{"investigation":{"slug":"blend-pools-v2","entity_name":"Blend Pools V2","trust_score":32,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"Blend Pools V2 is a modular, permissionless lending protocol built on the Stellar blockchain by Script3, launched as an upgrade to Blend V1 with additions including flash loans and a reduced backstop threshold. In February 2026, a community-managed pool built on top of the protocol (YieldBlox DAO Pool) suffered a $10.8 million oracle manipulation exploit; Script3 stated the core V2 contracts were not at fault, attributing the incident to pool-operator misconfiguration of the Reflector VWAP oracle.","sections":[{"content":"Blend Pools V2 is developed by Script3, a decentralized finance studio founded by Markus Paulson-Luna and based in the Greater Minneapolis-St. Paul area. The protocol is built on Stellar's Soroban smart contract engine and positions itself as a modular liquidity primitive — a foundation on which third parties can deploy isolated lending markets. Script3 first announced Blend in April 2023 while Soroban was still on testnet. Blend V2 is the current mainnet version, retaining the same core architecture as V1 but introducing flash loans, a reduced backstop threshold (from a higher value to 100,000), a shortened backstop withdrawal queue (17 days), and a fixed reward zone length of 50. The protocol is permissionless: any entity — DAO, institution, or individual — can create a lending pool with customized assets, collateral parameters, and oracle sources. As of early 2026, Blend Pools V2 carried approximately $94.85 million in total value locked (TVL) across 10 active lending pools on Stellar, with $39.27 million in active loans.","heading":"Background","sources":[{"url":"https://medium.com/script3/introducing-blend-95aaf66bdf41","name":"","type":"other","credibility":3},{"url":"https://docs.blend.capital/users/general-faq","name":"","type":"other","credibility":3},{"url":"https://defillama.com/protocol/blend-pools-v2","name":"","type":"other","credibility":3},{"url":"https://thedefiant.io/news/defi/meet-blend-stellar-s-modular-liquidity-layer","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Blend V2 operates as a set of immutable smart contracts on Stellar's Soroban runtime. Pool creators deploy isolated lending markets and configure supported assets, oracle sources, collateral factors, and liquidation parameters. Isolation is a core design property: a position in one pool has no effect on positions in any other pool, limiting systemic contagion. A backstop module functions as an insurance reserve for each individual pool; BLND token holders can deposit into a pool's backstop to earn a share of protocol emissions in exchange for absorbing bad debt when it arises. The protocol emits 1 BLND per second to users after an initial distribution of 49 million BLND tokens at launch. Blend V2 does not retain protocol revenue from borrow interest — all interest flows directly to lenders. Flash loans were introduced in V2 and are available to any caller within a single Soroban transaction. Because pool creation is permissionless, oracle selection and asset eligibility are entirely the responsibility of individual pool operators, a design choice that the February 2026 exploit exposed as a significant risk vector.","heading":"Protocol Mechanics","sources":[{"url":"https://docs.blend.capital/blend-whitepaper","name":"","type":"other","credibility":3},{"url":"https://docs.blend.capital/users/general-faq","name":"","type":"other","credibility":3},{"url":"https://docs.blend.capital/users/blnd-token","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Certora conducted a formal audit of the Blend protocol with findings published on January 25, 2024. The audit scope covered all core components: the emitter (BLND token generation), liquidity pool instances, and the backstop module. Certora noted the audit was performed against an actively developing codebase rather than a frozen snapshot. The audit aimed to validate architectural soundness and robustness assumptions. No specific critical or high severity findings from the Certora report have been independently confirmed in publicly available summaries. The GitHub repository for Blend V2 contracts is publicly available at blend-capital/blend-contracts-v2 on GitHub.\n\nDespite a clean core-contract posture, the protocol's most significant security event occurred in February 2026. On February 23, 2026, an attacker exploited the YieldBlox DAO Pool — a community-managed pool deployed on top of Blend V2 — via oracle price manipulation. The attacker exploited a 15-minute window of thin USTRY/USDC liquidity on the Stellar DEX (SDEX), placing a sell order at 501 USDC per USTRY that was accepted by the Reflector VWAP oracle, inflating the reported USTRY price from approximately $1.05 to approximately $106 — a 100x inflation. Using the inflated collateral valuation, the attacker borrowed 61.25 million XLM and 1 million USDC from the YieldBlox pool, then bridged assets toward Base, Binance Smart Chain, and Ethereum. Total losses were approximately $10.8 million. Stellar Tier 1 validators intervened and froze approximately 48 million XLM (valued at roughly $7.2 million) before the attacker could complete the bridge. The YieldBlox Security Council offered a 10% white-hat bounty with a 72-hour deadline; the attacker did not respond.