BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
DeFi

Balance Coin collapses 99% after $912,000 exploit, loses dollar peg

Balance Coin, an algorithmic stablecoin designed to maintain a fixed value of $1, plummeted by approximately 99% on Wednesday after a major security breach. The attack resulted in the loss of

AnonymousCryptoCompass newsroom
July 22, 2026
4 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for defi coverage.

Balance Coin, an algorithmic stablecoin designed to maintain a fixed value of $1, plummeted by approximately 99% on Wednesday after a major security breach. The attack resulted in the loss of $912,000 from the project’s treasury, wiping out nearly its entire $3.5 million nominal value.

Algorithmic stablecoin loses peg after exploit

Balance Coin (BLC) is a stablecoin built on an algorithmic model and aimed at consistently trading close to the US dollar. Before the incident, BLC was trading at around $0.9954. However, by early Wednesday, its price had plunged to between $0.0014 and $0.0025, according to several tracking services.

This sharp decline followed a targeted exploit that manipulated the project’s BTCB price oracle. By late Wednesday, BLC had lost nearly all of its market value.

Security flaw exploited via distorted oracle

The Balance Protocol operates a lending and minting system reminiscent of MakerDAO, allowing users to lock up assets such as Bitcoin Cash (BCH), Binance-pegged Bitcoin (BTCB), and USDT in order to mint new BLC tokens. When collateral falls below a required threshold, the protocol automatically liquidates the position and sells the collateral.

SlowMist, a blockchain security firm, traced the exploit to the protocol’s Median Oracle, which supplies BTCB price data. The attacker set an abnormally low price for BTCB using the Spotter contract’s ‘poke’ function, then triggered liquidations through the Dog module. SlowMist noted the Spotter module lacked safeguards such as a time-weighted average price, deviation bounds checking, or a liquidation delay.

SlowMist observed that the protocol’s absence of critical security features allowed an attacker to liquidate secure vaults by submitting a manipulated price, collecting the collateral in a single transaction.

Without these protections, the system quickly became vulnerable, making previously safe vaults suddenly appear insolvent and allowing the thief to claim the locked assets.

Mini dictionary: Oracle, a mechanism that provides external data (such as asset prices) to smart contracts, playing a crucial role in decentralized finance platforms’ operations.

Attacker mints tokens and converts to real assets

The exploitation did not stop with liquidations. Using a compromised GemJoin contract, the attacker minted around 4.5 million BLC tokens from a null address and promptly swapped them on PancakeSwap V2 for BSC-USD and BTCB, turning freshly created BLC into tangible cryptocurrencies.

A second similar transaction occurred two hours later, minting an additional 5,900 BLC. The sudden influx of unbacked tokens disrupted BLC’s peg in real time, as the mechanism intended to hold its dollar value was turned against the system itself.

Mini dictionary: PancakeSwap, a decentralized exchange protocol on the BNB Chain that allows swapping of BEP-20 tokens without intermediaries.

Security audit limitations and repeated BNB Chain attacks

42DAO, the team behind Balance Coin, had previously relied on a CertiK audit of its minting contract as a symbol of security. CertiK is a well-known blockchain security auditor. However, these audits generally focus on bugs such as coding or access control issues, and often treat oracle-price feeds as trusted inputs, overlooking the risk of manipulated data feeds.

Despite Oracle manipulation being highlighted by OWASP’s 2026 Smart Contract Top 10, such attacks typically fall outside standard audit scopes. Balance Coin’s system lacked a time-weighted average price feed, deviation bounds checking, and did not implement a liquidation delay similar to the one-hour Oracle Safety Module used by MakerDAO.

While the system underwent a legitimate audit, its lack of key security measures made it vulnerable to manipulation through the price oracle, which was not considered within the standard audit’s scope.

Security FeatureImplemented by Balance CoinImplemented by MakerDAOTime-weighted average price feedNoYesDeviation bounds checkingNoYesLiquidation delay (Oracle Safety Module)NoYes (1 hour)

The Balance Coin incident is the third significant DeFi exploit on BNB Chain in the past two months. In late May, around $7.3 million was stolen from DxScale’s legacy liquidity lockers, and in early June, TesseraDAO suffered a $2.5 million loss due to an admin-key compromise. In all three incidents, affected teams remained silent following the attacks.

Recent analyst commentary points out that attackers are increasingly targeting vulnerabilities in governance structures and data oracles, rather than searching for coding bugs.

Growing instability in algorithmic stablecoins has become more evident after prominent failures including the collapse of Terra’s UST in 2022, as well as repeated depegs affecting Ethena’s USDe and Abracadabra’s MIM.

The post Balance Coin collapses 99% after $912,000 exploit, loses dollar peg appeared first on COINTURK NEWS.