Blend Protocol Hack
Incident Overview
On February 22, 2026, the YieldBlox DAO Pool on Stellar's Blend V2 protocol suffered a $10.86M exploit when an attacker manipulated the SDEX price of USTRY (Etherfuse US Treasury stablebond) from ~$1.06 to ~$106.74 by exploiting minimal liquidity, which the Reflector oracle ingested and passed to Blend's health factor calculations, allowing the attacker to borrow 61.25M XLM and 1M USDC against collateral worth only $158,482.
The attacker exploited extremely low liquidity on the Stellar DEX, where the USTRY/XLM order book had fewer than 5 USTRY available for sale. By placing strategic trades, they inflated the USTRY price 100x from its real value of ~$1.06 to ~$106.74. The Reflector oracle sourced prices directly from SDEX trading activity and ingested this manipulated data, with the Oracle Adapter passing the inflated price to Blend's lending protocol without proper safeguards like time-weighted averages or median calculations.
The attacker deposited USTRY tokens as collateral, which the system valued at the inflated price of ~$16M instead of the real value of ~$158K. This allowed them to pass Blend's health factor validation and borrow 61.25M XLM (~$9.86M) and 1M USDC in two transactions. After the exploit, approximately 901K USDC was bridged to Ethereum, 16M XLM distributed to secondary wallets, and 48M XLM was frozen by the Stellar network.
Transaction simulations against current ledger state fail validation, confirming the exploit was entirely dependent on the temporary oracle manipulation.
Attacker Address: GBO7VUL2TOKPWFAWKATIW7K3QYA7WQ63VDY5CAE6AFUUX6BHZBOC2WXC
YieldBlox DAO Pool: CCCCIQSDILITHMM7PBSLVDT5MISSY7R26MNZXCX4H7J5JQ5FPIYOGYFS
Oracle Adapter: CD74A3C54EKUVEGUC6WNTUPOTHB624WFKXN3IYTFJGX3EHXDXHCYMXXR
Reflector Oracle: CALI2BYU2JE6WVRUFYTS6MSBNEHGJ35P4AVCZYF3B6QOE3QKOB2PLE6M
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Blend Protocol, these are the critical security checks that could have prevented this incident (February 2026).
- Verify all logic paths related to Oracle Issue are guarded by proper access controls and input validation - see the Oracle Manipulation & Price Manipulation attack class for patterns
- Audit oracle price feeds for manipulation risks - ensure time-weighted average prices (TWAPs) or multi-source aggregators are used, not spot prices
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialRelated Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Sources & References
- 01
- 02
- 03
Learn to Prevent the Next Blend Protocol
The Blend Protocol hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.