{"id":15831,"date":"2025-11-05T10:30:51","date_gmt":"2025-11-05T10:30:51","guid":{"rendered":"https:\/\/www.coinspeaker.com\/fr\/?p=15831"},"modified":"2025-11-05T10:37:25","modified_gmt":"2025-11-05T10:37:25","slug":"hack-defi-balancer","status":"publish","type":"post","link":"https:\/\/www.coinspeaker.com\/fr\/hack-defi-balancer\/","title":{"rendered":"DeFi en alerte : le hack Balancer de 116 M $ r\u00e9v\u00e8le une attaque ultra-pr\u00e9par\u00e9e"},"content":{"rendered":"<h2>Un hacker m\u00e9thodique et incroyablement patient<\/h2>\n<p>D\u2019apr\u00e8s les enqu\u00eates sur la blockchain apr\u00e8s le piratage en d\u00e9but de semaine, rien n\u2019a \u00e9t\u00e9 laiss\u00e9 au hasard. Le hacker de Balancer aurait <strong>pr\u00e9par\u00e9 son coup<\/strong> depuis plus de trois mois.<\/p>\n<p>Il a financ\u00e9 son compte d\u2019une extr\u00eame prudence en d\u00e9posant de petits montants de <strong>0,1 ETH via <a href=\"https:\/\/tornado.cash\/\" target=\"_blank\" rel=\"\">Tornado Cash<\/a><\/strong> pour brouiller les pistes et \u00e9viter toute d\u00e9tection. Ces d\u00e9p\u00f4ts minuscules paraissaient anodins, mais ils servaient en r\u00e9alit\u00e9 \u00e0 \u00e9tablir un historique \u00ab propre \u00bb avant le grand jour.<\/p>\n<p>Selon <strong>Conor Grogan<\/strong>, directeur chez Coinbase, l\u2019attaquant d\u00e9tenait <strong>d\u00e9j\u00e0 plus de 100 ETH<\/strong> sur Tornado Cash avant le piratage. De quoi penser qu\u2019il ne s\u2019agissait pas d\u2019un simple amateur. Certains analystes vont m\u00eame plus loin : ils soup\u00e7onnent<strong> un lien avec d\u2019autres hacks<\/strong> r\u00e9cents.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"474\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Balancer was hacked for ~$100M. Hacker seems experienced:<br \/>1. Seeded account via 100 ETH and 0.1 Tornado Cash deposits. No opsec leaks<br \/>2. Since there were no recent 100 ETH Tornado deposits,  likely that exploiter had funds there from previous exploits <a rel=\"noopener noreferrer\" target=\"_blank\" rel=\"noopener nofollow sponsored\" href=\"https:\/\/t.co\/OQOpfKwzxv\">pic.twitter.com\/OQOpfKwzxv<\/a><\/p>\n<p>&mdash; Conor (@jconorgrogan) <a rel=\"noopener noreferrer\" target=\"_blank\" rel=\"noopener nofollow sponsored\" href=\"https:\/\/twitter.com\/jconorgrogan\/status\/1985347767795859898?ref_src=twsrc%5Etfw\">November 3, 2025<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Et ce qui frappe le plus, c\u2019est la minutie. L&rsquo;agresseur n&rsquo;a pas exploit\u00e9 une simple faiblesse du protocole. Il a plut\u00f4t r\u00e9ussi \u00e0 <strong>manipuler les soldes d&rsquo;actifs<\/strong> directement. Pour cela, il a <strong>contourn\u00e9 les contr\u00f4les<\/strong> de s\u00e9curit\u00e9, un mode op\u00e9ratoire tr\u00e8s audacieux. Autrement dit, il connaissait Balancer mieux que beaucoup de ses propres d\u00e9veloppeurs.<\/p>\n<p>Face \u00e0 l\u2019utilisation de Tornado Cash dans des piratages, <strong><a href=\"https:\/\/www.coinspeaker.com\/fr\/tornado-cash-oxbow\/\" target=\"_blank\" rel=\"\">avec Oxbow<\/a><\/strong>, le m\u00e9langeur a m\u00eame introduit une fonction d\u00e9di\u00e9e. Cette derni\u00e8re permet aux utilisateurs de prouver la <strong>l\u00e9gitimit\u00e9 de leurs fonds<\/strong> sans r\u00e9v\u00e9ler leur identit\u00e9.<\/p>\n<h2>Une attaque chirurgicale, men\u00e9e \u00e0 la seconde pr\u00e8s<\/h2>\n<p>L\u2019exploitation s\u2019est d\u00e9roul\u00e9e en un \u00e9clair. En quelques minutes, plusieurs <strong>pools de liquidit\u00e9 ont \u00e9t\u00e9 siphonn\u00e9s<\/strong>, notamment ceux li\u00e9s \u00e0 <strong>WETH, osETH et wstETH<\/strong>. Les fonds ont ensuite \u00e9t\u00e9 d\u00e9plac\u00e9s sur diff\u00e9rentes cha\u00eenes, rendant le tra\u00e7age presque impossible.<\/p>\n<p>Selon plusieurs sp\u00e9cialistes en cybers\u00e9curit\u00e9, l\u2019attaque s\u2019est appuy\u00e9e sur une fonction mal prot\u00e9g\u00e9e appel\u00e9e \u201c<strong>manageUserBalance<\/strong>\u201d. En manipulant ce m\u00e9canisme, l\u2019assaillant a pu <strong>transf\u00e9rer des actifs<\/strong> sans d\u00e9clencher les alertes pr\u00e9vues. Une v\u00e9ritable op\u00e9ration chirurgicale.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"474\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Today, around 7:48 AM UTC, an exploit affected Balancer V2 Composable Stable Pools.<\/p>\n<p>Our team is working with leading security researchers to understand the issue and will share additional findings and a full post-mortem as soon as possible.<\/p>\n<p>Because these pools have been live\u2026 <a rel=\"noopener noreferrer\" target=\"_blank\" rel=\"noopener nofollow sponsored\" href=\"https:\/\/t.co\/LRLNNXogt3\">pic.twitter.com\/LRLNNXogt3<\/a><\/p>\n<p>&mdash; Balancer (@Balancer) <a rel=\"noopener noreferrer\" target=\"_blank\" rel=\"noopener nofollow sponsored\" href=\"https:\/\/twitter.com\/Balancer\/status\/1985390307245244573?ref_src=twsrc%5Etfw\">November 3, 2025<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Balancer, sous le choc, a rapidement r\u00e9agi. L\u2019\u00e9quipe a suspendu plusieurs contrats et propos\u00e9 <strong>une prime de 20 %<\/strong> au hacker s\u2019il rendait les fonds. Une tentative de \u00ab n\u00e9gociation \u00e9thique \u00bb devenue quasiment courante dans le monde DeFi. Mais pour l\u2019instant, silence radio du c\u00f4t\u00e9 du pirate.<\/p>\n<p>Dans un tout autre registre, <strong><a href=\"http:\/\/coinspeaker.com\/fr\/go\/bestwallet\" target=\"_blank\" rel=\" nofollow sponsored\">Best Wallet<\/a> <\/strong>profite de cette actualit\u00e9 pour mettre en avant <strong>sa s\u00e9curit\u00e9 renforc\u00e9e<\/strong> et sa pr\u00e9vente en cours. Une occasion unique pour les investisseurs de rejoindre un \u00e9cosyst\u00e8me crypto centr\u00e9 sur la transparence et la protection des utilisateurs.<\/p>\n<p style=\"text-align: center\"><span style=\"font-weight: 400\"><a href=\"http:\/\/coinspeaker.com\/fr\/go\/bestwallet-exchange\" rel=\"noopener sponsored nofollow\" target=\"_blank\" class=\"custom-cta-button\">D\u00e9couvrir Best Wallet<\/a><\/span><\/p>\n<h2>Une claque pour tout l\u2019\u00e9cosyst\u00e8me DeFi<\/h2>\n<p>Cet \u00e9pisode a \u00e9branl\u00e9 la confiance de toute la communaut\u00e9. Balancer avait pourtant pass\u00e9 plus de <strong>10 audits ind\u00e9pendants<\/strong>, preuve que la s\u00e9curit\u00e9 ne garantit pas l\u2019immunit\u00e9. Et cela remet clairement sur la table une question d\u00e9rangeante : peut-on vraiment s\u00e9curiser des protocoles aussi complexes ?