Balancer V1: $234K Drained Through a Rounding Flaw, Advisory Tells LPs to Withdraw
An attacker exploited a rounding and precision vulnerability in legacy Balancer V1 contracts on August 31, draining approximately $234,000, according to SlowMist's analysis. The mechanism was surgical: using flash loans to compress a pool's WBTC reserves to near-zero, the attacker minted a large amount of BPT pool tokens with roughly one satoshi of WBTC as the only real input, then exited proportionally with a haul that included DPI, USDC, WETH, and WBTC from the pool. The incident was separately reported the same day by Pluang, which described the flaw as a rounding error in WBTC reserve accounting.
The story did not end with the drain. A September 2 CryptoTicker advisory urged holders to withdraw their funds from legacy Balancer V1 pools themselves, on the premise that unmaintained contracts leave no patch coming. It is a recurring pattern in DeFi security: code that still holds funds after its maintainers have moved on becomes an open invitation, and the only available mitigation for users is exit.
FOGO: Mainnet Back Online, 237M Tokens Burned After Supply Attack
Fogo, the Solana-fork layer-1, has returned its mainnet to operation after a supply-level attack that began in late August, according to a September 2 report by Cryptonews.net. The Block previously reported that the chain was halted after the attacker received 400 million FOGO — roughly 10% of circulating supply — and Yellow.com reported the theft at approximately $3 million tied to a critical flaw. Per the September 2 relaunch report, 237 million FOGO tokens were burned as part of the recovery.
The sequence — halt, restructure, burn the unbacked supply, restart — mirrors choices other chains have made under identical pressure. The open question reported so far is accountability: none of the available reporting identifies the attacker or confirms fund recovery.
France: 678,000 Records Confirmed Extracted as Dataset Surfaces for Sale
The breach at France's tax authority, the DGFiP, continues to develop. The authority has confirmed that data on 678,000 people and professionals was extracted, and a purported DGFiP dataset has been listed for sale for thousands of euros, according to reporting aggregated by rekt.news and covered by Security Affairs and BleepingComputer. Decrypt's August 14 analysis warned the leak could fuel scams and physical attacks targeting Bitcoin holders.
The insider case that surfaced the breach remains the sharpest illustration of the risk: prosecutors allege a tax office employee used the administration's own software to search specifically for cryptocurrency specialists and investors and sold their data to criminal networks for extortion and physical attacks. The accused has been detained since June 30, 2025, admits passing information, and denies knowledge of her client's violent intentions, according to French reporting. In August 2026, another actor separately claimed access to DGFiP systems — a claim BleepingComputer covered as investigators work to verify it.
For self-custody holders, the lesson is unglamorous: the most dangerous databases are often the state's own financial records, and the $5-wrench threat model starts with who knows you hold keys.
TrustGrade covers the enforcement and security ecosystem. For verified trust data on the projects and firms shaping it, see trustgrade.ai.