logo

Copycat Attack on Balancer: Why DeFi Needs to Change

ID: 60bf608c-6c6d-5f1f-989d-18969ea1eceb

STIX ID: report--60bf608c-6c6d-5f1f-989d-18969ea1eceb

Feed Name: CertiK Blog

Threat Score
60/100

Date Published: 2020-07-02

Date Updated: 2026-06-11

...
...

**Executive summary:** On June 29, 2020 CertiK reports two copycat attacks against Balancer where attackers used dYdX and Uniswap flash loans to mint cTokens, trigger Compound's COMP airdrop, and exploit Balancer's gulp() function to siphon off newly created COMP (netting ~11.5 ETH in these instances), highlighting that the root cause is a financial-model/design weakness rather than a simple code bug and urging DeFi projects to adopt financial-model-level security and proactive defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.