42DAO’s BLC Stablecoin Depegs to Near Zero After $912K Oracle Exploit

42DAO’s BLC Stablecoin Depegs to Near Zero After $912K Oracle Exploit

AI Summary

Show

42DAO’s protocol was exploited due to a flaw in its oracle system, causing BLC to collapse from its $1 peg to around $0.0013
Security firms SlowMist and PeckShield identified the attacker’s manipulation of the oracle price as the key factor in the exploit
The incident highlights 42DAO’s failure to implement sufficient safety measures, unlike MakerDAO, which has safeguards in place to prevent such attacks

Balance Coin (BLC), a stablecoin designed to be worth one dollar and created by the DeFi platform 42DAO, suddenly lost almost all its value – dropping to around $0.0013. This happened because someone exploited a weakness in how the protocol received price data (its ‘oracle’), resulting in about $912,000 being stolen, according to blockchain security experts.

The Depeg

BLC, a cryptocurrency intended to be worth $1, lost almost all of its value in just one day – dropping by about 99%, according to PeckShield. After this sudden crash on the BNB Chain, the token was trading for around $0.001357, meaning it’s no longer holding its expected price.

Security researchers at PeckShield have detected a significant drop in the value of Balance Coin ($BLC). It appears that $915,000 worth of funds have been stolen from @42dao_official.

— PeckShieldAlert (@PeckShieldAlert) July 22, 2026

As a crypto investor, I’m tracking this recent hack, and estimates put the losses between $912,000 and $915,000. Security firms like SlowMist and PeckShield have both given figures in that range, so that’s what we’re looking at right now.

This significant loss of its stable value is different from a typical price drop for a fluctuating cryptocurrency. BalanceCoin (BLC) is the foundation of the Balance Protocol, a stablecoin created when users deposit assets like Bitcoin, Ethereum, and Bitcoin Cash as collateral. When the system designed to maintain its stable value fails, the token doesn’t just become cheaper – it loses its core function as a stablecoin.

How the Exploit Worked

The attack didn’t exploit a flaw in the token’s code itself; instead, it targeted how the system calculated prices and handled liquidations. SlowMist’s investigation revealed the attacker manipulated the price of BTCB using a faulty price feed (Median Oracle). They forced a false market price into the system through specific functions called ‘Spotter poke’ and ‘Dog bark’.

The problem stemmed from a lack of safety measures. According to SlowMist, the Spotter component didn’t have proper checks to prevent extreme price differences, limit potential losses, or establish a minimum price. This allowed a manipulated, very low price to be accepted instantly. The system then used this incorrect price to trigger liquidations immediately, without any delays for verification or confirmation from other sources.

The attacker was able to close several loan positions backed by BTCB in one go, using the artificially inflated price. This allowed them to profit from the difference between the fake price and the actual value of the collateral. Security firm SlowMist explained that this was a single transaction that took advantage of a lack of price safeguards and a missing delay mechanism in the system, which functions similarly to MakerDAO. The transaction details are publicly available on the blockchain (tx: 0xe7abe6416…).

A MakerDAO Fork Without MakerDAO’s Safeguards

The names of the parts within this system – specifically ‘Spotter poke’ and ‘Dog bark’ – come directly from the way MakerDAO is built. This shows that 42DAO created its system by copying MakerDAO’s existing framework for managing loans and collateral.

The key issue wasn’t what the system *did*, but what it *didn’t* protect against. MakerDAO is designed with safeguards – a system that slows down price updates and checks for unrealistic price changes – to prevent liquidations caused by sudden, unexpected market shifts. The security firm SlowMist identified an attack that specifically bypasses these safeguards. The attacker created a copy of MakerDAO’s liquidation system but didn’t include the security features that were meant to prevent this type of exploit.

This type of Oracle attack isn’t new. We’ve seen similar attacks on Binance Smart Chain lending platforms for years. The usual way to protect against these attacks – using average prices over time or delaying actions based on price changes – is well-known. Any system that immediately reacts to a single price without checking its validity will always be vulnerable.

Part of a Broader Pattern

As a crypto investor, I’ve noticed a worrying pattern in DeFi hacks lately. It’s no longer just about flaws in the smart contract code itself. Instead, attackers are increasingly targeting the systems *around* the code – things like the oracles that provide price data, the rules governing how projects are managed, and the underlying infrastructure. We’ve already seen this play out with Ostium Perpetuals, where manipulated oracle reports led to a major drain, and with Bonzo, which was exploited through a fake price feed from a third-party oracle. It seems these peripheral systems are becoming the weak point.

What’s becoming clear is that weaknesses are increasingly found in the parts of systems deciding an asset’s value, not just how those assets are transferred. Security reviews throughout the year have consistently shown this area of risk is growing more quickly than security checks can keep up with.

As of this writing, 42DAO hasn’t released any public information about the incident or how they plan to address it. Those holding the stablecoin, which is now worth significantly less than one cent, are finding that the very system designed to restore its value to one dollar is the one that was compromised in the attack.

2026-07-22 10:35