Loading market data...

Balance Coin Crashes 99.5% After 42DAO Exploit Drains $915,000

Balance Coin Crashes 99.5% After 42DAO Exploit Drains $915,000

Balance Coin (BLC) lost more than 99% of its value this week after an exploit on the DeFi protocol 42DAO drained roughly $915,000 from the platform. Blockchain security firm PeckShield first flagged the attack, and SlowMist later put the loss closer to $912,000. The crash sent BLC from around $0.997 to $0.0025 — a 99.75% drop in 24 hours.

How the exploit worked

The root cause was 42DAO's Median Oracle, which fed an abnormally low BTCB price into the system. The attacker used the Spotter poke function to write that manipulated price into the VAT contract. The Spotter lacked basic safeguards: no price deviation checks, no maximum drawdown limits, and no minimum price floor protections. The Dog module, which handles liquidations, had no liquidation delay or oracle price validation — so liquidations happened instantly once the false price was in place.

Security researchers identified the attacker's wallet as 0x9d8d...231c and the victim contract as 0x973a...a9c0c. The exploited Spotter and Dog contracts were 0x849d...29288 and 0x0010...1f634e.

The aftermath for BLC

BLC's market cap collapsed to about $12,000. Trading volume hit $94,900 across more than 1,600 transactions — over 1,000 of them buys, likely from traders trying to catch a dead-cat bounce or bots scooping up near-zero tokens. The token is now effectively worthless.

A pattern of missing safeguards

42DAO is the latest in a string of DeFi and bridge exploits in 2026. Earlier this year, Allbridge lost $1.65 million, Syscoin saw 5 billion SYS tokens drained, and Echo Protocol had 1,000 eBTC stolen. What these attacks share isn't broken cryptography or stolen private keys — it's missing safeguards around price feeds and liquidations. The 42DAO exploit followed that same blueprint: no deviation checks, no drawdown limits, no liquidation delays.

The industry keeps learning the same lesson the hard way. Until protocols build in basic circuit breakers, oracle manipulation will remain a cheap and effective attack vector.