Log in
For business
KYT office
Compliance solution to monitor risks, detect sanctions and ensure AML rules.
KYT office
Compliance solution to monitor risks, detect sanctions and ensure AML rules.
AML certification
How industry players can get up-to-date knowledge and professional certification.
AML certification
How industry players can get up-to-date knowledge and professional certification.
Comprehensive transaction analytics that helps to build graphs and trace funds.
Graph
Travel rule
(soon)
For personal use
Telegram bot
Bot for checking crypto for risks, providing AML reports.
Telegram bot
Bot for checking crypto for risks, providing AML reports.
Crypto recovery
Services are focused on tracking
and recovering crypto assets.
Сrypto recovery
Services are focused on tracking
and recovery crypto assets.
Docs and reports
All types of documents related
to cryptocurrency.
Docs and reports
All types of documents related
to cryptocurrency.
Portfolio tracker
Information about all assets and risk assessment in one place.
Portfolio tracker
Information about all assets and risk assessment in one place.
AML checks
Сhecking wallets and transactions
for illicit funds.
AML checks
Сhecking wallets and transactions
for illicit funds.
ES
FR
中文
Вход
AML-сертификация
Актуальные знания в области AML/KYT от ведущих экспертов отрасли.
AML-сертификация
Актуальные знания в области AML/KYT от ведущих экспертов отрасли.
Graph
Визуализация перемещения активов
и связей между кошельками.
Graph
Визуализация перемещения активов
и связей между кошельками.
KYT Office
Мониторинг транзакций и кошельков для вашего отдела комплаенса.
KYT Office
Мониторинг транзакций и кошельков для вашего отдела комплаенса.
Для себя
Для Бизнеса
Travel rule
(Cкоро)
Телеграм-бот
Бот для проверки кошельков и транзакций с выдачей отчётов.
Телеграм-бот
Бот для проверки кошельков и транзакций с выдачей отчётов.
Возврат средств
Услуги по отслеживанию и возврату украденных криптоактивов.
Возврат средств
Услуги по отслеживанию и возврату украденных криптоактивов.
AML-проверки
Проверка кошельков и транзакций на наличие "грязной" криптовалюты.
AML-проверки
Проверка кошельков и транзакций на наличие "грязной" криптовалюты.
Портфолио трекер
Информация о всех активах и оценка рисков в одном месте.
Портфолио трекер
Информация о всех активах и оценка рисков в одном месте.
Отчёты
Все типы документов связанные
с криптовалютой.
Отчёты
Все типы документов связанные
с криптовалютой.
PRIVATE
Government
Financial institutions
Exchanges
PSP's
Wallets
Gambling platforms
Investment platforms
Stablecoin issuers
Investigators
Regulators
Law enforcement
Для бизнеса
Госсектор
Финансовые организации
Биржи
Платежные провайдеры
Кошельки
Игровые платформы
Инвестиционные платформы
Эмитенты стейблкоинов
Расследователи
Регуляторы
Правоохранительные органы
ES
FR
中文
22.07.2026

How a False Bitcoin Price Helped Drain Over $1 Million From 42DAO

On July 22, 2026, Balance Coin (BLC) — the settlement asset of the 42DAO ecosystem — lost its dollar peg and plunged by more than 99% within hours. A stablecoin is designed to remain close to $1, so a collapse of this scale effectively rendered the token worthless. What makes the incident unusual is that it was not caused by market panic or a team disappearing with user funds. The protocol was “robbed” by its own rules. Someone made the system believe that the Bitcoin on its balance sheet was worth next to nothing, prompting it to sell off collateral at fire-sale prices. Losses may exceed $1 million.

BitOK analysts reconstructed the incident in detail. Here is how the attacker managed to make 42DAO “voluntarily” give up the funds.


Table of content:

  1. How Around $1 Million Was Drained from Balance Protocol
  2. How the Incident Worked
  3. Where the Money Went
  4. Attack Timeline
  5. The Funds Moved to Ethereum and Disappeared
  6. Key Addresses
  7. The Full Picture
  8. What This Case Teaches Us

How Around $1 Million Was Drained from Balance Protocol

The first point to understand is that no private key was stolen and no servers were breached. The weakness lay in the interaction between the price oracle and the liquidation mechanism — in other words, in the protocol’s economic design itself.

To make the rest of the analysis easier to follow, here are three key concepts in plain language:
  • Oracle is a price feed used by a protocol. A smart contract cannot determine Bitcoin’s market price on its own, so it obtains that price from an oracle — Median Oracle in this case — and relies on the data it receives.
  • BTCB is wrapped Bitcoin on BNB Smart Chain: a token designed to track the price of native BTC while operating on a different blockchain. It was used as collateral in the protocol.
  • Liquidation is the forced sale of collateral when a position is deemed undercollateralized. It is a standard protective mechanism: if collateral value falls too far, the protocol sells it to avoid taking a loss.
Investigator’s note: the incident was not caused by a compromised key. The protocol accepted an abnormally low BTCB price without any safeguards and immediately triggered liquidations at that incorrect valuation.

How the Incident Worked

The attacker followed this sequence:
  1. The oracle supplied an understated price. Median Oracle reported a BTCB price far below its actual market value.
  2. The protocol accepted the price without validation. Spotter — the module that receives oracle data and records it in the protocol’s internal accounting system, Vat, where all collateral and debt positions are stored — accepted the value as-is, with no mechanism to reject an extreme deviation.
  3. The collateral “collapsed” on paper. BTCB vaults — individual user positions holding collateral against loans — suddenly appeared undercollateralized, even though the underlying Bitcoin had not moved and retained its real market value.
  4. Liquidations were triggered. Dog, the module responsible for forced collateral sales, immediately began liquidating positions using the false price.
  5. The operator bought the collateral at a discount. The attacker acquired BTCB at the artificially depressed valuation and immediately sold it at the true market price through liquid PancakeSwap pools. The gap between the false and real prices became the attacker’s profit — and the protocol’s loss.
A simple analogy. Imagine a warehouse where an electronic price tag displays the value of each item. A faulty tag suddenly marks a full-price product as heavily discounted. No one verifies the change, and an automated liquidation system immediately sells the perfectly good inventory at the sale price. An operator buys it cheaply and resells it at the normal market rate.

