Infrastructure · Analysis
Who Watches Balancer's Pools After October 30?
A proposal to wind down Balancer picks one date for three things: pausable pools go withdrawals-only, Balancer stops operating the protocol, and the bug bounty ends. Pools that can't be paused keep trading. About $55 million is still in Balancer's contracts.
Most wind-down proposals are about money. This one, posted to Balancer's governance forum on Monday, September 14, spends most of its length on money too: a treasury of "at least $9M" going back to BAL holders who burn their tokens, in two rounds and a final sweep that ends in July 2028. The security details are in the operational sections, and they all land on one date.
On October 30, 2026, if holders approve the plan in a Snapshot vote scheduled for September 25–29, "pools that can be paused are paused and move to withdrawals only." Recovery mode is switched on where a pool's contracts require it. The protocol fee drops to zero. The bug bounty program, the proposal says, "ends on 30 October 2026." In the section for researchers, it says "After that date the program no longer exists."
One sentence covers the rest of the protocol: "Pools that cannot be paused keep working as they are."
Why the pause switch is the whole story
Balancer has already seen what separates a pausable pool from one that isn't. On November 3, 2025, an attacker exploited a rounding error in the "exact out" swap path of Balancer v2's Composable Stable Pools. According to the protocol's own post-mortem, the theft "primarily affected" version 5 of those pools. Vulnerable version 6 pools "were still within their pause windows." They were paused at 08:07 UTC, 21 minutes after the first malicious transaction, protecting $19.3 million in liquidity.
The post-mortem doesn't explain in so many words why the version 5 pools weren't paused too. Read alongside its statement that the version 6 pools were saved because they were still inside their windows, the implication is hard to miss. The figures don't line up neatly either. The post-mortem gives an estimated $94.8 million theft of user funds in its introduction and $121.1 million in total losses in its impact section. The Block uses about $128 million.
The wind-down plan sorts the protocol along the same line. Pools that can still be stopped will be. The rest keep running, with protocol fees zeroed where the contracts allow, no Balancer team operating them after the transition, and, from October 30, no bounty paying anyone to report a flaw instead of using it.
Where Balancer's remaining liquidity sits (TVL, $ millions)
What the plan does promise
The proposal is careful on custody. "The contracts are non custodial: withdrawing does not depend on Balancer or on anyone continuing to operate," it says. It promises documentation for withdrawing directly from the contracts and through third-party tools during a six-week exit window, plus a simplified withdrawal interface kept online through both distribution rounds. It also promises that "the treatment of each [pool] is published before that date."
It also plans to dismantle privileged access. Admin permissions and multisig roles, "including the mainnet DAO multisig and the Emergency subDAO," are to be inventoried and then revoked or transferred "as each becomes safe to retire," with low-risk revocations penciled in for November and December 2026. "Roles that cannot be removed are inventoried and published." The stated end state is "a protocol that needs no one from Balancer."
That's a coherent goal for immutable software. It's also the Emergency subDAO that, per the post-mortem, killed gauges on affected v2 pools the day after the 2025 exploit. The plan retires the bounty on October 30 and winds down those emergency roles afterward. It doesn't describe anything taking over monitoring once the transition team is gone.
The money behind the decision
The author, who posts as Marcus and whom The Block identifies as Marcus Hardt, a Treasury Council member and former Balancer Labs chief executive, is blunt about why. An April restructuring cut costs and ended emissions, and "None converted into sustained revenue growth." He puts monthly burn at about $150,000 against protocol revenue of about $30,000 in August, down from $97,000 in June, most of it still from v2. crypto.news gives a different August revenue figure, $56,781, and $1.13 million for October 2025, the month before the exploit. The two sources may be measuring different things. This desk hasn't reconciled them.
He's also direct about the hack's role. It "followed the name into every conversation since and made traction harder to build," he writes, but "it is not what this rests on." Funds recovered from the attacks "belong to the LPs of the affected pools" and stay outside the treasury distribution. The investigations "continue with private investigators and law enforcement."
The same document handles the bounty's money. BIP-687 set aside $1 million in USDC for the program. The wind-down supersedes it, and the earmark "is released when coverage ends and the reports open at that date are resolved." A separate, parallel proposal would change the critical-severity cap for the remaining weeks. The wind-down doesn't give the new figure.
Not everyone wants to close
The thread filled quickly. Contributors posting as zekraken and gosuto announced a "(Pitch)fork," arguing the urgency "is not justified" and proposing to keep the original restructuring timeline of a gradual pause ending in Q2 2027. The proposal itself notes that contributors are preparing a separate plan to keep the infrastructure running under a new name, which the author says he supports as a fork. Another respondent, 0xMaha, raised a practical problem: Aura "no longer has governance infrastructure," so it may not be able to vote at all.
Whichever way the vote goes, the proposal states that "winddown actions, including the pause, fee changes, permission revocations," wait for it. If it fails, the current framework stays, including the BIP-687 bounty.
The Take
This is an unusually honest wind-down, with real numbers and disclosed conflicts, and it deserves credit for putting its costs in the open. The October 30 date needs a second look anyway. Ending the bounty the same day the team stops operating makes sense for pools that can be frozen. It makes much less sense for pools that can't, because those are the ones that keep holding value with nobody paid to look at them. By Balancer's own post-mortem, the pools that couldn't be stopped in time are where most of the 2025 losses landed. Two changes would cost little against a $9 million treasury. First, publish the pool-by-pool list, including which pools can't be paused and how much each holds, before the Snapshot vote rather than before October 30, so voters know what they're leaving running. Second, keep a capped bounty funded from the $220,000 reserve until non-pausable TVL falls below a set threshold. A protocol "that needs no one" still needs someone it pays to report problems instead of exploiting them.