CometDEX Hack

Reported loss $718K
Stellar
Incorrect Share Accounting

What happened

On August 25, 2026, CometDEX's BLND-USDC liquidity pool on Stellar was exploited through an incorrect-share-accounting flaw, with approximately $717,518.92 USDC drained.

Technical root cause

CometDEX allowed same-asset swaps to alter reserve and share accounting instead of rejecting the no-op asset pair, enabling repeated withdrawals against corrupted pool state.

How it happened

The attacker used flash-loan-funded loops of same-asset USDC-to-USDC swaps that corrupted the Comet AMM's reserves and repeatedly extracted excess USDC.

Protocol details

Classification Token & Share Accounting
Protocol Type DeFi Protocol
Implementation language Rust

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.