YieldBlox Pool Hack (Blend V2)
What happened
A February 2026 incident drained a YieldBlox DAO lending pool operating on Stellar's Blend V2 protocol. The available technical analyses attribute the loss to a thin-market price feeding the pool's oracle configuration, not to a reported core Blend protocol bug. Estimates range from about $10.2 million to $10.86 million.
YieldBlox's configured oracle sourced USTRY collateral prices from a shallow SDEX market. Manipulating that market changed the accepted collateral value and inflated borrowing power.
How it happened
- The attacker consumed normal USTRY/USDC liquidity on SDEX and placed abnormal orders, moving the apparent price from about $1.06 to $107.
- The configured Reflector feed incorporated the manipulated price into its next update.
- The YieldBlox pool accepted the inflated USTRY valuation, allowing the attacker to borrow USDC and XLM against overvalued collateral.
- The drained assets were bridged away from Stellar.
BlockSec attributes this incident to YieldBlox's pool configuration, not a Blend V2 core-contract defect. Other pools have separate asset and oracle settings.
Protocol details
Security review history
- Code4rena View report
Evidence
- report @pashov incident report x.com
- report @script3official incident report x.com
- report @script3official incident report x.com
- code YieldBlox $10M proof of concept github.com
- analysis DeFiLlama defillama.com
- analysis BlockSec: YieldBlox DAO incident on Stellar blocksec.com
- analysis Halborn: YieldBlox hack explained halborn.com
- analysis DeFiLlama: Blend Pools V2 defillama.com
- analysis QuillAudits: YieldBlox $10M Hack Explained quillaudits.com
- analysis Olympix: The YieldBlox Exploit olympix.security
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.