direct risk observation from at least one detailed source: hooks increase programmability, which increases the importance of careful auditing and threat modeling specifically.

Pros

  • Distinctive V3 vault architecture; permissioned hooks for institutional pools

Cons

  • Increased programmability honestly raises the stakes of getting security review right
Where to get it

Access only through Balancer's official app, and avoid older, legacy V2 pools specifically given their history.

Given the real, confirmed exploit history tied specifically to V2 Composable Stable Pools, prefer V3 pools where possible, and size any position with the platform's repeated incident history genuinely factored into your own risk tolerance.

0/ 100

Genuinely important DeFi infrastructure, carrying the most severe security record we've documented in this entire project.

We want to give Balancer real credit for what it pioneered: flexible, weighted, multi-token liquidity pools are a genuine, lasting contribution to how AMMs work, and its V3 architecture remains technically sophisticated. But we don't think it would be honest to let that historical significance soften what the evidence actually shows. Four distinct security incidents since 2021, including a $116-128 million exploit in November 2025 that hit a component already audited twice before the attack, is a genuinely different order of magnitude than a single past incident, even a serious one. One industry analyst's blunt post-hack observation, that being "audited by X" provides little real assurance on its own, reflects a real, widely shared sentiment we think is fair to take seriously here specifically. Combined with a real, disclosed elimination of the token-holder revenue share, the fair picture is a technically important but genuinely high-risk platform, deserving of real caution regardless of its pedigree.

Best forSophisticated DeFi users who specifically need Balancer's flexible weighted-pool architecture and fully understand the platform's repeated security history
Not forRisk-averse users, anyone holding funds in older V2 pools specifically, or traders seeking a platform with a cleaner recent security record
Score Ledger
balancer · 7 line items
01Security9.0
02Liquidity8.0
03Decentralization7.5
04Assets7.5
05UX6.0
06Fees5.0
07Extras3.5
TOTAL46.5
≈ 47 / 100; Important pedigree, severe record

The scorecard above is deliberately general. Whether Balancer is right for you depends heavily on which of these you already are.

Best fit

The sophisticated DeFi user who specifically needs weighted, multi-token pool architecture unavailable elsewhere

This genuine architectural flexibility remains one of Balancer's real, durable strengths.

Good fit

The user willing to stick specifically to newer V3 pools rather than legacy V2 Composable Stable Pools

Given the real, confirmed exploit history tied to that specific older pool type, this distinction genuinely matters.

Workable fit

The institutional user interested in permissioned, KYC-gated hooks-based pools specifically

This is a genuinely distinctive, real capability, best approached with full awareness of the platform's history.

Poor fit

Risk-averse users, or anyone prioritizing a clean, recent security record above architectural flexibility

Given the severity and recency of the platform's incident history, this is a real, honest consideration.

The scorecard covers the headline judgment calls. These four tables cover the specifics we didn't want to bury in prose; all four security incidents timelined, the "11 audits still failed" narrative explained precisely, the token-holder revenue elimination detailed, and Balancer against the full field.

Four distinct incidents, 2021-2026

WhenWhat happened
2021An earlier, distinct security incident (first known breach)
2023A second, distinct security incident
November 3, 2025$116-128 million exploit via a price-calculation flaw in V2 Composable Stable Pools
August 30, 2026$234,000, classified as a rounding-error token and share accounting issue

Four distinct, confirmed incidents across five years is more than any other DEX we've reviewed in this series; even accounting for Balancer's genuinely long operating history, this is a real, well-documented pattern rather than a single isolated event.

How 11 audits still missed it

Detail
Total V2 audits11, across four named firms (OpenZeppelin, Trail of Bits, Certora, ABDK)
Exploited componentComposable Stable Pool
That component's own audit historyIndividually audited by Certora and Trail of Bits in September 2022
Root causeA flaw in how pool prices were calculated during batch swaps
Pause capabilityMany affected pools were outside the pause window due to their age

This is a genuinely stark illustration of a lesson we've raised elsewhere in this series (with GMX and Curve): an audit reflects a snapshot in time, and even a specifically-targeted, twice-audited component can still contain an undiscovered flaw.

