YieldBlox (Blend V2 pool) hack — February 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | February 22, 2026 |
| Target type | Lending protocol |
| Loss | $10,200,000Published estimates range $10,200,000 to $10,850,000Price at time of incident |
| Method | Oracle or price manipulationUSTRY collateral was priced through the Reflector oracle, which computed a volume-weighted average from the thin USTRY/USDC market on Stellar's built-in DEX. The attacker placed a sell offer at 501 USDC per USTRY and traded against it; that single trade dominated the oracle's averaging window, lifting USTRY's recorded price from about $1.05 to roughly $106.73. Blend's oracle wrapper applied a 10% deviation check between consecutive price-feed windows, but because both of the windows it compared already carried the manipulated price, the computed deviation was zero and the inflated value passed validation and was accepted as borrowing collateral. |
| Chains | Other |
| Outcome | Partially recovered |
What happened
On 22 February 2026 an attacker emptied the YieldBlox lending pool, a community-managed Blend V2 market on the Stellar network. On-chain accounting published by Blockaid records 61,249,278.31 XLM and 1,000,196.70 USDC borrowed out, effectively the pool's entire reserves. Blockaid and Halborn value that at about $10.2 million; BlockSec's breakdown of roughly $1 million in USDC plus about $9.85 million in XLM, and Bankless's reporting of $10.8 million, imply a higher figure. The range is recorded rather than a single number.
The pool accepted USTRY, a tokenised US Treasury product, as collateral, and priced it through the Reflector oracle. Reflector took a volume-weighted average from the USTRY/USDC pair on Stellar's built-in decentralised exchange, a market that was thin and, at the moment of the attack, effectively without resting liquidity. The attacker placed a sell offer at 501 USDC per USTRY and traded against it. Because that trade dominated the oracle's averaging window, USTRY's recorded price rose roughly a hundredfold, from about $1.05 to about $106.73. Blend's oracle wrapper was supposed to reject any move larger than 10%, but it measured deviation between consecutive price-feed windows, and by the time it checked, both windows already reflected the manipulated price, so the measured deviation was zero and the value was accepted. The attacker then posted USTRY as collateral and borrowed out the pool's USDC and XLM, moving the proceeds off Stellar, with the majority of the USDC bridged to Ethereum.
Stellar Tier-1 validator operators changed their configuration to refuse transactions from the attacker's accounts, quarantining 48,069,094 XLM, about $7.2-7.3 million or 73% of the take, with Blockaid supplying the wallet clustering. A 10% bounty offered by the YieldBlox Security Council for the return of the remaining funds went unanswered. Script3, which develops Blend and YieldBlox, said no Blend contract vulnerability was involved and that other pools were not exposed to the same vector.
Sources
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "YieldBlox (Blend V2 pool) hack — February 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/yieldblox-blend-v2https://itokenly.com/hacks/yieldblox-blend-v2Permalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.