Balancer said it has sent on-chain messages to known addresses linked to the Balancer V1 attack, offering the attacker a channel to make contact and return funds. According to Foresight News, the attacker is asked to respond privately through Blockscan before 5:00 on September 9 and begin the contact process.
Balancer said that if no response is received by the deadline, it will be treated as a refusal to cooperate and the company will escalate its response. If the attacker returns funds to the DAO multisig address, Balancer said it will negotiate a bounty and will not pursue or prosecute solely because the funds were returned, once the return is verified to meet the conditions.
If the attacker does not respond on time or rejects the proposal, Balancer said it will use all technical, on-chain, and legal means to pursue and prosecute the attacker. It added that the bounty would then be redirected to reward whistleblowers who help identify the attacker.
Balancer previously said on August 31 that a vulnerability in its legacy v1 contracts could allow LP funds to be stolen. The affected pools have been deprecated and cannot be paused, and users were advised to withdraw liquidity as soon as possible. Balancer said its other products were not affected by the vulnerability.