Balance Coin Collapses 99% After Reported $915K Exploit of 42DAO
An attacker exploited 42DAO's minting controls on BNB Chain twice in two hours, minting 4.5 million BLC from a null address and collapsing Balance Coin 99% from its dollar peg.

An attacker reportedly minted 4.5 million tokens from a null address, swapped them for real assets, and did it again two hours later. No one stopped it either time.
Key takeaways
- Balance Coin (BLC) fell from $0.9954 to $0.001358 on July 22, 2026, a collapse of more than 99%, after a reported $915,000 exploit of 42DAO on BNB Chain, per @PeckShieldAlert on X.
- The attacker reportedly executed two separate transactions involving GemJoin and 42DAO, minting an alleged 4.5 million BLC from a null address in the first hit and 5,900 more in a near-identical replay roughly two hours later, swapping both tranches for BSC-USD and BTCB on PancakeSwap V2.
- The second attack is the most damning detail: the same suspected exploit worked again with no circuit breaker, no pause mechanism, and no apparent response from the protocol between the two hits.
Balance Coin, the algorithmic stablecoin of Balance Protocol designed to hold a dollar peg, was trading at $0.001358 at the time of the reported exploit on July 22, 2026, down from $0.9954 before the attack, according to CoinMarketCap data cited at the time of initial reporting. Blockchain security firm @PeckShieldAlert on X attributed the depeg to a $915,000 exploit of 42DAO, the decentralized autonomous organization that governs Balance Protocol and its BLC token.
What the Exploit Actually Did
@TenArmor on X identified two suspected attack transactions involving GemJoin and 42DAO on BNB Chain. Onchain records reportedly show the first attack minted 4.5 million BLC from a null address. Those tokens were reportedly routed to PancakeSwap V2 and swapped for Binance-pegged USDT (BSC-USD) and Binance Bitcoin (BTCB), converting synthetic supply into real assets at the protocol's expense.
Approximately two hours later, the attacker reportedly returned and executed a near-identical transaction, minting an additional 5,900 BLC and extracting more BSC-USD and BTCB through the same venue. The BLC token contract on BscScan is publicly verifiable onchain.
The root cause of the null-address minting has not been confirmed by a technical post-mortem. Whether this is a smart-contract-level flaw or an access-control failure in 42DAO's governance layer is still an open question. Balance Protocol had not issued an official statement at press time.
The Governance Vacuum
The reported $915,000 figure is small in absolute terms. The architecture that made it possible is not.
BLC's entire dollar peg depended on three things holding simultaneously: the correctness of the minting contract, the security of 42DAO's governance controls, and sufficient liquidity on PancakeSwap V2 to absorb a dump without collapsing the price. All three failed in sequence, in under two hours. Users who held BLC believed they held a dollar. What they actually held was exposure to each of those layers, stacked.
The replay attack is what removes any charitable reading of this incident. The protocol had a window between the first and second hit. Nothing triggered. No emergency pause, no governance response, no on-chain circuit breaker. The attacker correctly identified that the window was safe to use again, and they were right.
This is the predictable output of a structure where an algorithmic stablecoin's integrity rests on a governance token held by an anonymous DAO. When the DAO's minting controls can be bypassed, the peg dissolves into a promise. Bitcoin has no governance token, no DAO minting controls, and no null-address vulnerability. There is no 42-anything that votes on Bitcoin's monetary policy. No one can mint sats from a null address.
That is not an accidental design property; it is the whole architecture. The fiat leverage spiral that plays out at the sovereign level has a miniature version here: synthetic supply, rehypothecated trust, and a single point of governance failure.
The falsifiable version of this thesis: if a post-mortem shows the exploit was purely an off-chain key compromise with no contract-level minting flaw, the governance-layer argument narrows to an operational security failure. Watch for the official post-mortem. Until then, the onchain record shows tokens reportedly minted from a null address, twice, uncontested.
What to Watch
The immediate question is whether 42DAO or Balance Protocol issues a technical post-mortem identifying the specific exploit vector in GemJoin or the minting contract. If funds were traced or any portion recovered, that would also narrow the damage. The broader question is whether BscScan's onchain transaction data surfaces a cleaner picture of the attack path before any official disclosure. This story was developing at press time, first reported by Cointelegraph.
Sources
- @PeckShieldAlert on X (plain-text attribution; exact post URL not confirmed at press time)
- @TenArmor on X (plain-text attribution; exact post URL not confirmed at press time)
- CoinMarketCap, Balance Coin (BLC)
- BscScan, 42DAO BLC Token Contract
- First reported by Cointelegraph
Frequently Asked Questions
An algorithmic stablecoin attempts to hold a dollar peg not through direct dollar or collateral reserves, but through protocol-controlled minting and burning of supply. When demand falls or the minting mechanism is exploited, there is no reserve buffer to absorb the pressure. The peg breaks. The BLC collapse follows the same structural pattern seen in prior algorithmic stablecoin failures: a mechanism that works until the assumption underlying it (that minting controls are secure) stops being true.
Bitcoin has a fixed supply of 21 million coins enforced at the protocol layer. No governance body can vote to mint more. No contract can be exploited to create new supply from a null address.
No DAO controls its monetary policy. Every property that made the 42DAO exploit possible, a minting function, a governance layer with control over supply, a liquidity venue to offload synthetic tokens, is absent from Bitcoin by design.
Unknown at press time. @PeckShieldAlert and @TenArmor described the event as a suspected exploit. Whether it involved an external attacker, a compromised key, or an insider has not been confirmed. The "reported exploit" qualifier should be preserved until a post-mortem establishes the attack vector.