\n\nScript3 stated publicly that the incident was isolated to a single asset in a single community-managed pool and that no other Blend pools were vulnerable to the same oracle manipulation vector, attributing root cause to pool-operator misconfiguration rather than a core contract flaw. BlockSec's post-mortem analysis concurred: 'This incident was not a Blend V2 core-contract issue. It was a pool-operator (YieldBlox DAO) configuration issue.' However, critics have noted that the permissionless nature of pool creation — and the absence of any protocol-enforced oracle safety guardrails — is a structural risk that Blend V2 does not mitigate at the contract level.","heading":"Security & Audits","sources":[{"url":"https://www.certora.com/reports/blend","name":"","type":"other","credibility":3},{"url":"https://blocksec.com/blog/yieldblox-dao-incident-on-stellar-oracle-misconfiguration-enabled-a-10m-drain","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-yieldblox-hack-february-2026","name":"","type":"other","credibility":3},{"url":"https://crypto-economy.com/stellar-based-lending-protocol-hit-by-oracle-manipulation-attack/","name":"","type":"other","credibility":3},{"url":"https://www.bankless.com/read/news/lending-market-blend-suffers-10m-exploit","name":"","type":"other","credibility":3},{"url":"https://www.quillaudits.com/blog/hack-analysis/yeildblox-10m-hack-explained","name":"","type":"other","credibility":3},{"url":"https://github.com/blend-capital/blend-contracts-v2","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Blend V2 is built and maintained by Script3, a DeFi studio described as focused on strategic building within the Stellar ecosystem. Markus Paulson-Luna is publicly identified as co-founder of Script3 via LinkedIn and multiple crypto media appearances, including a podcast interview with The Defiant in April 2024. The full team composition is not publicly disclosed; the Stellar Community Fund project page describes the team size as approximately three people. Script3 has received funding from the Stellar Community Fund. The protocol's smart contracts are deployed as immutable on-chain code; Script3 does not have administrative upgrade keys over deployed pool contracts, which limits centralization risk at the contract level but also limits the team's ability to respond to emergencies. No regulatory filings by Script3 or Blend Capital have been identified with the SEC, CFTC, or any other financial regulator. The Blend App Terms of Service explicitly state that Script3 is not registered or licensed by the CFTC, SEC, or any financial regulatory authority, and that Script3 has no oversight, involvement, or control over transactions conducted through the app.","heading":"Team & Ownership","sources":[{"url":"https://www.linkedin.com/in/markuspaulsonluna/","name":"","type":"other","credibility":3},{"url":"https://thedefiant.io/news/defi/meet-blend-stellar-s-modular-liquidity-layer","name":"","type":"other","credibility":3},{"url":"https://communityfund.stellar.org/project/blend-mfy","name":"","type":"other","credibility":3},{"url":"https://testnet.blend.capital/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Blend Pools V2 presents a layered risk profile. At the core-contract level, the protocol has undergone a third-party formal audit by Certora (January 2024) and its contracts are open source and immutable, which reduces but does not eliminate smart contract risk. No exploits of the core V2 contracts have been confirmed. At the pool-operator level, the February 2026 YieldBlox exploit demonstrated that the permissionless, immutable design of Blend V2 creates a structural problem: pool operators who misconfigure oracles or accept illiquid collateral assets can expose their depositors to total loss, and the core protocol provides no on-chain safeguards against such configurations. The Reflector VWAP oracle used by the exploited pool had no minimum liquidity threshold or circuit breaker. Oracle risk is explicitly acknowledged in Blend's own documentation as one of four primary risk categories. The protocol's backstop mechanism is designed to absorb bad debt, but a $10.8 million loss in a single pool would likely exceed any backstop balance in a small community pool. Approximately $7.2 million of the February 2026 loss was frozen by Stellar validators — an intervention that relied