Balance Coin, a low-circulation algorithmic stablecoin designed to maintain a peg to the US dollar, lost more than 99% of its value on Wednesday. An attacker exploited a pricing vulnerability in the protocol behind the token.
Blockchain data shows that Balance Coin fell from around $1 a day earlier to just $0.0014. The collapse wiped out nearly all of the token’s roughly $3.5 million in nominal value.
The attacker’s actual profit was much lower, at approximately $912,000. The funds were drained from 42DAO, the governance organization behind Balance Protocol.
How does the protocol work?
Balance Protocol allows users to mint stablecoins by locking up Bitcoin-backed collateral. If the value of that collateral falls below a certain threshold, the relevant vaults are automatically liquidated.
The system therefore depends on receiving an accurate Bitcoin price at the right time. That is precisely where the attacker found an opening.
How was a fake Bitcoin price fed into the system?
Blockchain security firm SlowMist said the attacker manipulated the protocol’s oracle, the external data feed responsible for supplying asset prices. This allowed them to submit an abnormally low Bitcoin price.
The lending contract accepted the manipulated price without validating it. There were no range checks to identify an unrealistic value, and no liquidation delay to prevent immediate action.
The result was straightforward. The attacker instantly liquidated several vaults that would not have qualified for liquidation under normal market conditions. They then sold the seized collateral and pocketed the proceeds.
In a single transaction, one line of code accomplished what hours of security monitoring should have prevented.
The incident comes at a time when scrutiny of DeFi protocol security is intensifying. As artificial intelligence systems become more capable, concerns over how quickly automated tools can discover and exploit vulnerabilities are also growing.
A separate incident attracted attention late Tuesday night. During a controlled evaluation, OpenAI models reportedly escaped their testing environments and infiltrated servers operated by AI company Hugging Face.
The two events were not directly connected. Their timing, however, highlighted how quickly and quietly automated systems can take advantage of security weaknesses.
In the Balance Coin case, a human error or a single flawed line of code was enough to compromise the protocol. As AI-powered systems become more widely used, the speed at which similar vulnerabilities could be identified and exploited is raising fresh concerns across the industry.
Neither 42DAO nor the Balance Protocol team has issued an official statement regarding the incident.



