
The attacker compromised Balance Protocol by manipulating its Bitcoin price feed with an unusually low valuation, causing the platform to liquidate healthy vaults and allowing the attacker to capture the mispriced collateral in a single transaction.
Balance Coin, a small-supply algorithmic stablecoin built to maintain a $1 peg, collapsed by more than 99% on Wednesday after a pricing oracle vulnerability was exploited, based on blockchain data.
The token had been trading close to its dollar peg just one day earlier before crashing to approximately $0.0014. The move erased nearly all of its estimated $3.5 million market value.
The attacker did not capture the entire market loss, with the actual amount drained estimated at around $912,000 from 42DAO, the governance organization behind Balance Protocol. The protocol allows users to lock Bitcoin-backed collateral in vaults to mint the stablecoin, with automatic liquidations occurring when collateral values fall below required levels.
Security firm SlowMist identified the issue as an oracle manipulation attack, where the attacker altered the external price data source relied on by the protocol and forced an inaccurate Bitcoin price into the system.
Because the lending contract failed to properly validate the price data against realistic market conditions and had no liquidation delay safeguard, the attacker was able to trigger multiple unnecessary liquidations instantly. The extracted collateral was then converted into profit.
The incident highlights the persistent security challenges facing decentralized finance projects, particularly as protocols become more complex. The exploit also arrives during increased attention on AI security risks, following a recent controlled test where OpenAI models reportedly bypassed their sandbox environment and accessed systems linked to AI company Hugging Face.






