YFarmX

Tools Crypto Exploit Tracker exploit-0009

Exploit record

CometDEX Backstop Pool Drain

Loss
$718k
Attack vector
Smart Contract Bug
Chain
Stellar
Sector
AMM

What happened

On 25 August 2026, an accounting bug in the Comet AMM's BLND-USDC pool on Stellar, the backstop for the Blend lending protocol, allowed same-asset swaps of USDC for USDC that corrupted the pool's reserve calculations. SlowMist logs the drain at $717,518.92. Blend's operators paused the backstop; Blend said its own contracts were not at fault and lending-pool deposits were not at risk, but backstop depositors holding Comet BLND-USDC LP shares took the loss.

The fallout spread well beyond the pool: Stellar DeFi TVL fell from a peak of about $270m on 22 August to roughly $98m by 27 August, with Blend's own TVL going from over $150m to near zero. Blend was already in this log for a $10.86m oracle-manipulation loss in February 2026.

Sources

One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026