Balance Coin plunged 99% after attack, losing U.S. dollar anchor
Balance Coin, an algorithmic stablecoin designed to maintain a fixed value of one dollar, plunged about 99% after encountering a major security breach on Wednesday. The attack cost the project treasury $912,000, almost wiping out its nominal value of $3.5 million.
Algorithm stablecoin unanchors after attack
Balance Coin (BLC) is a stablecoin based on an algorithmic model that is designed to always trade close to the U.S. dollar. Before the incident, BLC was trading at approximately $0.9954. However, by early Wednesday, its price had plunged to between $0.0014 and $0.0025, according to data from multiple tracking services. The sharp decline stems from a targeted attack that manipulated the project's BTCB price oracle. By late Wednesday, BLC had lost almost all market value.
Security vulnerability exploited by twisting the oracle
Balance Protocol operates a lending and casting system similar to MakerDAO that allows users to lock in assets such as BitcoinCash (BCH), Binance-anchored Bitcoin (BTCB), and USDT to mint new BLC tokens. When collateral falls below the required threshold, the agreement automatically liquidates the position and sells the collateral. Blockchain security company SlowMist traced the attack to the protocol's median oracle, which provides BTCB price data. The attacker used the "poke" function of the Spotter contract to set an abnormally low BTCB price, and then triggered liquidation through the Dog module. SlowMist pointed out that the Spotter module lacks security measures such as time-weighted average prices, deviation range checks or clearing delays. SlowMist observed that the protocol lacked critical security features, allowing attackers to liquidate secure vaults by submitting manipulated prices and obtain collateral in a single transaction. Without these protections, the system quickly became fragile, making the otherwise secure vault suddenly appear insolvent, allowing attackers to gain access to locked assets.
Small Dictionary: Oracle is a mechanism that provides external data (such as asset prices) to smart contracts and plays a key role in the operation of decentralized financial platforms.
Attacker mints tokens and converts them into real assets
The attack did not stop at reckoning. Using the compromised GemJoin contract, the attacker minted approximately 4.5 million BLC tokens from empty addresses, and immediately exchanged them for BSC-USD and BTCB on PancakeSwap V2, converting the newly minted BLC into actual cryptocurrency. A second similar transaction occurred two hours later, with an additional 5900 BLC minting. The sudden influx of unsecured coins undermines the BLC's anchoring in real time, as the mechanism originally used to maintain its dollar value is turned against the system itself.
Small Dictionary: PancakeSwap is a decentralized transaction protocol on the BNB chain that allows the exchange of BEP-20 tokens without intermediaries.
Limitations of security audits and repeated attacks on the BNB chain
The team behind Balance Coin 42DAO previously relied on CertiK's audit of its casting contracts as a security flag. CertiK is a well-known blockchain security auditor. However, these audits often focus on vulnerabilities such as coding or access controls, and often treat oracle price feeds as trusted inputs, ignoring the risk of data feeds being manipulated. Although oracle manipulation has been highlighted by OWASP's 2026 Top Ten Risks for Smart Contracts, such attacks are usually outside the scope of standard audits. Balance Coin's system lacks time-weighted average price feeds, deviation range checks, and fails to implement clearing delays similar to the one-hour oracle security module used by MakerDAO. Although the system has been legally audited, the lack of critical security measures makes it vulnerable to manipulation through price predictors that are not considered outside the scope of standard audits.
In terms of security features, Comparison between Balance Coin and MakerDAO: Time-weighted average price feed: Balance Coin not implemented, MakerDAO implemented; Deviation range check: not implemented, MakerDAO implemented; Clearing delay (Oracle Security Module): not implemented, MakerDAO implemented (1 hour).
The Balance Coin incident is the third major DeFi attack on the BNB chain in the past two months. At the end of May, approximately $7.3 million was stolen from DxScale's legacy liquidity lockups; in early June, TesseraDAO lost $2.5 million due to the leak of an administrator key. In all three incidents, the affected teams remained silent after the attack. Analysts have recently pointed out that attackers are increasingly targeting vulnerabilities in governance structures and data oracles rather than looking for coding errors. The increasing instability of algorithmic stablecoins has become more evident after major failures such as Terra's UST crash in 2022 and the repeated unanchoring of Ethena's USDe and Abracadabra's MIM.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BCH