T
iTokenly

YieldBlox hack — February 2026

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedFebruary 22, 2026
Target typeLending protocol
Loss$10,200,000Published estimates range $10,200,000 to $10,970,000Price at time of incident
MethodOracle or price manipulationThe YieldBlox DAO pool, a community-managed deployment on Blend V2 on Stellar, priced USTRY collateral using the Reflector oracle, which derives a volume-weighted average price from Stellar DEX trades. The USTRY/USDC market there had almost no liquidity after a market maker withdrew. The attacker cleared existing orders and executed a single small trade at an inflated price, moving the recorded USTRY price from about $1.05 to roughly $106. Because that was the only trade in the pricing window it dominated the average, and the oracle's deviation check compared two consecutive windows that both carried the manipulated price, so it passed. The attacker then borrowed 1,000,196.70 USDC and 61,249,278.31 XLM against the inflated collateral.
ChainsOther
OutcomePartially recovered

What happened

The YieldBlox DAO lending pool, a community-managed deployment of the Blend V2 protocol on Stellar, was drained on 22 February 2026 through price oracle manipulation.

The pool valued USTRY, a tokenised Treasury asset, using the Reflector oracle, which computes a volume-weighted average price from trades on the Stellar decentralised exchange. That USTRY/USDC market was extremely thin — under $1 of hourly trading volume — after a market maker pulled its liquidity. The attacker cleared the standing orders and executed a single small trade at an inflated price, pushing the recorded USTRY price from about $1.05 to roughly $106.73. Because that trade was the only one inside the 300-second aggregation window it dominated the average, and the deviation check on Blend's oracle wrapper compared each new price only to the immediately preceding window, so two consecutive manipulated windows both passed. The attacker posted USTRY as collateral and borrowed 1,000,196.70 USDC and 61,249,278.31 XLM.

Most published loss figures cluster at $10 million to $10.2 million. A higher figure of about $10.97 million circulates but could not be traced to a citable statement. At the day's XLM spot rate of about $0.161 the borrowed XLM and USDC total roughly $10.9 million. Proceeds were bridged to BNB Chain, Base and Ethereum.

Stellar tier-1 validators coordinated to reject transactions from the attacker's accounts, quarantining about 48,069,094 XLM — roughly 73 percent of the borrowed XLM, put at $7.2 million to $7.3 million. The protocol offered a 10 percent bounty with a 72-hour deadline, which the attacker ignored. Script3, the developer behind YieldBlox, said all EURC, USDC and XLM depositors in the affected pool would be fully compensated for bad debt. The Blend V2 core contracts were not at fault — the pool was misconfigured by its operator.

Sources

  1. BlockaidPrimary · retrieved 2026-08-01
  2. BlockSecOn-chain · retrieved 2026-08-01
  3. HalbornSecondary · retrieved 2026-08-01
  4. QuillAuditsSecondary · retrieved 2026-08-01

Official post-mortem: https://www.blockaid.io/blog/73-quarantined-how-blockaid-and-stellar-validators-contained-a-10m-price-manipulation-attack

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "YieldBlox hack — February 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/yieldblox
https://itokenly.com/hacks/yieldblox

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.