Koinlytics

42DAO's Own Oracle Signed Off On A BTCB Print That Let An Attacker Mint 4.5 Million BLC From Nothing

Jul 22, 2026BLCBTCBUSDTBNBCAKE42daoblcstablecoinexploitbnb-chainoraclepancakeswapdepeg
An attacker poked 42DAO's Median Oracle on July 22, 2026, got a bad BTCB print accepted, and used it to mint 4.5M BLC from a null address on BNB Chain. The drain via PancakeSwap V2 hit $915K and the stablecoin collapsed 99% to $0.001209 in two hours.

The BLC depeg was not a bank run. It was an oracle write that the protocol treated as gospel, followed by a mint path that turned that lie into 4.5 million units of a supposedly dollar-pegged token. The attacker did not need to bridge exotic collateral or find a reentrancy bug. They called two functions the protocol exposes on purpose: poke on the Median Oracle Spotter, and bark on the Dog contract that handles bad-debt liquidations.

The exact mechanism, function by function

42DAO's collateral system reads BTCB prices through a Median Oracle Spotter. The poke function pulls the current median feed value into the system's internal state. If the feed returns an abnormally low print, poke propagates that number as the working BTCB price for the next block of logic. That is what happened here: BTCB was momentarily accepted at a price far below market. Vaults collateralized in BTCB immediately looked undercollateralized. Dog.bark is the liquidation trigger. Called against those newly underwater vaults, it initiated liquidation auctions that let the attacker acquire BTCB positions and, through the protocol's own accounting, mint fresh BLC against them. The first transaction produced approximately 4.5 million BLC out of a null address, which is exactly the on-chain fingerprint of a mint that never had real collateral behind it. The attacker moved that BLC to PancakeSwap V2 and swapped it for USDT and BTCB. SlowMist put the loss at $912K, PeckShield at $915K.

Why algorithmic stablecoins with self-referential collateral snap

Algorithmic stablecoins that mint against on-chain collateral priced by an on-chain oracle are only as strong as the weakest link in that oracle chain. When the same protocol both trusts the price and mints new supply based on it, a single bad print is not a temporary mispricing. It is a permission slip to create tokens. That is the fragility BLC exposed. There was no fraud in the smart contract logic in the traditional sense. The code did what it was told. The Median Oracle Spotter, the Dog contract, the mint path: each function executed as designed. The design itself assumed the oracle could not lie for long enough to matter. It could, and it did.

PancakeSwap V2 was the exit, and the second transaction proves nobody was watching

The drain would have been theoretical without a venue to sell the freshly minted BLC. PancakeSwap V2 provided that venue. Deep pools of USDT and BTCB paired against BLC gave the attacker instant, non-custodial liquidity. The 99% depeg to $0.001209 is a direct function of how much BLC hit those pools versus how much stable liquidity was there to absorb it. The more damaging detail is the timing. Roughly two hours after the first transaction, the same attacker ran the pattern again, minting another 5,900 BLC and pulling more liquidity out. The mempool for that second call was public. The first exploit was already trending on security Twitter. Nobody paused the oracle, nobody froze the mint, nobody moved liquidity. Two hours is not a millisecond MEV race. It is a governance failure.

The pattern across BNB Chain oracle exploits, 2024 to 2026

This is the same script as several BNB Chain incidents since 2024: a low-liquidity or thinly monitored oracle feeds a lending or minting protocol, an attacker flash-manipulates the price for one block, and PancakeSwap absorbs the exit. The venue changes rarely, the shape of the trace does not. The question every stablecoin holder should now ask their own protocol: what oracle prices your collateral, how many independent price sources feed it, what is the delay between a poke and a mint, and who has the authority to pause it in the two hours between the first exploit transaction and the second. If any answer is unclear, that position is priced in the same currency as BLC was at 1:00 PM UTC and at 3:00 PM UTC on the same day.

What Koinlytics tracks: real-time depeg alerts on stablecoin positions below $50M market cap, oracle source concentration and update frequency for each stablecoin in a portfolio, BNB Chain lending exposure by collateral type, mint-and-dump signatures on PancakeSwap V2 and V3 pairs, and cross-referencing of held stablecoins against SlowMist and PeckShield exploit feeds within the same session.

Powered by Koinlytics · Portfolio and DeFi analytics that see what others miss.

See every headline that moves your bag.

Koinlytics Market Intel is live inside the app. Track your portfolio, LPs and impermanent loss while the news breaks.

Join Koinlytics