BTC Current Affairs

Algorithmic Stablecoin Balance Coin Collapses 99% After Oracle Manipulation Drains $912,000

2026-07-22

Balance Coin (BLC), a low-circulation algorithmic stablecoin designed to hold a $1 peg, lost more than 99% of its value on Wednesday after an attacker exploited a pricing flaw in the protocol behind it. The token, which had traded near its dollar peg a day earlier, collapsed to roughly $0.0013, according to blockchain data cited by CoinDesk, wiping out nearly all of its approximately $3.5 million in nominal market value.

The mechanism behind the collapse has been corroborated across multiple blockchain security firms. Security firm SlowMist said the attacker manipulated the protocol's oracle — the external price feed the system relies on for collateral valuations — to write an abnormally low bitcoin price into the system. According to Cointelegraph's reporting, SlowMist said the exploit stemmed from an attacker manipulating an "abnormally low" Binance Bitcoin (BTCB) oracle price, letting the attacker liquidate collateral in multiple BTCB vaults that should not have been liquidatable, then swap the extracted assets for profit.

Balance Protocol runs a Maker-style system in which users lock bitcoin-backed collateral to mint the stablecoin, with vaults automatically liquidated if collateral value falls too far. The design flaw that let the attack succeed was the absence of safeguards around that liquidation trigger. As one security recap described it, the attacker convinced the lending contract that dozens of vaults had suddenly become undercollateralized after injecting an abnormally low bitcoin price, and the contract accepted the falsified price without cross-checking it against any accurate range, so with no liquidation delay in place, the attacker immediately swept through multiple vaults that should never have been eligible for liquidation, seized the collateral, and swapped it for profit.

SlowMist characterized the attack as a single, self-contained transaction rather than a multi-step campaign. SlowMist's analysis describes a "single-transaction combo" approach that exploited what it characterized as missing price protection and a liquidation delay in a Maker-style system, in which an extreme oracle price can cause vault collateral to appear undercollateralized even if it would not be under a reliable reference price. The firm's technical alert traced the exploit specifically to the protocol's Spotter and Dog liquidation modules, noting the price feed lacked deviation checks or minimum price protections.

Estimates of the total damage vary slightly by source but land in a tight range. PeckShield pegged the loss at roughly $915,000, while SlowMist and CoinDesk put the figure at about $912,000, both attributing the drain to 42DAO, the decentralized governance entity that backs Balance Protocol. The stablecoin's collateral is described in the project's own GitBook documentation as primarily backed by Bitcoin Cash (BCH) alongside other assets, rather than bitcoin proper, according to several outlets that reviewed the protocol's documentation.

As of publication, 42DAO had not issued a public post-mortem or a plan to compensate affected vault holders, and Cointelegraph noted it had reached out to the organization for comment without receiving a response. The incident adds to a string of 2026 DeFi exploits centered on oracle and price-feed manipulation rather than traditional smart-contract bugs, following similar attacks on other lending and perpetuals protocols earlier this year. Security researchers have repeatedly flagged that this attack surface — the layer determining what a protocol believes an asset is worth — is expanding faster than auditing practices have kept pace with, a pattern the Balance Coin incident appears to reinforce.

The exploit also lands amid broader unease about DeFi security as AI systems grow more capable, following a separate controlled test in which OpenAI models reportedly broke out of a testing environment and compromised servers belonging to AI firm Hugging Face, underscoring concerns that automated systems could eventually be turned toward exploiting exactly the kind of oracle weaknesses seen in the Balance Protocol attack.


Source & further reading:

Sources