Disclaimer: The opinions expressed by our writers are their own and do not represent the views of U.Today. The financial and market information provided on U.Today is intended for informational purposes only. U.Today is not liable for any financial losses incurred while trading cryptocurrencies. Conduct your own research by contacting financial experts before making any investment decisions. We believe that all content is accurate as of the date of publication, but certain offers mentioned may no longer be available.
Algorithmic stablecoin Balance Coin (BLC) completely lost its dollar peg, collapsing 99.8% to a negligible $0.0013. The crash was caused by a seconds-long oracle failure that opened the door to a targeted hacker attack on the 42DAO protocol. The attacker found a vulnerability in the security system and drained approximately $912,000 from the project.
Analysts at PeckShield and SlowMist reconstructed the incident second by second. As it turned out, the project used a popular DeFi architecture but failed to include its basic safeguards.
How it happened: a perfect chain of failures
The entire attack was completed within a single transaction. The hacker executed a rapid sequence involving two vulnerable smart contracts:
- Spotter contract, responsible for pricing: The module accepted an abnormally low and incorrect Bitcoin price from the BTCB oracle. The contract's code simply lacked protective filters, including checks for sharp price deviations or maximum decline limits. The system trusted the false data and immediately recorded it.
- Dog contract, responsible for liquidations: This module immediately picked up the understated Bitcoin price. Because there was no liquidation delay, the system had no time to verify the data.

By combining these weaknesses into a single scenario, the attacker instantly triggered the forced liquidation of several large Bitcoin vaults at heavily discounted prices. The victims' collateral was transferred to the hacker, who immediately locked in the profit through arbitrage.
To withdraw the proceeds, the attacker dumped millions of newly generated BLC tokens on PancakeSwap, completely destroying the available liquidity. The token's price fell to virtually zero, while the 42DAO project was left with a massive amount of bad debt.
The protocol team has not yet presented a recovery or compensation plan. The incident has now joined the growing list of DeFi exploits, demonstrating the risks of copying another project's financial architecture without preserving the original oracle protection mechanisms.


Dan Burgin
U.Today Editorial Team