The incident occurred on July 22, 2026. The attackers minted millions of unsecured $BLC tokens from the agreement and exchanged them for USDT and BTCB through the PancakeSwap liquidity pool, making a profit of approximately $915,000. PeckShield flagged the exploit involving the 42DAO. Balance Coin, an algorithmic stablecoin designed to maintain the anchor of $1, plunged more than 99% in value within hours, trading as low as $0.001357. The rapid unanchoring caused significant losses to holders and liquidity providers in the 42DAO ecosystem.
Attack process
Based on on-chain records, the attacker executed two main transactions, using the GemJoin contract of the protocol on the BLC token (0x5343b458…c54668). They minted a large number of BLC from empty addresses and then transferred the tokens to the PancakeSwap V2 pool to drain available liquidity. Withdrawn funds are exchanged for stable assets and BTCB, allowing attackers to quickly cash in large amounts of value.
This exploit is one of a series of recent security incidents on the BNB chain. Earlier this month, attackers stole approximately $7.3 million from DxSale's legacy liquidity lock pool, highlighting the risks that still exist to DeFi infrastructure on the network.
Project Background and Impact
42DAO focuses on the minting of stablecoins with overcollateralized assets such as USDT, BTC and BCH. The agreement previously published smart contract audit reports, including CertiK's audit of BLC foundry contracts. The breach comes as the protocol is expanding functions such as pledge and cross-chain. The incident follows another recent BNB chain vulnerability-TesseraDAO lost approximately $2.5 million when attackers hacked its protocols, causing the TSR token to fall sharply. The successive security incidents highlight the growing security challenges facing the small DeFi ecosystem.
This vulnerability severely affects BLC holders and users who provide liquidity to PancakeSwap. Liquidity from the relevant trading pools was quickly drained, further restricting market activity and deepening losses. Total lock-in value (TVL) data for 42 DAO-related components has not yet been released. The incident exacerbated the continuing challenges faced by small DeFi projects and algorithmic stablecoins, highlighting the risks that still exist in casting control and authorization mechanisms even in audited agreements.
Recent attacks also reflect a general trend of infrastructure-level exploit in the decentralized finance sector. Earlier this month, Allbridge Core suffered an approximately $1.65 million vulnerability targeting its Solana liquidity pool, demonstrating that cross-chain bridges and liquidity protocols continue to face ongoing security threats across multiple blockchain ecosystems. As of the time of publication of this article, the 42DAO team has not issued an official statement. The agreement is expected to issue updates on any mitigation measures, financial recovery efforts or contract adjustments. Users are advised to pay attention to official channels and be cautious about related assets.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BCH
BTC