<\/p>\n<p>Au-del\u00e0 des millions envol\u00e9s, le hack de Balancer rappelle une v\u00e9rit\u00e9 simple : <strong>personne n\u2019est intouchable<\/strong>. La DeFi avance \u00e0 toute vitesse, parfois plus vite que sa propre s\u00e9curit\u00e9. Et malheureusement, les hackers, eux, ont tout le temps du monde.<\/p>\n<p>Un rappel amer, tout comme celui d&rsquo;<strong><a href=\"https:\/\/www.coinspeaker.com\/fr\/astra-nova-hack-10m\/\">exploit d\u2019Astra Nova<\/a><\/strong> \u00e0 10 millions de dollars, qui a, lui aussi, mis en lumi\u00e8re la<strong> fragilit\u00e9 des projets DeFi<\/strong> face \u00e0 des attaques toujours plus sophistiqu\u00e9es.<\/p>\n<p>Un <strong>co-fondateur de Cyvers<\/strong> consid\u00e8re m\u00eame cet exploit comme le plus sophistiqu\u00e9 de l&rsquo;ann\u00e9e. Ce type d&rsquo;attaque rappelle d&rsquo;ailleurs les op\u00e9rations du <strong>c\u00e9l\u00e8bre groupe Lazarus<\/strong>.<\/p>\n<p>De m\u00eame, on raconte que le c\u00e9l\u00e8bre groupe de hackers nord-cor\u00e9en, Lazarus, a pris une longue pause strat\u00e9gique avant de frapper \u00e0 nouveau en mars. Leur retour a \u00e9t\u00e9 fracassant : ils auraient orchestr\u00e9 un <strong>piratage massif contre <a href=\"https:\/\/www.coinspeaker.com\/from-sony-to-bybit-how-lazarus-group-became-the-worlds-most-dangerous-crypto-hackers\/\" rel=\"\">Bybit<\/a><\/strong>, s&#8217;emparant 1,4 milliard de dollars !<\/p>\n<hr \/>\n<p>\u00c0 lire aussi :<\/p>\n<ul>\n<li><a href=\"https:\/\/www.coinspeaker.com\/fr\/2-milliards-dollars-voles-2025\/\">Plus de 2 milliards de dollars vol\u00e9s en 2025 : la crypto face \u00e0 une nouvelle vague de hacks<br \/>\n<\/a><\/li>\n<li><a href=\"https:\/\/www.coinspeaker.com\/fr\/hackers-ethiques-deviennent-nouveaux-influenceurs-web3\/\">Pourquoi les hackers \u00e9thiques deviennent les nouveaux influenceurs du Web3<br \/>\n<\/a><\/li>\n<li><a href=\"https:\/\/www.coinspeaker.com\/fr\/seal-safe-harbor-hackers-ethiques\/\">SEAL : les hackers \u00e9thiques ont sauv\u00e9 plus de 25 milliards $ en cryptomonnaies<\/a><\/li>\n<\/ul>\n<a class=\"infinscroll_next_page_link\" style=\"display:none\" href=\"https:\/\/www.coinspeaker.com\/fr\/mamdani-maire-new-york-avenir-cryptos\/\" rel=\"prev\">next<\/a>","protected":false},"excerpt":{"rendered":"<p>Le monde de la finance d\u00e9centralis\u00e9e vient de vivre un vrai s\u00e9isme. Le protocole Balancer, pourtant consid\u00e9r\u00e9 comme l\u2019un des piliers de la DeFi, a \u00e9t\u00e9 victime d\u2019un piratage d\u2019environ 116 millions de dollars. Une attaque d\u2019une pr\u00e9cision gla\u00e7ante, men\u00e9e par un hacker manifestement tr\u00e8s exp\u00e9riment\u00e9. Et surtout, planifi\u00e9e pendant des mois, dans le plus grand secret.<\/p>\n","protected":false},"author":200,"featured_media":15850,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-15831","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-actu"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>DeFi en alerte : le hack Balancer de 116 M $ r\u00e9v\u00e8le une attaque ultra-pr\u00e9par\u00e9e<\/title>\n<meta name=\"description\" content=\"Le protocole Balancer pirat\u00e9 de 116 M$ : une attaque ultra-pr\u00e9par\u00e9e, m\u00e9thodique et gla\u00e7ante, qui secoue tout l\u2019\u00e9cosyst\u00e8me DeFi.