Where the Money Went

While the funds remained on BNB Smart Chain, every trail converged on a single point. The attack organizer did not send anything to centralized services, and the decentralized exchange addresses involved were merely technical infrastructure used for swaps. After that, the flow became more complex. Let us examine it step by step.

The addresses played the following roles:
The main asset into which the proceeds were consolidated was Binance-Peg BSC-USD, a stablecoin on BNB Smart Chain. The final address also received a separate transfer of 4.939781 BNB. During the preparation phase, the DPIN token also appeared in the flow and was used, alongside BNB and BSC-USD, to fund the coordinator address.

Attack Timeline

Note: some amounts in the source data have been rounded.

The Funds Moved to Ethereum and Disappeared

This is where the key turn occurred: the collection address was not the final destination but a staging point. After accumulating roughly 1.037 million BSC-USD, the operator moved the funds onward — first to another blockchain and ultimately into a privacy service.

Investigator’s note: several hours after the first withdrawal, a related contract sent the operator another 63,254 BSC-USD, which was routed almost immediately to the same consolidation address. Including this tranche, the total value of assets identified there exceeded $1.04 million.

The route was as follows:
  1. Bridge to Ethereum. From the collection address, the funds moved through LI.FI infrastructure — an aggregator that automatically selects an efficient route for swaps and cross-chain transfers — and the Across bridge. A bridge is a mechanism used to transfer value from one blockchain to another.
  2. Conversion to USDC. On Ethereum, a new wallet, 0x086e…d08b, received approximately 1.036 million native USDC — genuine USDC issued on Ethereum rather than a wrapped representation from another network. Across also sent the wallet 0.01478 ETH to cover network fees.
  3. Transit and entry into a privacy pool. All of the USDC was then transferred to another newly created wallet, 0xe82f…fe7d. From there, approximately 1.033 million USDC was deposited into Railgun, a private transaction service that obscures the link between sender and recipient and functions similarly to a mixer.
One detail points to advance preparation: before moving the main amount, the operator routed roughly 3,200 USDT through Railgun directly on BSC. This appears to have been a test of the privacy route before the larger transfer.

An important clarification about the addresses: not every link in this chain belongs to the attacker. The LI.FI addresses — Permit2 Proxy 0x89c6…f818 and Diamond 0x1231…4eae — and the Across addresses — Spoke Pool 0x5c7B…35c5 and relayer 0xe742…ea88 — are technical bridge infrastructure used by many customers. They are not part of the attacker’s cluster. Three newly created addresses are attributable to the attack organizer: the post-bridge recipient 0x086e…d08b, the final public transit wallet 0xe82f…fe7d, and the BSC test address 0xca08…675f.

Key Addresses

In addition to the operator’s wallets, the incident involved addresses belonging to the protocol itself — the vulnerable modules through which the attack unfolded.
How the attacker moved the funds. The graph was built using BitOK's Graph tool.

The Full Picture

Taken together, the activity forms a coherent sequence. At least two days in advance, the operator prepared the infrastructure and assigned different functions to separate addresses: funding, coordination, swapping, temporary storage, and final consolidation. During the attack, the proceeds were routed through exchange pools and converted into a liquid stablecoin.

The operator proceeded methodically. A dedicated bot address, 0xb0a3…7ddb, executed transactions roughly every five seconds, indicating a prewritten script rather than manual activity. Before sending a large transfer to the temporary address, the operator first sent a test payment of 1 BSC-USD and waited 16 seconds before moving the main amount — a typical manual check to confirm the destination address.
Investigator’s note: at first, it appeared that the operator was making no attempt to conceal the funds. The entire flow was traceable within BNB Smart Chain and converged on a single address with no outgoing transactions. But this was only a pause. The funds were later bridged to Ethereum, converted into native USDC, and ultimately obscured through Railgun. The transparent phase gave way to a private one precisely when the operator decided the timing was right — and the earlier Railgun test shows that this outcome had been planned from the start.

What This Case Teaches Us

The central lesson is that a protocol can be exploited without changing a single line of code or compromising a single private key.
  • The vulnerability may lie in the economics, not the code. The attacker did not exploit a flaw in encryption. The protocol sold its own collateral because it blindly trusted an oracle price. The lesson for any decentralized service is clear: data the system relies on — prices, exchange rates, and other external inputs — must be sanity-checked. Protocols should reject extreme deviations, enforce minimum acceptable prices and drawdown thresholds, and validate data before liquidation. A single anomalous reading should never trigger an immediate, irreversible action.
  • Wrapped assets and oracles introduce intermediary risk. When a protocol uses BTCB or a similar token as collateral and obtains its valuation from an oracle, users are relying not only on Bitcoin but also on the integrity of that pricing chain. It is important to understand where a service obtains its prices and what happens if the provider supplies incorrect data.
  • The window of transparency can close at any moment. For a time, the funds were fully visible: they sat at a single address without moving. But that transparency was temporary. Once the assets were bridged to another network and deposited into Railgun, the trail effectively went cold. Tracking works only while funds remain in the public layer of the blockchain, giving investigators a limited window in which to respond. In this case, as in many others, preventing the theft is far cheaper than chasing funds that are being methodically routed into privacy services.
Support
Get it

To inquire about our plans, click here

Try BitOK for free