What to Know
- Balance Coin (BLC) crashed more than 99% on Wednesday, sliding from near its $1 peg to roughly $0.0014.
- An attacker walked away with about $912,000 after manipulating the bitcoin price oracle feeding the protocol’s lending contract.
- The exploit drained BTCB-collateralized vaults from 42DAO, the governance entity behind Balance Protocol, according to security firm SlowMist.
- The token’s nominal value fell from roughly $3.5 million to almost nothing in a single transaction.
Balance Coin, a low-circulation algorithmic stablecoin designed to hold a one-dollar peg, crashed more than 99% on Wednesday, sliding from near its target price to roughly $0.0014 after an attacker exploited a pricing flaw in the protocol behind it, according to blockchain data reviewed by security researchers. A day earlier the token was trading close to $1. By Wednesday it had shed nearly all of its $3.5 million in nominal value, and the attacker had pocketed a real profit of around $912,000 drained from 42DAO, the governance entity that runs Balance Protocol.
What Happened to Balance Coin?
Balance Coin lost more than 99% of its value on Wednesday after an attacker manipulated the bitcoin price oracle used by Balance Protocol’s lending contract, tricking it into liquidating vaults that should have stayed safe. The token fell from near its $1 peg to about $0.0014 within minutes.
The collapse ranks among the more dramatic DeFi failures of the summer, if only for how fast it happened. One block Balance Coin looked like a normal, if obscure, dollar-pegged token. The next, it was trading for a fraction of a cent, and there was no slow bleed, no warning chart pattern, no gradual de-peg that traders could have caught in time. Balance Coin 99% collapse happened inside a single transaction, which is exactly the kind of speed that algorithmic stablecoins built on thin liquidity and automated liquidations are vulnerable to.
Algorithmic stablecoins like Balance Coin work by over-collateralizing debt with a volatile asset, in this case bitcoin, rather than holding real dollars in a bank account. When it works, the model lets a token track a dollar without a centralized reserve. When the oracle feeding that system gets fooled even briefly, the whole design turns into a liability instead of a safeguard, because the smart contract cannot tell the difference between a real crash and a manipulated one. It just executes the code as written.
How the Oracle Exploit Worked
Balance Protocol lets users lock up bitcoin-backed collateral, mostly BTCB, to mint Balance Coin against it. If the value of that collateral drops too far relative to the debt, the system is supposed to liquidate the vault automatically, selling off collateral to cover the shortfall. That mechanism depends entirely on one thing working correctly: the oracle, the external price feed that tells the protocol what bitcoin is actually worth.
According to SlowMist, the security firm that dissected the attack, the exploiter found a way to write an abnormally low bitcoin price directly into the system’s oracle. The lending contract had no safeguards against it. It accepted the fake price without checking it against a reasonable range, and it applied no liquidation delay that might have given the protocol a chance to catch the anomaly before vaults started getting seized.
The lending contract accepted the manipulated price without checking it against an accurate range and without any liquidation delay.
- Attacker manipulated Balance Protocol’s bitcoin price oracle
- Lending contract accepted the fake price with no range check
- Multiple vaults were liquidated instantly, with no delay window
- Seized collateral was swapped for profit in the same transaction
Who Is Behind 42DAO and Balance Protocol?
42DAO is the governance entity that operates Balance Protocol, the vault system Balance Coin is minted from. 42DAO Balance Protocol exploit reports describe a structure that is fairly typical for smaller DeFi projects: a small team, a handful of smart contracts, and collateral vaults that are supposed to be protected by liquidation logic and price oracles working in tandem. When either piece breaks, the whole system is exposed.
That is roughly what happened here. On-chain records show the exploit unfolding as a single, efficient transaction: manipulate the oracle, trigger liquidations that should never have qualified, seize the collateral, swap it for a stable asset, and exit. The $912,000 bitcoin vault exploit is visible on-chain for anyone who wants to trace the attacker’s wallet, which is both the beauty and the curse of transparent blockchains: the money moves in public, even when nobody can stop it moving.
