The CryptoPotato 42DAO oracle exploit tore through Balance Protocol on 22 July, collapsing Balance Coin (BLC) by more than 99% and draining an estimated $912,000 to $915,000 from the protocol’s liquidity in what security firms describe as a textbook oracle manipulation attack.
PeckShield put losses at $915,000 and confirmed BLC “has plummeted -99%” after the incident. SlowMist independently pegged losses closer to $912,000, tracing the root cause to the protocol’s Median Oracle rather than a direct minting vulnerability. Both firms converged on the same attack vector; the dollar difference reflects methodology, not a factual dispute.
BLC fell from near its $1 peg to a record low of $0.001209 on 22 July. At the time of the original report, CoinMarketCap showed the token trading near $0.00247, down 99.75% over 24 hours, with the day’s range stretching from $0.001209 to $0.9955.
How the 42DAO Oracle Exploit Unfolded
Balance Protocol is a MakerDAO-style collateralised vault system. Users deposit Bitcoin Cash (BCH), Binance-pegged Bitcoin (BTCB), or USDT as collateral and receive BLC in return, with the system designed to stay overcollateralised to absorb price swings, according to TechTimes.
According to Cryptopolitan, the primary theft was executed in a single transaction. The attacker used the Spotter contract’s “poke” function to push an artificially low BTCB price directly into the VAT contract, the protocol’s core accounting ledger.
With BTCB’s price manipulated to a near-zero level, solvent vaults suddenly appeared undercollateralised. The Dog module, which handles liquidations, triggered instantly and without delay. As CoinGabbar reports, the attacker then walked away with the vault collateral at the manipulated price.
SlowMist identified three specific control failures in the Spotter contract: no price deviation checks, no maximum drawdown limit, and no minimum price floor. The Dog module compounded the damage by lacking both a liquidation delay and any oracle price validation.
TenArmor separately flagged two suspicious transactions involving GemJoin and 42DAO on BNB Chain. The first minted roughly 4.5 million BLC from a null address before routing them into PancakeSwap V2, where the attacker swapped them for BSC-USD and BTCB. A second transaction, approximately two hours later, minted an additional 5,900 BLC and extracted further assets from available liquidity pools.
Audit Coverage Left the Key Vulnerability Exposed
42DAO had previously commissioned smart contract audits, including a CertiK audit of its BLC minting contract. However, as TechTimes reports, the CertiK audit did not cover the oracle vulnerability that the attacker ultimately exploited.
The gap illustrates a recurring problem in DeFi security: scope-limited audits that sign off on specific modules while leaving adjacent attack surfaces unexamined. The Spotter and Dog contracts sat outside the audit’s remit, and the missing controls in those two contracts proved sufficient to unwind the entire peg.
According to Tangem, both PeckShield and SlowMist identified the oracle system as the specific vulnerability, with estimated losses ranging between $912,000 and $915,000.
The 42DAO attack fits a wider pattern. TRM Labs data cited by TechTimes shows DeFi attackers carried out a record 207 separate incidents in H1 2026, extracting $972 million in total, more than double the 83 incidents recorded in H1 2025.
Unauthorised minting following oracle manipulation has hit multiple protocols this cycle. Resolv’s USR stablecoin depegged in March after an attacker minted unbacked tokens through DeFi markets; MAPO dropped 96% in May after a bridge flaw enabled the same playbook. In each case, the entry point was a contract the protocol either had not audited or had audited incompletely.
According to the Bitcoin Foundation, PeckShield confirmed BLC is primarily backed by BCH, positioning it as a collateral-backed design rather than a purely algorithmic one. That distinction matters little when the liquidation engine can be triggered by a manipulated price feed with no floor check in place.
No post-incident report from 42DAO had been published at the time of writing. The next question for BLC holders is whether the protocol can recapitalise the affected vaults and restore oracle controls before what remains of the peg is tested again.