Blend Protocol Hack

TOTAL LOST $10.9M
High Oracle Manipulation & Price Manipulation stellar

What happened

A February 2026 incident drained a YieldBlox DAO lending pool operating on Stellar's Blend V2 protocol. The available technical analyses attribute the loss to a thin-market price feeding the pool's oracle configuration, not to a reported core Blend protocol bug. Estimates range from about $10.2 million to $10.86 million.

Technical Root Cause

An oracle configuration accepted a manipulable price from a thin-liquidity market for collateral valuation. Lending pools need liquidity-aware price-source selection, bounds on price movement, collateral limits, and a safe response when market depth is insufficient.

Case & protocol details

Classification Oracle Manipulation / Pool Configuration
Protocol Type Exploit/Oracle Issue
Official Website blend.capital/
Protocol Twitter/X @blend_capital

Market Context at Time of Hack

Token Price at Hack $0.0619
Market Cap at Hack $2.2M
% of Market Cap Stolen 100.00%
Token Categories
Platform Ethereum Ecosystem

Attack Timeline

The affected pool accepted USTRY as collateral and relied on a Reflector oracle configuration that incorporated price data from Stellar's decentralized exchange. Researchers reported that USTRY liquidity was thin enough for an attacker to move its quoted price materially. Once the oracle treated the inflated quote as collateral value, the attacker could borrow high-value assets against collateral whose real market value was far lower.

Public proof-of-concept analysis describes the drain as including USDC and XLM. This distinction matters: the incident was specific to the YieldBlox DAO pool's asset and oracle configuration, rather than evidence that every Blend V2 pool shared the same flaw.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.