Two decentralized finance protocols disclosed separate flash-loan exploits on August 31, 2026, highlighting ongoing security weaknesses in legacy and poorly validated liquidity pools.
Balancer V1 BPool drain. Blockchain security firm SlowMist detailed an attack on a Balancer V1 BPool that caused roughly $234,000 in losses. The attacker manipulated the joinswapPoolAmountOut function, used public swaps to reduce the pool’s WBTC balance to near zero, and then minted 4,408.8 BPT with a WBTC input of approximately one satoshi. Those pool tokens were redeemed for DPI, USDC, WETH and WBTC. The exploit was funded by flash loans from Spark, Aave, Morpho and Uniswap V3. SlowMist said the pool lacked a minimum input threshold, had no minimum pool balance requirement, and did not validate calculation outputs.
FloatProtocol and Uniswap V3 pricing. FloatProtocol separately reported a loss of about $28,000 after an attacker used a flash loan to manipulate Uniswap V3 spot pricing. The manipulated price created inflated LP share values, and the attacker repeatedly deposited and withdrew. According to reporting citing SlowMist, critical functions lacked TWAP/oracle validation and slippage protection.
The combined losses of about $262,000 are modest compared with larger DeFi breaches, but they reinforce concerns about legacy contract risk, oracle reliance, and the use of flash loans in exploits. Users are advised to review exposure to older pools and require stronger validation, circuit breakers, and oracle-based pricing in DeFi protocols.