
Balance Coin (BLC) lost more than 99% of its value on Tuesday after decentralized finance platform 42DAO suffered an exploit that blockchain security firms estimate resulted in losses of roughly $915,000.
The attack sent BLC crashing from nearly $1 to just a fraction of a cent, marking another major DeFi security breach in 2026.
Oracle Flaw Enabled Instant Liquidations
Blockchain security firm PeckShield was the first to report the exploit, estimating losses of approximately $915,000. Security researchers at SlowMist later placed the figure at around $912,000 and identified the protocol’s Median Oracle as the source of the vulnerability.
According to SlowMist, the oracle supplied an abnormally low BTCB price to the protocol after the attacker invoked the Spotter contract’s poke function. Because the Spotter contract lacked critical safety mechanisms, including price deviation checks, maximum drawdown limits, and a minimum price threshold, the manipulated price was accepted without resistance.
Once the false price was recorded in the protocol’s accounting system, the Dog liquidation module immediately acted on it. With no delay or additional validation of oracle data, the attacker was able to trigger liquidations across multiple BTCB vaults within a single transaction.
Researchers identified the attacker’s wallet and the affected smart contracts while continuing to monitor the movement of the stolen funds.
BLC Price Collapses
The exploit triggered an immediate market selloff. According to GeckoTerminal data, BLC was trading near $0.0025 at the time of writing, representing a 99.75% decline from its previous price of roughly $0.997.
The token’s market capitalization has shrunk to around $12,000, while trading volume reached nearly $95,000 across more than 1,600 transactions. Most of those trades were buy orders, though heavy selling pressure continued to dominate price action.
DeFi Exploits Continue to Mount
The 42DAO incident adds to a growing list of decentralized finance hacks this year.
On July 20, cross chain stablecoin bridge Allbridge suspended operations after attackers exploited its liquidity pools and stole approximately $1.65 million through a flash loan based manipulation.
In June, Syscoin suffered a bridge exploit that enabled an attacker to mint up to 5 billion SYS tokens, sending the cryptocurrency down nearly 20%.
A month earlier, Echo Protocol halted cross chain transfers after an exploit involving the unauthorized minting of 1,000 eBTC. The incident also triggered a sharp decline of more than 12% in Echo’s native token.
Although each exploit involved different technical methods, the 42DAO attack highlights a recurring weakness across DeFi platforms. Rather than breaking encryption or compromising private keys, attackers continue to exploit inadequate safeguards surrounding oracle price feeds and liquidation mechanisms.#crypto#cryptonews https://coinsignals.net https://t.me/coinsignalpublic