BTCC / BTCC Square / Cryptopolitan /
Balance Coin Plunges 99% from $1 Peg as Oracle Exploit Drains $1M from Bitcoin Vault

Balance Coin Plunges 99% from $1 Peg as Oracle Exploit Drains $1M from Bitcoin Vault

Cryptopolitan
Release Time:
2026-07-22 19:40:17
0

Balance Coin (BLC) suffered a catastrophic 99% crash on Wednesday, dropping from its $1 dollar peg to as low as $0.0014, after an attacker manipulated its BTCB price oracle and drained approximately $912,000 from the project's treasury. The algorithmic stablecoin, designed to trade at exactly $1, had been hovering near par at $0.9954 just a day earlier. By late Wednesday, the exploit had wiped out nearly all of Balance Coin's $3.5 million nominal market value, with some trackers pricing the token closer to $0.0025. The incident highlights the persistent vulnerability of oracle-dependent stablecoins in decentralized finance.

A deceptive Bitcoin price that made safe vaults liquidation targets

Balance Protocol uses a maker-style setup. It lets users lock collateral, typically Bitcoin Cash (BCH), as well as Binance-pegged Bitcoin (BTCB) and USDT, and mint BLC against it. Once the value of that collateral drops way below the debt, the protocol instantly liquidates the position and sells the backing.

The theft was traced to the protocol’s Median Oracle by SlowMist, a security firm. Median Oracle is the price feed that informs the system of how much BTCB is worth. 

The attacker input an unusually low price into the feed via the ‘poke’ function on the Spotter’s contract and went on to trigger liquidations via the Dog module. In the words of SlowMist, the Spotter had no  time-weighted average price feed, a bounds check that could reject prices deviating far away from the market, and a liquidation delay 

Without those measures, safe vaults suddenly became insolvent, and the thief liquidated them at the fake price, walking away with the collateral all in one transaction.

Minted tokens routed directly through PancakeSwap

The theft continued beyond the vaults. The attacker minted ~4.5 million BLC from a null address via a corrupted GemJoin contract and those tokens to PancakeSwap V2, exchanging them for BSC-USD and BTCB; this converted freshly created coins into real assets. 

A second transaction was reported two hours later that minted 5,900 BLC. 

That wave of unbacked supply is what moved BLC off its target in real time. As the mechanism supposed to pin the peg was the same one the attacker used to break it. 

The CertiK audit missed the fault 

In the past, 42DAO had propped up the CertiK audit of its BLC minting contract as a mark of its security. However, that proved futile in this instance because while the audit was legit, standard smart-contract audits are looking for access-control errors, reentrancy, overflow, and coding flaws. 

They typically see oracle inputs as trusted instead of seeing them as modeling a manipulated price feed as an in-scope threat.

Despite OWASP listing oracle manipulation in its 2026 Smart Contract Top 10, the measures that could have prevented the attack are outside the typical audit scope. 

42DAO’s system had none of the following: 

  • A time-weighted average price feed 
  • A bounds check that could reject prices deviating far away from the market
  • A liquidation delay similar to MakerDAO’s one-hour Oracle Safety Module. 

The third BNB Chain protocol to go mute after an attack

Within the past two months, Wednesday’s incident became the third major DeFi security incident on BNB Chain. It is also the third incident where the team affected by the exploit stayed quiet. 

Late May, approximately $7.3 million was stolen from DxScale’s legacy liquidity lockers. Early in June, TesseraDAO lost roughly $2.5 million when an attacker stole 99 million TSR, pouncing on an admin-key compromise. 

This spate of attacks is consistent with a recent trend amongst attackers in 2026. Analysts noted that attackers are no longer looking to exploit code bugs but rather are focused on the oracles and governance layers around the code. 

These attacks also happen at a time the market has grown wary of algorithmic stablecoins, especially after the collapse of Terra’s UST in 2022 and more recently the depegs of Ethena’s USDe and Abracadabra’s MIM.

If you're reading this, you’re already ahead. Stay there with our newsletter.