Hacker steals over $120 million from Balancer DeFi crypto protocol

In a significant security breach, a hacker has exploited the Balancer DeFi crypto protocol, resulting in a theft exceeding $120 million. This incident highlights the growing risks associated with decentralized finance platforms, which, despite their innovative approach to financial services, remain vulnerable to sophisticated cyberattacks. The attacker leveraged vulnerabilities within the Balancer protocol's smart contracts to execute the heist, underscoring the critical need for rigorous security audits and enhanced protective measures in DeFi ecosystems. This event serves as a stark reminder for investors and developers alike to prioritize security and due diligence when engaging with or building decentralized financial applications. As the DeFi sector continues to expand rapidly, the importance of robust cybersecurity frameworks becomes paramount to safeguard assets and maintain user trust.

This Cyber News was published on www.bleepingcomputer.com. Publication date: Mon, 03 Nov 2025 21:55:12 +0000


Cyber News related to Hacker steals over $120 million from Balancer DeFi crypto protocol

CVE-2022-49123 - In the Linux kernel, the following vulnerability has been resolved: ...
8 months ago
CVE-2025-41233 - Description: ...
4 months ago
Hacker steals over $120 million from Balancer DeFi crypto protocol - In a significant security breach, a hacker has exploited the Balancer DeFi crypto protocol, resulting in a theft exceeding $120 million. This incident highlights the growing risks associated with decentralized finance platforms, which, despite their ...
1 week ago Bleepingcomputer.com
DeFi Protocol Balancer Loses $120M in Exploit - Balancer, a decentralized finance (DeFi) protocol, recently suffered a significant security breach resulting in a loss of $120 million. The exploit targeted vulnerabilities within the protocol's smart contracts, allowing attackers to manipulate the ...
1 week ago Infosecurity-magazine.com
Hackers Stolen $500K Exploiting Balancer Vulnerability - Hackers have exploited a critical vulnerability in the Balancer protocol, resulting in a theft exceeding $500,000. This incident highlights the growing risks associated with decentralized finance (DeFi) platforms and the urgent need for enhanced ...
1 week ago Cybersecuritynews.com
CVE-2025-12194 - Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules), Legion of the Bouncy Castle Inc. Bouncy Castle for Java LTS bcprov-lts8on on All (API modules) allows ...
2 weeks ago
Feds Seize 'Sinbad' Crypto Mixer Used by North Korea's Lazarus - In its continued efforts to crack down on North Korea's most formidable state-sponsored threat group, the US government has seized a virtual currency mixer that has been serving as the principal way the group launders money stolen from its ...
1 year ago Darkreading.com Lazarus Group
Ex-Amazon engineer pleads guilty to hacking crypto exchanges - Former Amazon security engineer Shakeeb Ahmed pleaded guilty this week to hacking and stealing over $12.3 million from two cryptocurrency exchanges in July 2022. The two affected companies are Nirvana Finance, a decentralized crypto exchange, and an ...
1 year ago Bleepingcomputer.com
Attackers Drained $128M From Balancer Pools - In a significant cybersecurity incident, attackers successfully drained $128 million from Balancer pools, highlighting vulnerabilities in decentralized finance (DeFi) platforms. This attack underscores the increasing sophistication of cybercriminals ...
6 days ago Cybersecuritynews.com
US removes sanctions against Tornado Cash crypto mixer - The U.S. Department of Treasury announced today that it has removed sanctions against Tornado Cash, a cryptocurrency mixer used by North Korean Lazarus hackers to launder hundreds of millions stolen in multiple crypto heists. In August 2023, the ...
7 months ago Bleepingcomputer.com
Netgear, Hyundai latest X accounts hacked to push crypto drainers - The official Netgear and Hyundai MEA Twitter/X accounts are the latest hijacked to push scams designed to infect potential victims with cryptocurrency wallet drainer malware. While Hyundai has already regained access to their account and has cleaned ...
1 year ago Bleepingcomputer.com