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.coinspeaker.com\/fr\/hack-defi-balancer\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DeFi en alerte : le hack Balancer de 116 M $ r\u00e9v\u00e8le une attaque ultra-pr\u00e9par\u00e9e\" \/>\n<meta property=\"og:description\" content=\"Le protocole Balancer pirat\u00e9 de 116 M$ : une attaque ultra-pr\u00e9par\u00e9e, m\u00e9thodique et gla\u00e7ante, qui secoue tout l\u2019\u00e9cosyst\u00e8me DeFi.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.coinspeaker.com\/fr\/hack-defi-balancer\/\" \/>\n<meta property=\"og:site_name\" content=\"Coinspeaker France\" \/>\n<meta property=\"article:published_time\" content=\"2025-11-05T10:30:51+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-11-05T10:37:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.coinspeaker.com\/fr\/wp-content\/uploads\/sites\/6\/2025\/11\/Balancer-hack.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"800\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Emmanuel Roux\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Emmanuel Roux\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"DeFi en alerte : le hack Balancer de 116 M $ r\u00e9v\u00e8le une attaque ultra-pr\u00e9par\u00e9e","description":"Le protocole Balancer pirat\u00e9 de 116 M$ : une attaque ultra-pr\u00e9par\u00e9e, m\u00e9thodique et gla\u00e7ante, qui secoue tout l\u2019\u00e9cosyst\u00e8me DeFi.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.coinspeaker.com\/fr\/hack-defi-balancer\/","og_locale":"fr_FR","og_type":"article","og_title":"DeFi en alerte : le hack Balancer de 116 M $ r\u00e9v\u00e8le une attaque ultra-pr\u00e9par\u00e9e","og_description":"Le protocole Balancer pirat\u00e9 de 116 M$ : une attaque ultra-pr\u00e9par\u00e9e, m\u00e9thodique et gla\u00e7ante, qui secoue tout l\u2019\u00e9cosyst\u00e8me DeFi.","og_url":"https:\/\/www.coinspeaker.com\/fr\/hack-defi-balancer\/","og_site_name":"Coinspeaker France","article_published_time":"2025-11-05T10:30:51+00:00","article_modified_time":"2025-11-05T10:37:25+00:00","og_image":[{"width":1200,"height":800,"url":"https:\/\/www.coinspeaker.com\/fr\/wp-content\/uploads\/sites\/6\/2025\/11\/Balancer-hack.png","type":"image\/png"}],"author":"Emmanuel Roux","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Emmanuel Roux","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.coinspeaker.com\/fr\/hack-defi-balancer\/","url":"https:\/\/www.coinspeaker.com\/fr\/hack-defi-balancer\/","name":"DeFi en alerte : le hack Balancer de 116 M $ r\u00e9v\u00e8le une attaque ultra-pr\u00e9par\u00e9e","isPartOf":{"@id":"https:\/\/www.coinspeaker.com\/fr\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.coinspeaker.com\/fr\/hack-defi-balancer\/#primaryimage"},"image":{"@id":"https:\/\/www.coinspeaker.com\/fr\/hack-defi-balancer\/#primaryimage"},"thumbnailUrl":"https:\/\/www.coinspeaker.com\/fr\/wp-content\/uploads\/sites\/6\/2025\/11\/Balancer-hack.png","datePublished":"2025-11-05T10:30:51+00:00","dateModified":"2025-11-05T10:37:25+00:00","author":{"@id":"https:\/\/www.coinspeaker.com\/fr\/#\/schema\/person\/cfb5df450a3f98d6cbdac45264af1e5d"},"description":"Le protocole Balancer pirat\u00e9 de 116 M$ : une attaque ultra-pr\u00e9par\u00e9e, m\u00e9thodique et gla\u00e7ante, qui secoue tout l\u2019\u00e9cosyst\u00e8me