YieldBlox Pool Hack (Blend V2)

Estimated pool loss $10.9M
Stellar
Thin-Liquidity Oracle Price Manipulation

What happened

A February 2026 incident drained a YieldBlox DAO lending pool operating on Stellar's Blend V2 protocol. The available technical analyses attribute the loss to a thin-market price feeding the pool's oracle configuration, not to a reported core Blend protocol bug. Estimates range from about $10.2 million to $10.86 million.

Technical root cause

YieldBlox's configured oracle sourced USTRY collateral prices from a shallow SDEX market. Manipulating that market changed the accepted collateral value and inflated borrowing power.

How it happened

  1. The attacker consumed normal USTRY/USDC liquidity on SDEX and placed abnormal orders, moving the apparent price from about $1.06 to $107.
  2. The configured Reflector feed incorporated the manipulated price into its next update.
  3. The YieldBlox pool accepted the inflated USTRY valuation, allowing the attacker to borrow USDC and XLM against overvalued collateral.
  4. The drained assets were bridged away from Stellar.

BlockSec attributes this incident to YieldBlox's pool configuration, not a Blend V2 core-contract defect. Other pools have separate asset and oracle settings.

Protocol details

Classification Oracle Manipulation / Pool Configuration
Protocol Type Isolated lending pool
Protocol links Website @blend_capital

Market Context at Time of Hack

Token Price at Hack $0.0619
Market Cap at Hack $2.2M
Reported loss / token market cap 100.00%
Token Categories
Decentralized Finance (DeFi) Lending/Borrowing Protocols Stellar Ecosystem

Security review history

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.