1inch Partners with InnerWorks to Strengthen DeFi Security - 1inch, a leading decentralized finance (DeFi) aggregator, has announced a strategic partnership with InnerWorks, a cybersecurity firm specializing in blockchain security. This collaboration aims to enhance the security framework of 1inch's DeFi ...
2 weeks ago Cybersecuritynews.com
CVE-2022-50231 - In the Linux kernel, the following vulnerability has been resolved: ...
4 months ago
The past year was the most detrimental for digital currency security breaches, with North Korean organizations profiting. - In 2022, cyberattacks on cryptocurrency platforms resulted in the theft of almost $4 billion, with a large portion of the activity being attributed to hackers working on behalf of the North Korean government. According to blockchain research firm ...
2 years ago Therecord.media Lazarus Group
Hacker spins up 1 million virtual servers to illegally mine crypto - A 29-year-old man in Ukraine was arrested this week for using hacked accounts to create 1 million virtual servers used to mine $2 million in cryptocurrency. As announced today by Europol, the suspect is believed to be the mastermind behind a ...
1 year ago Bleepingcomputer.com
FBI Charges North Korean Hackers Over $100 Million Stolen in Crypto Hack - The FBI has recently charged a North Korean hacker in connection with the Harmony crypto hack from which the hacker allegedly stole over $100 million. The hacker, Jon Chang Hyok, is a member of the North Korean military intelligence agency, the ...
2 years ago Bleepingcomputer.com
Massive Data Breach at Gokumarket: Over a Million Users' Information Exposed - Several days before the leak, the GokuMarket team found an unprotected MongoDB instance, which was storing information about its users, namely those who bought and sold crypto on the exchange. In GokuMarket's case, it is the details of more than a ...
1 year ago Cysecurity.news
Cybersecurity Industry Gains $1.7 Billion to Develop Cutting-Edge Protection Technologies - As digital threats grow in sophistication, the cybersecurity sector has ignited a funding frenzy, with startups raising $1.7 billion in April 2025 alone ahead of the RSA Conference in San Francisco. As banks and fintechs face a 40% spike in ...
5 months ago Cybersecuritynews.com
Hacker Conversations: Chris Evans, Hacker and CISO - Chris Evans is CISO and chief hacking officer at HackerOne. SecurityWeek's Hacker Conversations series seeks to understand the mind and motivations of hackers by talking to hackers. Evans challenges the common perception of both hackers and their ...
1 year ago Securityweek.com Silence
Hacker returns cryptocurrency stolen from GMX exchange after $5 million bounty payment | The Record from Recorded Future News - Last year, a man behind a $110 million theft from defunct crypto platform Mango Markets was convicted in federal court despite having negotiated with the platform to return the funds. The person behind the theft began transferring the funds in $5 ...
4 months ago Therecord.media
Key Takeaways from the 2024 Crypto Crime Mid-Year Update | Tripwire - Contrary to what one might expect, aggregate illicit activity on the blockchain decreased 19.6% from H1 2023 to H1 2024, falling from $20.9B to $16.7B. Although ChainAnalysis notes that illicit activity totals will likely rise over time, these ...
1 year ago Tripwire.com
The Week in Ransomware - January 20th, 2023 Crypto Exchanges Under Attack - The week of January 20th, 2023 brought yet another wave of ransomware attacks targeting crypto exchanges. Crypto exchanges all around the world have been hit by a barrage of sophisticated and well-planned ransomware campaigns. From high-profile ...
2 years ago Bleepingcomputer.com
Web3 security firm CertiK's X account hacked to push crypto drainer - The Twitter/X account of blockchain security firm CertiK was hijacked today to redirect the company's more than 343,000 followers to a malicious website pushing a cryptocurrency wallet drainer. Crypto fraud sleuth ZachXBT later leaked screenshots of ...
1 year ago Bleepingcomputer.com
Crypto drainer steals $59 million from 63k people in Twitter ad push - Google and Twitter ads are promoting sites containing a cryptocurrency drainer named 'MS Drainer' that has already stolen $59 million from 63,210 victims over the past nine months. According to blockchain threat analysts at ScamSniffer, they ...
1 year ago Bleepingcomputer.com

Cyber Trends (last 7 days)