YFarmX

Tools Crypto Exploit Tracker exploit-0064

Exploit record

Blend Protocol

Loss
$11M
Attack vector
Oracle Manipulation
Chain
Stellar
Sector
Borrowing

What happened

On February 22, 2026, the YieldBlox DAO Pool on Blend V2 was exploited for about $10.86M after an attacker pushed USTRY's SDEX price roughly 100x higher and let the oracle swallow it whole.

The attacker found an absurdly thin order book and did what attackers do when markets are basically decorative: they walked the price into the sky. Reflector picked up the manipulated SDEX price and Blend treated the attacker's USTRY as prime collateral instead of what it actually was. That opened the door to borrowing tens of millions in XLM and USDC against collateral worth a fraction of that. Once again, the oracle was not hacked in the Hollywood sense; it was just far too trusting.

On-chain references

  • Attacker AddressGBO7VUL2TOKPWFAWKATIW7K3QYA7WQ63VDY5CAE6AFUUX6BHZBOC2WXC
  • YieldBlox DAO PoolCCCCIQSDILITHMM7PBSLVDT5MISSY7R26MNZXCX4H7J5JQ5FPIYOGYFS
  • Oracle AdapterCD74A3C54EKUVEGUC6WNTUPOTHB624WFKXN3IYTFJGX3EHXDXHCYMXXR
  • Reflector OracleCALI2BYU2JE6WVRUFYTS6MSBNEHGJ35P4AVCZYF3B6QOE3QKOB2PLE6M

One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026