Key highlights:

  • Balance Coin has been depegged following the $915k protocol attack. 
  • The BLC coin dropped by around 99% as attackers exploited the protocol’s Bitcoin price oracle.
  • The event highlights the growing number of security issues in the DeFi space.

Balance Coin (BLC), an algorithmic stablecoin built on BNB Chain, has been depegged, falling by more than 99% after a $915k exploit. According to the findings of SlowMist, the attacker exploited a vulnerability in the Balance Protocol’s Bitcoin price oracle.  The incident has raised fresh concerns about the security of decentralized finance (DeFi) platforms.

What caused the 99% Balance Coin crash?

On July 22, 2026, the crypto market witnessed another major DeFi exploit. Attackers have reportedly taken advantage of a brief oracle failure in the Balance Protocol and exploited the 42DAO protocol, draining around $912,000.

In an X post, blockchain security firm Slowmist shared the root cause of the DeFi exploit. The platform noted that the attacker exploited a flaw in Balance Protocol’s Bitcoin-backed (BTCB) price oracle. They manipulated the oracle and reported an artificially low BTCB price. Via this strategy, the attackers made the protocol believe that BTCB-backed vaults had fallen below the required collateral level.

As a result, the Balance Coin lost its dollar peg, dropping from $1 to nearly zero. Although the BLC token is designed to remain pegged to the dollar, maintaining a value of $1, the latest Balance protocol hack has depegged it. 

At press time, the Balance Coin is trading at $0.0006849, marking a massive fall of 99.9%. The current value represents only a fraction of the token’s intended price. While the stablecoin has slightly recovered from the intraday low, it is still down by more than 99%.

How did the Balance protocol exploit take place?

Notably, security firm TenArmor identified two suspicious transactions on the BNB Chain. The firm revealed that these transactions are apparently linked to GemJoin and 42DAO. As per the findings, the attacker initially minted about 4.5 million BLC tokens from a null address. Later, they moved them to PancakeSwap V2.

Soon, the attacker swapped the newly created BLC tokens for Binance-Peg USDT (BSC-USD) and Binance Bitcoin (BTCB). This highlights the attacker’s tactics of converting the tokens into other digital currencies. They repeated the process after a few hours, minting another batch of Balance Coins and accumulating more funds.

The security research platforms added that the DeFi hack was executed due to the protocol’s lack of some security features. The protocol has no safety features like price deviation checks, minimum price limits, and delay before liquidations. Thus, the attacker was able to mint Balance Coin without these security checks.

Unveiling rising DeFi exploits

It is worth noting that the Balance Coin hack is only one of the growing number of DeFi exploits that expose weaknesses in smart contracts, bridges, or oracle systems. The latest incident highlights the intensity of such exploits, which can result in massive losses.

In recent months, the crypto industry has witnessed a lot of security issues. For instance, in May, MAPO lost 96% of its value, driven by unauthorized minting. Due to a flaw in the platform’s cross-chain bridge, the attackers were able to mint and drain tokens. Another case is the Stake DAO hack, where attackers minted trillions of vsdCRV tokens.