The token-holder revenue elimination, precisely

PeriodveBAL/BAL holder revenue share
Before April 23, 202682.5% of protocol revenue
After April 23, 20260%

Our sources don't establish a direct causal link between this policy change and the November 2025 exploit; we're presenting it as a separate, real, disclosed fact about the platform's current tokenomics.

Balancer against the full field

DEXConfirmed security incidents
BalancerFour (2021, 2023, 2025, 2026)
CurveThree (2023, 2025, 2026)
Raydium / dYdX / GMXTwo each
Uniswap / Aerodrome / MeteoraOne each
Orca / PancakeSwap / Hyperliquid / Injective / OsmosisNone found in our research

Balancer now holds the most confirmed security incidents of any DEX we've reviewed across this entire series, and its November 2025 exploit alone is larger in dollar terms than several other platforms' entire combined incident histories.

We don't just want to hand you our number; we want to show you how it sits next to what other review desks and comparison sites have published. Several of our sources are incident-specific hack postmortems rather than general platform reviews, so we've excluded those from this comparison and used only genuine overall-assessment sources below. We've also excluded one source (a site at an unusual domain resembling a copycat URL) that we could not verify as a legitimate, independent publisher.

The Block Note (us)N/A / 100
Industry averageN/A / 100

Our score lands substantially below the aggregated industry average, one of the largest gaps we've found in this series; some general "best DEX" roundup content published after the November 2025 exploit still describes Balancer in terms of its historical "battle-tested" reputation without fully re-pricing that reputation against the severity of what actually happened.

SourceScoreType

Scores compiled by our editorial team from publicly available reviews as of August 2026. "Editorial estimate" means the outlet didn't publish a single numeric score, so we converted their published verdict and sentiment into a comparable 100-point figure. Verify current figures directly with each source before citing them elsewhere.

Yes, four times: incidents in 2021 and 2023, a major $116-128 million exploit on November 3, 2025, and a smaller $234,000 incident on August 30, 2026. This is the most confirmed security incidents of any DEX we've reviewed in this series.

An attacker exploited a flaw in how Balancer V2's Composable Stable Pools calculated prices during batch swaps, stealing $116-128 million. The exploited component had itself already been individually audited twice before the attack. V3 and other pool types were unaffected.

Audits reflect a snapshot in time and can't guarantee a flaw won't be found later, even in specifically-targeted, twice-reviewed code. This is a genuinely stark example of that limitation, one that's come up elsewhere in this series with GMX and Curve as well.

Balancer stated that many affected pools had been live on-chain for several years and were outside the platform's pause window, a real, disclosed governance limitation specific to older, legacy contracts.

No, not as of April 23, 2026. The revenue share to veBAL and BAL holders was reduced from a disclosed 82.5% to 0%, a real, material change to the platform's token economics.

A pool holding multiple tokens at customizable ratios rather than the standard 50/50 split most AMMs use, something Balancer pioneered and that Osmosis, reviewed earlier in this series, later adapted a similar option for.

The exploited V2 Composable Stable Pool type carries genuine, elevated historical risk; newer V3 pools were unaffected by the November 2025 exploit. We'd recommend real caution and preferring V3 pools specifically given this history.

A V3 feature allowing permissioned, KYC-gated pools for institutional use without compromising the core protocol's permissionless nature elsewhere, though at least one source notes this added programmability also raises the stakes of getting security review right.

Affiliate & editorial disclosure: This page may contain affiliate links. If you buy through one, we may earn a commission at no extra cost to you. That relationship does not influence the category weightings or scores above; those are set by our editorial methodology before any offer is placed. Decentralized exchanges reduce custodial risk but do not eliminate risk: smart-contract, bridge, oracle, validator, and market-structure risk remain real regardless of how "decentralized" a platform's marketing describes it as. Leverage trading can result in losses exceeding your initial deposit. Nothing here is financial advice.
Features, pricing, and security details verified against public sources as of Aug 2026; always confirm current terms directly with Balancer.

More Reviews

Vertex – DEX Review

Score: 62/100. Sophisticated cross-margin trading, reviewed mid-migration to a new chain with conflicting founder accounts.

Read More
raydium logo cover image

Raydium – DEX Review

Score: 68/100. Solana's liquidity leader, carrying two confirmed incidents and a real, wide gap in third-party security ratings.

Read More