EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Balance Coin (BLC) plunged 99% after being attacked by oracle, losing $915,000

2026-07-23 00:12:37
Bookmark

Core Points

This article will provide an in-depth analysis of the security breach incidents encountered by Balance Coin (BLC), covering attack methods, losses and market impact.

Balance Coin (BLC) plunged more than 99% after BNB Chain suffered a security breach

Attackers minted millions of unauthorized BLC tokens and exchanged them for USDT and BTCB. The attack involved two malicious transactions that stole approximately $915,000 from the ecosystem. Blockchain security analysis agency SlowMist and PeckShield confirmed that the attack vector is a Bitcoin price oracle vulnerability. The incident targeted the 42DAO platform, which is responsible for managing the Balance Protocol infrastructure.

stablecoin unanchors and prices nearly return to zero

Balance Coin is an algorithmic stablecoin designed to maintain a 1:1 anchor with the U.S. dollar. On July 22, the currency suffered a catastrophic collapse after blockchain security researchers reported that the 42DAO platform on BNB Chain had been attacked. Digital assets plunged from about $1 to an all-time low of $0.001209 in a matter of hours. According to CoinMarketCap data at press time, Balance Coin's trading price was approximately US$0.00247, a one-day drop of 99.75%.

Attack Details: Oracle Price Manipulation

Cybersecurity firm PeckShield estimated the total damage at approximately $915,000. The company traced the incident to a vulnerability in the 42DAO, a decentralized autonomous organization responsible for managing the Balance Protocol. Security researcher TenArmor discovered two suspicious transactions related to GemJoin and 42DAO on BNB Chain. The first transaction created approximately 4.5 million BLC tokens from a zero address, which were subsequently transferred to PancakeSwap V2. The attacker then exchanged the newly minted BLC for Binance-anchored USDT and Binance Bitcoin. About two hours later, the second transaction used the same approach, generating 5900 more BLC and withdrawing more funds from liquidity reserves.

According to SlowMist's analysis, the attacker took advantage of a manipulated Binance Bitcoin oracle that showed an artificially low price. This fraud led to the protocol mistakenly marking the secure Bitcoin mortgage pool as liquidable. "The attacker executed a single combination of transactions, exploiting vulnerabilities similar to the lack of price protection and clearing delays in the MakerDAO architecture," SlowMist explained. Malicious actors liquidated multiple BTCB vaults and captured the resulting price difference. The creation of unsecured coins flooded the liquidity pool of decentralized exchanges with excessive BLC inventory. This overwhelming selling pressure, in the absence of an effective stabilization mechanism, pushed the token price well below its U.S. dollar anchor level.

Unauthorized token creation: DeFi platform's continuing obsession

Similar attack patterns have emerged in multiple protocols. In May last year, MAPO's value fell by 96% after malicious actors used a bridging vulnerability to create unauthorized tokens and cleared them through a decentralized trading platform. In another incident, Stake DAO was attacked, and attackers generated trillions of vsdCRV tokens, which were subsequently exchanged for ETH. In addition, Resolv's USR stablecoin also fell unanchored in March due to a similar unauthorized minting incident.

Balance Coin is the main stablecoin in the Balance Protocol ecosystem, which, according to its GitBook documentation, is mainly backed by Bitcoin Cash as collateral. As of the release of this report, the 42DAO has not yet released an official post-mortem analysis report. Relevant media tried to contact 42DAO for official comments, but have not yet received any statement. Blockchain evidence shows that two suspicious transactions were the root cause of the security breach, and multiple security agencies confirmed the loss of approximately US$915,000.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP