Balance Coin (BLC), an algorithmic stablecoin designed to track the US dollar, lost more than 99% of its value on July 22, 2026, after blockchain security firms reported an exploit tied to 42DAO, the decentralized organization behind the Balance Protocol ecosystem on BNB Chain.
Inside the Collapse
BLC fell from close to its intended $1 peg to a low near $0.0012 to $0.0014, and the token’s total nominal market value fell from roughly $3.5 million to near zero in the process.
Security researchers have offered two different technical explanations for how the exploit happened.
PeckShield and TenArmor’s analysis describes unauthorized minting, which is two transactions on BNB Chain that reportedly minted about 4.5 million BLC and then 5,900 BLC from a null address, with the tokens swapped through PancakeSwap for Binance-pegged USDT and BTCB, flooding the market and crashing the peg.
Separately, cybersecurity firm SlowMist stated that an attacker injected a falsified, abnormally low Bitcoin price into the protocol’s oracle, causing the lending contract to treat properly collateralized vaults as undercollateralized, then liquidating them without any price validation or liquidation delay to catch the manipulation.
PeckShield estimated the losses at about $915,000, while SlowMist’s figure put the drained amount at about $912,000.
A detailed post-incident report from 42DAO itself had not been published, and the organization had not released an official statement on recovery or compensation as of this writing.
A Recurring Pattern in DeFi
Unauthorized token creation has caused several sharp depegs this year. Resolv’s USR stablecoin lost its peg in March after an attacker minted millions of unbacked tokens and exchanged them through DeFi markets, prompting Resolv to pause protocol functions during its investigation, a story our earlier coverage of the Resolv Labs stablecoin depeg covered in detail.
MAPO fell 96% in May after attackers exploited a bridge flaw to create unauthorized tokens, and Stake DAO was exploited the same month after an attacker reportedly minted trillions of vsdCRV tokens before swapping them for ETH.
Each case involved a different specific technical weakness, but all shared the same underlying pattern, which is creating tokens outside the protocol’s intended supply controls.
Algorithmic stablecoins carry meaningfully higher structural risk than collateralized alternatives, since they depend entirely on smart contract logic rather than reserve assets to hold their peg, a distinction our beginner’s guide to stablecoin types covers in more depth.
What Comes Next
The immediate focus remains on confirming which technical account, or combination of factors, explains the exploit, and whether 42DAO issues its own detailed post-mortem or any compensation plan for affected holders. Security firms continue tracking the movement of the drained funds.
What this means for you: A stablecoin’s peg is only as strong as the controls behind its supply and pricing mechanisms, and holding or trading a small-cap algorithmic stablecoin carries meaningfully different risk than holding a fiat-backed one with transparent, audited reserves.

