Balance Coin Falls Nearly 99% After Oracle Exploit Drains $912,000 From Treasury
Key Takeaways
- •Balance Coin plummeted approximately 99% after an attacker manipulated the protocol's BTCB price oracle to steal $912,000 from the treasury.
- •The exploit succeeded because the Spotter contract lacked a time-weighted average price feed, deviation bounds checks, and a liquidation delay mechanism.
- •The attacker minted approximately 4.5 million unbacked BLC tokens through a compromised GemJoin contract and converted them into real assets via PancakeSwap V2.
- •A CertiK audit of the BLC minting contract had been cited as evidence of security but did not identify oracle manipulation as a threat vector.
- •This was the third major DeFi security incident on BNB Chain in two months, following exploits at DxScale and TesseraDAO, with all three affected teams remaining silent afterward.

Balance Coin (BLC) plunged by about 99% on Wednesday after an attacker manipulated the protocol's BTCB price oracle and removed $912,000 from the project's treasury, leaving the token with almost no remaining value.
BLC is an algorithmic stablecoin designed to track the U.S. dollar and trade at $1. The token was priced at about $0.9954 on Tuesday, but by early Wednesday it had fallen to a fraction of a cent. It was trading near $0.0014, while some other trackers placed the price closer to $0.0025.
By late Wednesday, Balance Coin had lost nearly all of its $3.5 million nominal value.
Manipulated BTCB price turned safe vaults into liquidation targets
Balance Protocol operates with a Maker-style structure. Users can lock collateral, typically Bitcoin Cash (BCH), Binance-pegged Bitcoin (BTCB), and USDT, and mint BLC against that collateral. When the value of the collateral falls far below the debt attached to a position, the protocol liquidates the position and sells the backing assets.
Security firm SlowMist traced the theft to the protocol's Median Oracle, the price feed that tells the system how much BTCB is worth.
According to the reported findings, the attacker submitted an unusually low price through the "poke" function on the Spotter contract, then triggered liquidations through the Dog module. SlowMist said the Spotter lacked a time-weighted average price feed, a bounds check capable of rejecting prices that deviate sharply from the market, and a liquidation delay.
Time-weighted average price, or TWAP, feeds smooth out short-term price spikes by averaging values over a set window, making it harder for a single transaction to move the reported price. They are used across major DeFi platforms including Uniswap and by oracle networks like Chainlink. Without such protections or a deviation threshold, vaults that had previously been safe suddenly appeared insolvent. The attacker was then able to liquidate them using the false price and take the collateral in a single transaction.
Minted BLC was routed through PancakeSwap
The exploit did not stop with the vault liquidations. The attacker also minted about 4.5 million BLC from a null address through a compromised GemJoin contract and sent the tokens to PancakeSwap V2, where they were exchanged for BSC-USD and BTCB. That step converted newly created tokens into real assets.
A second transaction, reported two hours later, minted another 5,900 BLC.
The influx of unbacked supply pushed BLC away from its intended target in real time. The mechanism intended to maintain the peg became the same mechanism used to break it.
CertiK audit did not catch the issue
42DAO had previously highlighted a CertiK audit of its BLC minting contract as evidence of the system's security. In this case, the audit did not prevent the exploit. Standard smart contract audits typically focus on access-control failures, reentrancy, overflow issues, and coding defects.
Such audits often treat oracle inputs as trusted rather than modeling a manipulated price feed as an in-scope threat. The distinction matters because oracle manipulation has been a recurring vector in DeFi thefts, and multiple past exploits have traced losses to price feeds that audits treated as reliable inputs.
Although OWASP lists oracle manipulation in its 2026 Smart Contract Top 10, the controls that could have prevented this attack are often outside the usual audit scope.
42DAO's system did not have the following safeguards:
- A time-weighted average price feed
- A bounds check that could reject prices deviating far from the market
- A liquidation delay similar to MakerDAO's one-hour Oracle Safety Module
Third BNB Chain protocol to go silent after an attack
The Wednesday incident was the third major DeFi security event on BNB Chain in the past two months. It was also the third case in which the team affected by the exploit stayed quiet.
In late May, about $7.3 million was stolen from DxScale's legacy liquidity lockers. In early June, TesseraDAO lost roughly $2.5 million after an attacker stole 99 million TSR through an admin-key compromise.
The series of attacks aligns with a trend observed by analysts in 2026: attackers are increasingly targeting oracle and governance layers around protocols rather than only looking for bugs in code.
The incidents also come as the market remains cautious toward algorithmic stablecoins, following the collapse of Terra's UST in 2022 and more recent depegs involving Ethena's USDe and Abracadabra's MIM.