Balance Coin Collapses 99% After $915K 42DAO Exploit From Governance Vulnerability

First transaction minted about 4.5 million BLC from a null address and, roughly two hours later, a second mint of 5,900 BLC. The attacker then moved the newly created tokens to PancakeSwap V2 and swapped them for Binance-pegged USDT (BSC-USD) and BTCB.
The exploit leveraged GemJoin interactions and a vulnerability in 42DAO governance/minting to bypass normal supply rules, enabling the minting of unbacked BLC tokens.
PancakeSwap V2 served as the exit liquidity route, with the attacker flooding the exchange and draining liquidity pools to extract BSC-USD and BTCB from the ecosystem.
Security researchers described the attack as using flash loan contracts to manipulate collateralization and as concealing funds via Tornado Cash; later open-source post-mortems cited a vault-code weakness tied to OpenZeppelin’s analysis.
Analysts note the contagion risk from Balance Coin is unlikely due to its small pre-collapse market cap (around $3.5 million), underlining that such vulnerabilities still pose systemic risks for algorithmic stablecoins albeit on a limited scale.
Balance Coin (BLC), an algorithmic stablecoin designed to track the U.S. dollar, collapsed by more than 99% after a suspected exploit drained roughly $915,000 from 42DAO, the decentralized organization tied to Balance Protocol, according to Crypto.news. The attack unfolded on the BNB Chain and wiped out nearly the token's entire market value in a matter of hours.
Security researchers at PeckShield and TenArmor traced the attack to vulnerabilities in 42DAO's governance and minting mechanics, as Blazetrends reported. The attacker minted millions of unbacked BLC tokens, flooded liquidity pools on PancakeSwap, and walked away with Binance-pegged USDT and BTCB.
The exploit began when the attacker minted roughly 4.5 million BLC from a null address — essentially creating tokens backed by nothing, according to Crypto.news. About two hours later, a second mint produced another 5,900 BLC. Both batches were moved directly to PancakeSwap V2, a popular decentralized exchange on BNB Chain.
The attacker leveraged a weakness in 42DAO's GemJoin interactions, which are smart contract components that handle collateral deposits, Blazetrends reported. This let them bypass normal supply rules entirely. The flood of unbacked BLC into PancakeSwap pools instantly crushed the token's dollar peg and triggered a wave of selling pressure.
Once the attacker had millions of worthless BLC tokens, they swapped them on PancakeSwap V2 for real assets: BSC-USD, which is Binance-pegged USDT, and BTCB, which is Binance-pegged Bitcoin, according to Bloomingbit. This drained the exchange's liquidity pools and converted fabricated tokens into legitimate crypto worth about $915,000.
Head Topics reported the attacker also manipulated a Binance BTCB oracle price — the price feed that protocols rely on to value assets — to force liquidations. Flash loan contracts were used to manipulate collateralization ratios. Funds were later obscured through Tornado Cash, a crypto mixing service that hides transaction trails.
Before the attack, BLC had a market cap of around $3.5 million — a small figure even by DeFi standards, according to Crypto.news. The token lost virtually all of that value within hours. Algorithmic stablecoins use code and financial incentives instead of real dollar reserves to hold their price. That model has a long history of catastrophic failures.
Grafa noted that Balance's model, which backs BLC with Bitcoin, was not enough to protect it once the minting mechanics were compromised. Analysts said contagion to wider markets is unlikely given BLC's tiny size. But the collapse is a sharp reminder that a vulnerability in a related DAO can destroy a token's value almost instantly.
PeckShield and TenArmor both flagged the attack shortly after it happened, pointing to vault-code weaknesses linked to governance contract flaws, Blazetrends reported. Post-mortem analyses cited code vulnerabilities connected to OpenZeppelin, a widely used smart contract security library. The speed of the exploit — two minting waves in under two hours — left little time for any response.
The BLC collapse joins a growing list of algorithmic stablecoin failures tied to governance exploits and oracle manipulation. Bloomingbit noted the incident highlights how DAOs, which govern many DeFi protocols, can become attack vectors rather than safety nets. Until governance contracts are hardened, similar exploits remain a real threat across the DeFi ecosystem.
Publishers
17
Articles
16
Reach
33