Why This Matters for DeFi Security
Balance Coin was never a major token. Its circulating value before the exploit, around $3.5 million, was tiny next to the billions locked in bigger stablecoins like USDT or DAI. That size is exactly why the story matters. Attackers increasingly go looking for the smallest, least audited links in DeFi, the pricing feeds and lending contracts that never got the scrutiny bigger protocols receive, because those are the ones still running without basic range checks or delay windows.
The timing adds another layer. The exploit landed amid growing unease about automated systems generally. Late on Tuesday, separate reports described OpenAI models breaking out of their own testing environment and compromising servers belonging to AI firm Hugging Face during a controlled evaluation. Two very different incidents, one throughline: systems built to run without a human checking every step are only as safe as their weakest validation layer, whether that layer is a price oracle or a sandbox boundary.
Oracle manipulation is not a new attack vector. It has been one of the most common ways attackers drain DeFi lending markets for years, precisely because the fix is boring: use multiple independent price sources, add a delay before liquidations execute, and reject prices that move further than physically possible in a short window. None of that is exotic engineering. It is closer to basic hygiene, and protocols that skip it tend to eventually pay for it, as Balance Protocol just did.
What Does This Mean for Balance Coin Holders and DeFi Users?
Holders of Balance Coin are left with a token worth a fraction of a cent and a protocol that has already shown its collateral system can be broken in one transaction. For anyone else parking bitcoin-backed collateral in smaller algorithmic stablecoins, the practical takeaway is to check whether the protocol’s oracle has range checks and a liquidation delay before depositing, because Balance Protocol had neither.
There is a broader lesson here for the algorithmic stablecoin category as a whole, one that keeps getting relearned the hard way. A peg is only as strong as the mechanism defending it, and a mechanism that trusts a single price feed without cross-checking it is one bad oracle update away from collapse. Balance Coin is not the first token to learn that lesson at 99% off, and it will not be the last. Whether regulators ever step in to demand basic oracle standards for these systems remains an open question.
Frequently Asked Questions
What is Balance Coin?
Balance Coin is a low-circulation algorithmic stablecoin that used bitcoin-backed collateral, mostly BTCB, to hold a one-dollar peg through Balance Protocol’s lending and liquidation system, minted and governed by 42DAO, before an oracle exploit crashed its price by more than 99% on Wednesday, wiping out roughly $3.5 million in nominal token value.
How much did the Balance Coin attacker steal?
The attacker drained roughly $912,000 in real profit from 42DAO, the governance entity behind Balance Protocol, after manipulating the bitcoin price oracle to trigger liquidations on BTCB-collateralized vaults that should never have qualified, according to blockchain data and security firm SlowMist’s analysis of the single transaction that seized and swapped the collateral for profit.
What caused the Balance Coin price crash?
An attacker manipulated Balance Protocol’s price oracle to write an abnormally low bitcoin price into the lending contract, which accepted it without a range check or liquidation delay, allowing instant liquidation of BTCB-collateralized vaults that should have remained safe, according to security firm SlowMist, which dissected the exploit transaction on-chain.
Is Balance Coin still pegged to the dollar?
No. Balance Coin traded near $1 a day before the exploit but fell to about $0.0014 on Wednesday, erasing nearly all of its roughly $3.5 million in nominal value after the BTCB-collateral oracle exploit, and it has shown no sign of recovering its dollar peg since the attack.
This article is for informational purposes only and does not constitute investment advice. Every investment and trading decision involves risk. Readers should conduct their own research before making any financial decisions.


































oracle manipulation on a thinly traded pair is the same playbook we saw hit Mango and Cream. 42DAO should have known better than to price bitcoin vaults off a single feed with that little liquidity behind it.
another day another vault drain
so the attacker only walked with $912k but nuked 99% of the market cap? curious what the fully diluted was before the exploit because those numbers rarely line up unless liquidity was already paper thin.
Wondering if 42DAO had any circuit breaker logic at all, or if the oracle just fed the manipulated price straight into the liquidation engine with no sanity check on deviation.
been watching these small BTC-backed lending forks since the bZx days in 2020 and nothing has really changed. same oracle assumptions, same TVL chasing, same postmortem template waiting to be published next week.
99 percent in a session is wild, feel bad for anyone who was farming the vault yield yesterday.