Skip to main content
4 min read

42DAO BLC Exploit: $912K
Drained via BTCB Oracle Manipulation

$912,000 was drained from 42DAO after a manipulated BTCB oracle triggered instant vault liquidations; Balance Coin (BLC) then collapsed more than 99%.

AUTOSEC.DEVAUTOSEC.DEV
42DAO BLC Exploit: $912K Drained via BTCB Oracle Manipulation
  • Incident Date: July 22, 2026
  • Target: 42DAO / Balance Protocol
  • Target Overview: Balance Protocol is a Maker-style collateralized debt system on BNB Chain governed by 42DAO. Users lock assets including BTCB as collateral to mint the dollar-pegged Balance Coin (BLC).
  • Total Loss: Approximately $912,000, based on SlowMist's estimate; PeckShield separately estimated approximately $915,000
  • Attacker Address: 0x9d8dd9f2d734675e2bfcc142d1c7a45609ca213c
  • Victim Address: 0x973a722fd8bcd4b81f4c5c1ac687073e44aa9a0c
  • Exploit Transaction: 0xe7abe6416e386332b41d63cf5f16903251dc178942cd79bf080fe61058587628
  • Attack Vector: Oracle manipulation combined with missing price-protection and liquidation-delay controls

Incident Review & Technical Details

1. Attack Path

  1. An abnormally low BTCB price entered the oracle path: According to SlowMist, the attacker exploited a BTCB price sourced from Balance Protocol's Median Oracle that was far below the asset's real market value. Available analysis does not establish how the Median Oracle produced that value, but it shows the downstream protocol accepted it as actionable.
  2. Spotter.poke accepted the anomalous price: The Spotter contract at 0x849d...9228 lacked deviation checks, maximum-drawdown limits, and minimum-price protection. Calling poke therefore allowed the low BTCB spot price to be written immediately into the protocol's Vat accounting state.
  3. Dog.bark liquidated healthy vaults without delay: The Dog liquidation module at 0x0010...634e consumed the updated spot price without a liquidation delay or secondary oracle validation. Multiple BTCB-backed vaults were made to appear undercollateralized and were liquidated within the same transaction.
  4. The attacker converted the false valuation into real assets: The attacker acted on the resulting liquidation opportunity and profited from the gap between the artificial BTCB valuation and its executable market price. PeckShield-linked reporting also described approximately 4.5 million BLC entering the sequence and liquidity being extracted through PancakeSwap, intensifying the stablecoin's collapse.

2. Impact Scope

  • Protocol-Level Loss: SlowMist estimated the direct loss at approximately $912,000. PeckShield's separate estimate was approximately $915,000; this article uses SlowMist's figure consistently as the canonical headline amount.
  • BLC Depeg: Balance Coin fell from near its $1 target to approximately $0.0012–$0.0014, a decline of more than 99%. The depeg destroyed BLC's defining price-stability function even though the token's broader market-value decline is distinct from the attacker's direct profit.
  • Vault Liquidations: Multiple BTCB-backed positions were liquidated using the abnormal oracle value even though their collateral would have remained healthy under the real market price.
  • DEX Liquidity: Reporting tied the exploit sequence to BLC sales through PancakeSwap. The influx of BLC and removal of paired assets amplified the loss of confidence and pushed the stablecoin toward near-zero trading levels.

3. Official Statements

  • SlowMist: In its technical alert, SlowMist identified the missing price-deviation checks, drawdown limits, minimum-price floor, liquidation delay, and secondary validation as the controls that allowed one anomalous BTCB price to trigger atomic liquidations.
  • PeckShield: PeckShield reported that BLC had fallen approximately 99% and estimated the exploit loss at roughly $915,000.
  • 42DAO: The reviewed sources found no public 42DAO incident statement, technical post-mortem, compensation plan, or recovery announcement at the time of publication.

4. Investigation Progress

The primary transaction, attacker address, victim address, and the two liquidation-path contracts have been publicly identified. SlowMist's reconstruction supports a single-transaction sequence centered on the Spotter.poke and Dog.bark calls, while later reporting described a smaller follow-on BLC mint and liquidity extraction approximately two hours later.

No recovered funds or attacker settlement were reported in the reviewed sources. A durable recovery would require more than restoring the front end or replenishing a pool: 42DAO would need to validate the oracle source, introduce price bounds or cross-oracle checks, add a delay before anomalous prices can trigger liquidation, and establish a credible mechanism for restoring BLC's collateral support and market liquidity.


AUTOSEC.DEV Solution

The 42DAO exploit demonstrates that a collateralized stablecoin is only as safe as the controls between its oracle input and its liquidation engine.

  1. Secure Code Review — Balance Protocol's Spotter.poke accepted an abnormally low BTCB value and Dog.bark acted on it immediately, with no deviation bound, price floor, or secondary validation. AUTOSEC.DEV reviews the entire oracle-consumption path with adversarial price tests, invariant fuzzing, stale-data handling, and fail-closed liquidation conditions rather than treating oracle output as inherently trustworthy.
  2. Security Strategy & Planning — A single price update was able to liquidate multiple BTCB vaults and destabilize BLC in one transaction. AUTOSEC.DEV designs layered oracle policies using independent feeds, time-weighted validation, per-collateral drawdown limits, delayed liquidation, and automated circuit breakers that pause affected markets before an anomalous value becomes irreversible protocol state.

Reference