EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Balance Coin plunges from $1 anchored price, exploit pulls $1 million from Bitcoin vault

2026-07-23 12:11:37
Bookmark

Balance Coin was attacked and its price plunged about 99%

Balance Coin's price plunged about 99% on Wednesday after an attacker manipulated its BTCB price oracle and stole $912,000 from the project vault, causing the token to lose almost all its value.

Balance Coin (BLC) is an algorithmic stablecoin pegged to the U.S. dollar. Its design goal is to maintain a trading price of US$1. On Tuesday, it was trading at about $0.9954, but by early Wednesday, the price had dropped to less than a penny, or about $0.0014, while other tracking platforms showed prices closer to $0.0025. Whichever data you use, Balance Coin had lost almost the vast majority of its $3.5 million nominal value by late Wednesday.

False Bitcoin prices turn safe vaults into clearing targets

Balance Protocol uses a Maker-like architecture. It allows users to lock in collateral (usually Bitcoin Cash (BCH), and Binance-anchored Bitcoin (BTCB) and USDT) and cast BLC accordingly. Once the value of the collateral is significantly lower than the debt, the agreement will immediately liquidate the position and sell the collateral assets.

Security company SlowMist traced the theft to the protocol's median oracle (Median Oracle). The median oracle is a price feed that provides BTCB value to the system. The attacker entered an abnormally low price into the price feed through the "poke" function on the Spotter contract, and then triggered a liquidation through the Dog module. In SlowMist's words, Spotter lacks a time-weighted average price feed, a boundary check that can reject deviations from market prices, and a clearing delay mechanism. In the absence of these measures, the originally safe vault suddenly became insolvent, and thieves liquidated it at a false price and took away all the collateral in a single transaction.

Coins minted are transferred directly through PancakeSwap

The theft does not stop in the vault. The attacker minted approximately 4.5 million BLC from an empty address through a tampered GemJoin contract, and sent the tokens to PancakeSwap V2 to exchange them for BSC-USD and BTCB; this successfully converted the newly minted tokens into real assets. Two hours later, another deal was reported to have taken place and 5900 BLC pieces were minted.

It was this wave of unsupported supply that caused BLC to deviate from its target price in real time. Because the mechanism originally used to maintain the hook is used by attackers to break the hook.

CertiK audit failed to find vulnerability

Previously, 42DAO had used CertiK audit results of its BLC casting contracts as a sign of safety. This time, however, it didn't work-although the audit itself is legal, standard smart contract audits focus mainly on access control errors, re-entry attacks, overflows and coding flaws. They often view oracle input as credible rather than simulating manipulated price feeds as a threat that needs to be included in scope.

Although OWASP lists oracle manipulation in its Top Ten Risks for Smart Contracts for 2026, measures to prevent such attacks are generally outside the scope of standard audits. The 42DAO's system lacks any of the following: a time-weighted average price feed; a price boundary check that can reject deviations from market prices; and a clearing delay mechanism similar to the MakerDAO's one-hour oracle security module.

Third protocol on BNB Chain to silence after attack

In the past two months, Wednesday's incident has become the third major DeFi security incident on BNB Chain. This is also the third incident in which an attacked team chose to remain silent. At the end of May, approximately $7.3 million was stolen from DxScale's legacy liquidity locker. In early June, TesseraDAO lost approximately $2.5 million when attackers used an administrator key leak to steal 99 million TSR tokens.

This string of attacks is consistent with recent trends among attackers in 2026. Analysts point out that attackers are no longer focusing on exploiting code vulnerabilities, but are looking to the oracles and governance layers around the code. These attacks also occur at a time when markets are increasingly wary of algorithmic stablecoins, especially after the Terra UST crash in 2022 and the recent unanchoring of Ethena's USDe and Abracadabra's MIM.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP