Balance Coin, an algorithmic stablecoin designed to hold a $1 peg, crashed more than 99% to roughly $0.0014 on Wednesday after an attacker drained about $912,000 from its protocol through a manipulated price oracle. The token erased nearly all of its roughly $3.5 million in nominal value in a single transaction.
According to security firm SlowMist, the attacker wrote an abnormally low Bitcoin price into Balance Protocol's oracle. The lending contract accepted the write without validating it against an accurate range and without any liquidation delay, letting the attacker instantly liquidate multiple collateralized vaults that should never have qualified, then swapped the seized Bitcoin-backed collateral for profit. Most of the loss fell on 42DAO, the governance entity behind the protocol, rather than on retail holders.
Why it matters
The exploit is small in dollar terms, but the mechanism is the part every lending desk reads. An unguarded oracle write that triggers instantaneous liquidations with no sanity-check range is a primitive failure mode, the kind that has cost DeFi protocols hundreds of millions cumulatively over the past three years. Balance's design, where users lock BTC-backed collateral to mint a dollar-pegged token, inherits all the oracle risk of a Bitcoin lending book while sitting inside a low-circulation stablecoin that lacked the liquidity depth to absorb the forced selling.
Market impact
Balance Coin was a long-tail project with minimal liquidity, so contagion to the broader stablecoin complex is near zero. The durable read is reputational: algorithmic stablecoins continue to break the same way, via price-feed manipulation followed by cascading liquidations, and SlowMist's involvement keeps the post-mortem visible to institutional underwriters now mapping DeFi counterparty risk.
Frequently asked questions
-
What happened to Balance Coin on Wednesday?
Balance Coin, an algorithmic stablecoin designed to hold a $1 peg, collapsed more than 99% to roughly $0.0014 after an attacker exploited a pricing flaw in Balance Protocol. Most of the roughly $912,000 loss hit 42DAO, the project's governance entity.
-
How did the attacker drain the vaults?
According to SlowMist, the attacker wrote an abnormally low Bitcoin price into the protocol's oracle. The lending contract accepted the write without validating it against an accurate range and without any liquidation delay, letting the attacker instantly liquidate vaults that should not have qualified.
-
What is Balance Coin and how does it work?
Balance Coin is a low-circulation algorithmic stablecoin. Users lock Bitcoin-backed collateral into vaults to mint the token, which is designed to hold a $1 peg. If collateral value drops too far, vaults are supposed to be liquidated under controlled conditions.
-
How much did the attacker actually profit?
The attacker's net profit was around $912,000, drained primarily from 42DAO, the governance entity behind Balance Protocol. The token itself lost nearly all of its roughly $3.5 million in nominal value as the price collapsed.
-
Is the exploit likely to spread to other stablecoins?
Contagion to the broader stablecoin complex is near zero because Balance Coin was a long-tail project with minimal liquidity. The durable concern is the failure pattern itself: unguarded oracle writes and instant liquidations remain a known weak point for BTC-collateralized lending books.
CoinDesk