Balancer V2
DEX / AMM — Established Vault-based AMM (weighted / stable / boosted pools). The 2023 and 2025 exploits below were both on V2.
AI review
AI assessment
updated 4h ago·Claude (preview)·previewBalancer V2 is a dex / amm protocol. 3 of 16 risk feeds in the registry report on it. 2 sourced incidents on record. No material change has been detected in the current window.
- Governance: BAL/veBAL holders vote via Snapshot; DAO multisig enacts (no discretionary power, no fund custody) governance
- 3 of 16 feeds report on Balancer V2. coverage
- Most recent recorded event: ComposableStablePool rounding-error exploit. incident
AI-generated summary of facts already in this registry — not a Rails assessment, not a risk score, and not a ranking. Per the project charter, the registry never produces its own composite risk judgement. Verify every point against the linked sources below. This is an illustrative preview of a proposed feature; the content is not live.
Feeds
How feeds see it
Seen through 1 of 4 methodology lenses (rating). A neutral view of who is looking and how — not a risk judgement.
The 3 reporting feeds are split on how fully they assess Balancer V2: 1 assess it fully, 2 only partially, and they use different methodologies and scales. We show every position side by side and do not reconcile them into a single verdict — oracle diversity made visible, not adjudicated.
Process Quality Review published (PQR id 568); a 100% figure appears in one source — treat as unconfirmed pending the live PQR.
View sourceSeparate 'Balancer V2' page; only Verifiability graded, other dimensions unknown.
Balancer V2 protocol page listed; pool grades not captured pre-migration.
View sourceDecentralization maturity: who controls keys, upgrades, and admin powers. Stage 0–2 framework.
Protocol risk research and parameter recommendations; collateral and governance risk.
Quantitative on-chain risk dashboards for lending markets: liquidations, collateral health, exposure.
Vault-level risk monitoring for Morpho curators: allocation risk and curator behavior.
Institutional-grade credit-risk ratings for DeFi protocols and borrowers. Credora by RedStone; GraphQL API + on-chain attestations (EAS).
Independent risk rating for DeFi vaults; 300+ subscores across 85+ mechanisms. Open-source.
Deterministic vault risk scoring across 700+ vaults: asset quality, code maturity, governance. Open methodology (public API, CLI, MCP server).
Vault analytics and risk-adjusted yield across 50+ protocols; exploits, concentration, risk-adjusted APY. Paid structured API.
Position-management tooling: live loan-health / safety-ratio tracking and automated liquidation protection for leveraged positions.
Real-time risk scores for DeFi liquidity pools: risk metrics, TVL, APY, security grades.
DAO governance-capture risk: delegate/voting-power concentration, cost-to-attack vs. treasury value, and proposal/power-shift monitoring across major DAOs. Open-source.
Agent-based economic simulation: insolvency prevention, parameter optimization, and risk-scenario analysis for lending markets.
Edge risk oracles and economic-risk dashboards: real-time parameter automation and scenario stress for lending markets (active on Aave, GMX, Pendle).
Governance
Governance at a glance
- Governance
- DAO (Snapshot + multisig)
- Timelock
- None
- Core contracts
- Immutable
Structural facts, distilled from the sourced control records below — neutral capabilities, not a risk score. Multisig threshold and signer count are fetched live via the Safe API.
| Governance | |
| Upgradeability | |
| Admin control | |
| Authorizer |
Incidents
An attacker exploited integer-division precision loss in Balancer V2 ComposableStablePool invariant math to drain pools across several chains; reported losses range ~$110M–$128M. As of late Nov 2025 the DAO was discussing redistributing ~$8M recovered — most funds were not recovered.
Balancer disclosed a critical V2 Boosted Pool vulnerability and urged LPs to withdraw; ~$0.9M was exploited despite mitigation, with most at-risk funds withdrawn after the warning.
Material risk events, presented verbatim from cited sources — not a Rails assessment.