CometDEX Hack
What happened
On August 25, 2026, CometDEX's BLND-USDC liquidity pool on Stellar was exploited through an incorrect-share-accounting flaw, with approximately $717,518.92 USDC drained.
CometDEX allowed same-asset swaps to alter reserve and share accounting instead of rejecting the no-op asset pair, enabling repeated withdrawals against corrupted pool state.
How it happened
The attacker used flash-loan-funded loops of same-asset USDC-to-USDC swaps that corrupted the Comet AMM's reserves and repeatedly extracted excess USDC.
Protocol details
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.