DeFi.","breadcrumb":{"@id":"https:\/\/www.coinspeaker.com\/fr\/hack-defi-balancer\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.coinspeaker.com\/fr\/hack-defi-balancer\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/www.coinspeaker.com\/fr\/hack-defi-balancer\/#primaryimage","url":"https:\/\/www.coinspeaker.com\/fr\/wp-content\/uploads\/sites\/6\/2025\/11\/Balancer-hack.png","contentUrl":"https:\/\/www.coinspeaker.com\/fr\/wp-content\/uploads\/sites\/6\/2025\/11\/Balancer-hack.png","width":1200,"height":800,"caption":"Balancer hack"},{"@type":"BreadcrumbList","@id":"https:\/\/www.coinspeaker.com\/fr\/hack-defi-balancer\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.coinspeaker.com\/fr\/"},{"@type":"ListItem","position":2,"name":"DeFi en alerte : le hack Balancer de 116 M $ r\u00e9v\u00e8le une attaque ultra-pr\u00e9par\u00e9e"}]},{"@type":"WebSite","@id":"https:\/\/www.coinspeaker.com\/fr\/#website","url":"https:\/\/www.coinspeaker.com\/fr\/","name":"Coinspeaker France","description":"Bitcoin, Ethereum, Altcoins et actualit\u00e9s crypto avec analyses, cours en direct, graphiques de donn\u00e9es et guides","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.coinspeaker.com\/fr\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Person","@id":"https:\/\/www.coinspeaker.com\/fr\/#\/schema\/person\/cfb5df450a3f98d6cbdac45264af1e5d","name":"Emmanuel Roux","image":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/www.coinspeaker.com\/fr\/#\/schema\/person\/image\/","url":"https:\/\/www.coinspeaker.com\/fr\/wp-content\/uploads\/sites\/6\/2025\/06\/cropped-pp-1-96x96.png","contentUrl":"https:\/\/www.coinspeaker.com\/fr\/wp-content\/uploads\/sites\/6\/2025\/06\/cropped-pp-1-96x96.png","caption":"Emmanuel Roux"},"description":"Issu de la finance traditionnelle, j\u2019ai naturellement bascul\u00e9 vers l\u2019univers crypto, attir\u00e9 par son potentiel. Je souhaite y apporter mon approche analytique et rationnelle, tout en conservant ma curiosit\u00e9. En dehors de l\u2019\u00e9cran, je lis beaucoup (\u00e9conomie, essais, un peu de science-fiction) et je prends plaisir \u00e0 bricoler. Le DIY, pour moi, c\u2019est comme la crypto : comprendre, tester, construire soi-m\u00eame.","url":"https:\/\/www.coinspeaker.com\/fr\/author\/emmanuel\/"}]}},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.coinspeaker.com\/fr\/wp-json\/wp\/v2\/posts\/15831","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.coinspeaker.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.coinspeaker.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.coinspeaker.com\/fr\/wp-json\/wp\/v2\/users\/200"}],"replies":[{"embeddable":true,"href":"https:\/\/www.coinspeaker.com\/fr\/wp-json\/wp\/v2\/comments?post=15831"}],"version-history":[{"count":2,"href":"https:\/\/www.coinspeaker.com\/fr\/wp-json\/wp\/v2\/posts\/15831\/revisions"}],"predecessor-version":[{"id":15853,"href":"https:\/\/www.coinspeaker.com\/fr\/wp-json\/wp\/v2\/posts\/15831\/revisions\/15853"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.coinspeaker.com\/fr\/wp-json\/wp\/v2\/media\/15850"}],"wp:attachment":[{"href":"https:\/\/www.coinspeaker.com\/fr\/wp-json\/wp\/v2\/media?parent=15831"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.coinspeaker.com\/fr\/wp-json\/wp\/v2\/categories?post=15831"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.coinspeaker.com\/fr\/wp-json\/wp\/v2\/tags?post=15831"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}