시가 총액
24시간 볼륨
16099
암호화폐
58.54%
Bitcoin 공유

Balance Coin crashes from $1 peg as exploit drains $1M from Bitcoin vault

Balance Coin crashes from $1 peg as exploit drains $1M from Bitcoin vault


Cryptopolitan
2026-07-22 19:40:17

Balance Coin fell by ~99% on Wednesday, after an attacker distorted its BTCB price oracle and carted away with $912,000 out of the project’s treasury, losing almost all of its value. Balance Coin (BLC) is an algorithmic stablecoin tied to the dollar; it’s built to trade at $1 and nothing more. It traded at around $0.9954 on Tuesday, but by early Wednesday, it had dropped to a fraction of a cent, trading at around $0.0014, with some other trackers putting it closer to $0.0025. Either way, by late Wednesday, Balance Coin had lost almost all of its $3.5 million nominal value. A deceptive Bitcoin price that made safe vaults liquidation targets Balance Protocol uses a maker-style setup. It lets users lock collateral, typically Bitcoin Cash (BCH), as well as Binance-pegged Bitcoin (BTCB) and USDT, and mint BLC against it. Once the value of that collateral drops way below the debt, the protocol instantly liquidates the position and sells the backing. The theft was traced to the protocol’s Median Oracle by SlowMist, a security firm. Median Oracle is the price feed that informs the system of how much BTCB is worth. The attacker input an unusually low price into the feed via the ‘poke’ function on the Spotter’s contract and went on to trigger liquidations via the Dog module. In the words of SlowMist, the Spotter had no time-weighted average price feed, a bounds check that could reject prices deviating far away from the market, and a liquidation delay Without those measures, safe vaults suddenly became insolvent, and the thief liquidated them at the fake price, walking away with the collateral all in one transaction. Minted tokens routed directly through PancakeSwap The theft continued beyond the vaults. The attacker minted ~4.5 million BLC from a null address via a corrupted GemJoin contract and those tokens to PancakeSwap V2, exchanging them for BSC-USD and BTCB; this converted freshly created coins into real assets. A second transaction was reported two hours later that minted 5,900 BLC. That wave of unbacked supply is what moved BLC off its target in real time. As the mechanism supposed to pin the peg was the same one the attacker used to break it. The CertiK audit missed the fault In the past, 42DAO had propped up the CertiK audit of its BLC minting contract as a mark of its security. However, that proved futile in this instance because while the audit was legit, standard smart-contract audits are looking for access-control errors, reentrancy, overflow, and coding flaws. They typically see oracle inputs as trusted instead of seeing them as modeling a manipulated price feed as an in-scope threat. Despite OWASP listing oracle manipulation in its 2026 Smart Contract Top 10, the measures that could have prevented the attack are outside the typical audit scope. 42DAO’s system had none of the following: A time-weighted average price feed A bounds check that could reject prices deviating far away from the market A liquidation delay similar to MakerDAO’s one-hour Oracle Safety Module. The third BNB Chain protocol to go mute after an attack Within the past two months, Wednesday’s incident became the third major DeFi security incident on BNB Chain. It is also the third incident where the team affected by the exploit stayed quiet. Late May, approximately $7.3 million was stolen from DxScale’s legacy liquidity lockers. Early in June, TesseraDAO lost roughly $2.5 million when an attacker stole 99 million TSR, pouncing on an admin-key compromise. This spate of attacks is consistent with a recent trend amongst attackers in 2026. Analysts noted that attackers are no longer looking to exploit code bugs but rather are focused on the oracles and governance layers around the code. These attacks also happen at a time the market has grown wary of algorithmic stablecoins, especially after the collapse of Terra’s UST in 2022 and more recently the depegs of Ethena’s USDe and Abracadabra’s MIM. If you're reading this, you’re already ahead. Stay there with our newsletter .


면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.