Balance Coin crashes over 99% in oracle exploit as Zilliqa halts native transfers over Ledger flaw

Balance Coin crashes over 99% in oracle exploit as Zilliqa halts native transfers over Ledger flaw

N
News Editor
2026-07-22 13:54:16
WuBlockchain’s daily crypto news roundup highlighted several developments across the market, led by a sharp collapse in algorithmic stablecoin Balance Coin after an oracle pricing flaw was exploited. The token fell from nearly $1 to about $0.0014, wiping out almost all of its roughly $3.5 million nominal market value. SlowMist said the attacker manipulated the protocol oracle by feeding in an abnormally low Bitcoin price, which caused the lending contract to liquidate vaults that should not have been liquidated and generated about $912,000 in profit in a single transaction, with the funds sourced from Balance Protocol governance entity 42DAO. Elsewhere, trading activity at South Korea’s five largest crypto exchanges fell about 89% year over year, while Kraken parent Payward is working with GTN to expand xStocks to include Hong Kong-listed shares, followed by UK, European and South Korean stocks pending regulatory approval. Movement has filed for bankruptcy, and Zilliqa has suspended native transactions after disclosing a critical Ledger app nonce-generation bug that could allow private keys to be recovered from public signatures. Upbit later placed ZIL under a trading warning designation and suspended deposits and withdrawals.
Balance CoinZilliqaUpbitKrakenMovementSouth Korea exchangesOracle exploitPolicy Regulation

WuBlockchain’s daily crypto news selection was led by an exploit involving Balance Coin, an algorithmic stablecoin that fell from nearly $1 to about $0.0014 after a protocol pricing flaw was abused. The drop exceeded 99%, erasing nearly all of its roughly $3.5 million nominal market value. SlowMist said the attacker manipulated the protocol oracle by writing an abnormally low Bitcoin price into the system. Because the lending contract lacked both price-range checks and a liquidation delay, multiple vaults that should not have been liquidated were wrongly closed out, allowing the attacker to make about $912,000 in a single transaction. The funds came from Balance Protocol governance entity 42DAO.

Trading volume at South Korea’s top five exchanges drops sharply

Average daily trading volume across Upbit, Bithumb, Coinone, Korbit and Gopax fell from $2.82 billion in the same period of July 2025 to $305 million, a year-over-year decline of about 89%. Over the same period, the Korea Composite Stock Price Index, or KOSPI, rose 114.44%.

ZDNet Korea reported that Monday trading volume at the five exchanges was down 88% from a year earlier. Some platforms sold crypto assets as fee income weakened. Korbit sold 15 BTC and 60 ETH, raising about 1.6 billion won, or roughly $1 million.

Payward plans broader xStocks offering

Kraken parent company Payward is working with investment infrastructure provider GTN to bring Hong Kong-listed stocks to xStocks. UK, European and South Korean equities are expected to follow, subject to regulatory approval. GTN will provide execution, custody and recordkeeping services for the securities underlying the related tokens.

Movement files for bankruptcy

Since last November, daily app revenue on Movement has remained below $800 for extended periods, while daily chain fees have stayed in the single digits. Fees over the past 24 hours were just $1. At the same time, Movement has raised a cumulative $141.4 million. Its token’s current fully diluted valuation stands at $107 million, down more than 99% from its peak. Movement has now filed for bankruptcy.

Zilliqa discloses Ledger app vulnerability

Zilliqa said on X that its Ledger application contains a severe random number generation flaw affecting Schnorr signatures for native non-EVM transactions. Accounts that used the app to sign around five or more native transactions should be treated as compromised. According to the project, an attacker can recover the private key in seconds using only publicly available on-chain signature data.

Zilliqa said the flaw exists in all versions released from 2019 through 2026, and that on-chain activity consistent with active exploitation was observed on July 19. The issue came from the signing program copying the wrong 32 bytes, causing the top 64 bits of each ephemeral nonce to be fixed at zero.

The network has suspended native transactions and is preparing a patched application with Ledger. The update will not protect keys that have already been affected, and those keys will ultimately need to be retired. EVM transactions, as well as zilliqa-js, gozilliqa-sdk and pyzil, are not affected. Zilliqa said impacted users should wait for an official remediation plan and should not move assets on their own.

Upbit, the largest crypto exchange in South Korea, later designated Zilliqa (ZIL) as a trading warning asset in the ZIL/KRW and ZIL/BTC markets, with the warning period lasting until the third week of August. Upbit said wallets or the distributed ledger associated with ZIL may face security incident risks that have not yet been identified or fixed. Deposits and withdrawals of ZIL have been suspended, and trading support could be terminated if the issue is not resolved.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.