Blend Protocol Hack

TOTAL LOST $10.9M
High Oracle Issue

Summarize with AI

Affected Chain 2026 Incident surface
Recovered - No recovery reported
All-Time Rank #299 By amount stolen
Protocol Type Lending Target category

Incident Overview

On February 22, 2026, the YieldBlox DAO Pool on Stellar's Blend V2 protocol suffered a $10.86M exploit when an attacker manipulated the SDEX price of USTRY (Etherfuse US Treasury stablebond) from ~$1.06 to ~$106.74 by exploiting minimal liquidity, which the Reflector oracle ingested and passed to Blend's health factor calculations, allowing the attacker to borrow 61.25M XLM and 1M USDC against collateral worth only $158,482.

The attacker exploited extremely low liquidity on the Stellar DEX, where the USTRY/XLM order book had fewer than 5 USTRY available for sale. By placing strategic trades, they inflated the USTRY price 100x from its real value of ~$1.06 to ~$106.74. The Reflector oracle sourced prices directly from SDEX trading activity and ingested this manipulated data, with the Oracle Adapter passing the inflated price to Blend's lending protocol without proper safeguards like time-weighted averages or median calculations.

The attacker deposited USTRY tokens as collateral, which the system valued at the inflated price of ~$16M instead of the real value of ~$158K. This allowed them to pass Blend's health factor validation and borrow 61.25M XLM (~$9.86M) and 1M USDC in two transactions. After the exploit, approximately 901K USDC was bridged to Ethereum, 16M XLM distributed to secondary wallets, and 48M XLM was frozen by the Stellar network.

Transaction simulations against current ledger state fail validation, confirming the exploit was entirely dependent on the temporary oracle manipulation.

Attacker Address: GBO7VUL2TOKPWFAWKATIW7K3QYA7WQ63VDY5CAE6AFUUX6BHZBOC2WXC

YieldBlox DAO Pool: CCCCIQSDILITHMM7PBSLVDT5MISSY7R26MNZXCX4H7J5JQ5FPIYOGYFS

Oracle Adapter: CD74A3C54EKUVEGUC6WNTUPOTHB624WFKXN3IYTFJGX3EHXDXHCYMXXR

Reflector Oracle: CALI2BYU2JE6WVRUFYTS6MSBNEHGJ35P4AVCZYF3B6QOE3QKOB2PLE6M

Incident Report

Protocol / Project Blend Protocol
Date of Incident
Attack Technique Oracle Issue
Classification Borrowing and Lending

Protocol Information

Protocol Type Lending
Official Website blend.capital/
Protocol Twitter/X @blend_capital
Team Anonymous
Source Code Unverified

Market Context at Time of Hack

Token Categories
Platform Ethereum Ecosystem

What the Attacker Needed to Succeed

Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.

Technical Knowledge Deep understanding of oracle issue and Solidity and EVM internals
Capital Required Seed capital to cover gas and initial position setup
On-Chain Access Ability to interact with smart contracts and deploy a custom exploit contract
Protocol Analysis Identification of the exploitable vulnerability in Blend Protocol's contract logic - root cause: borrowing and lending
Execution Speed Precise transaction ordering and timing to exploit the vulnerability within a single atomic block
Obfuscation Plan A strategy to launder and move stolen funds - typically through mixers, cross-chain bridges, or decentralized DEX swaps to resist tracing

What Auditors Should Check

Could this have been caught in audit? Yes — skilled auditors routinely flag Oracle Issue vulnerabilities in code review

If you're auditing a protocol with similar architecture to Blend Protocol, these are the critical security checks that could have prevented this incident (February 2026).

  • Verify all logic paths related to Oracle Issue are guarded by proper access controls and input validation - see the Oracle Manipulation & Price Manipulation attack class for patterns
  • Audit oracle price feeds for manipulation risks - ensure time-weighted average prices (TWAPs) or multi-source aggregators are used, not spot prices
  • Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs

Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.

Free Trial

Related Attack Classes

The technique used in this hack maps to these vulnerability classes in our security curriculum:

See all Oracle Manipulation & Price Manipulation examples →

Sources & References

Learn to Prevent the Next Blend Protocol

The Blend Protocol hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.

Recreate exploit patterns safely Free Trial