on Stellar's validator network acting in a coordinated, extra-protocol manner, which may not be guaranteed in future incidents. The BLND token has no identified SEC regulatory filing and its governance and emission structure carries unquantified securities risk in some jurisdictions. Users interacting with any Blend V2 pool bear oracle risk, asset risk, and pool-operator-configuration risk that cannot be assessed from the core protocol alone and must be evaluated on a pool-by-pool basis.","heading":"Risk Assessment","sources":[{"url":"https://docs.blend.capital/users/general-faq","name":"","type":"other","credibility":3},{"url":"https://blocksec.com/blog/yieldblox-dao-incident-on-stellar-oracle-misconfiguration-enabled-a-10m-drain","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-yieldblox-hack-february-2026","name":"","type":"other","credibility":3},{"url":"https://medium.com/@cryip/10-8m-oracle-manipulation-exploit-on-stellars-blend-protocol-6bdcbb1568c0","name":"","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2023-04-03","event":"Script3 publicly introduces Blend as a liquidity protocol primitive for Stellar's Soroban smart contract platform, announcing it as pre-testnet.","source":""},{"date":"2024-01-25","event":"Certora publishes formal audit of the Blend protocol covering the emitter, liquidity pool instances, and backstop module.","source":""},{"date":"2024-04-09","event":"Co-founder Markus Paulson-Luna discusses Blend's architecture and Stellar DeFi positioning in a public interview with The Defiant.","source":""},{"date":"2026-02-23","event":"Attacker manipulates USTRY/USDC price 100x on SDEX via thin liquidity, exploiting the YieldBlox DAO Pool on Blend V2 and borrowing 61.25M XLM and 1M USDC — approximately $10.8M total.","source":""},{"date":"2026-02-23","event":"Stellar Tier 1 validators coordinate to freeze approximately 48 million XLM (roughly $7.2M) in attacker accounts before bridging to Ethereum is complete.","source":""},{"date":"2026-02-24","event":"Script3 issues public statement attributing the exploit to pool-operator misconfiguration, stating core Blend V2 contracts are unaffected.","source":""},{"date":"2026-02-24","event":"YieldBlox Security Council offers a 10% white-hat bounty with a 72-hour deadline in exchange for return of funds. Attacker does not respond.","source":""},{"date":"2026-02-25","event":"BlockSec and Halborn publish independent post-mortems confirming oracle misconfiguration as root cause; net user loss estimated at approximately $3.6M after frozen XLM is accounted for.","source":""}],"sources_used":[{"url":"https://medium.com/script3/introducing-blend-95aaf66bdf41","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://docs.blend.capital/users/general-faq","name":"","type":"other","archive_url":"http://web.archive.org/web/20260312221437/https://docs.blend.capital/users/general-faq","credibility":3,"archive_timestamp":"2026-03-12T22:14:37+00:00"},{"url":"https://defillama.com/protocol/blend-pools-v2","name":"","type":"other","archive_url":"http://web.archive.org/web/20250916081924/https://defillama.com/protocol/blend-pools-v2","credibility":3,"archive_timestamp":"2025-09-16T08:19:24+00:00"},{"url":"https://thedefiant.io/news/defi/meet-blend-stellar-s-modular-liquidity-layer","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://docs.blend.capital/blend-whitepaper","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-job","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://docs.blend.capital/users/blnd-token","name":"","type":"other","archive_url":"http://web.archive.org/web/20260411044156/https://docs.blend.capital/users/blnd-token","credibility":3,"archive_timestamp":"2026-04-11T04:41:56+00:00"},{"url":"https://www.certora.com/reports/blend","name":"","type":"other","archive_url":"http://web.archive.org/web/20260123213704/https://www.certora.com/reports/blend","credibility":3,"archive_timestamp":"2026-01-23T21:37:04+00:00"},{"url":"https://blocksec.com/blog/yieldblox-dao-incident-on-stellar-oracle-misconfiguration-enabled-a-10m-drain","name":"","type":"other","archive_url":"http://web.archive.org/web/20260315202324/https://blocksec.com/blog/yieldblox-dao-incident-on-stellar-oracle-misconfiguration-enabled-a-10m-drain","credibility":3,"archive_timestamp":"2026-03-15T20:23:24+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-yieldblox-hack-february-2026","name":"","type":"other","archive_url":"http://web.archive.org/web/20260315173622/https://www.halborn.com/blog/post/explained-the-yieldblox-hack-february-2026","credibility":3,"archive_timestamp":"2026-03-15T17:36:22+00:00"},{"url":"https://crypto-economy.com/stellar-based-lending-protocol-hit-by-oracle-manipulation-attack/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260315203728/https://crypto-economy.com/stellar-based-lending-protocol-hit-by-oracle-manipulation-attack/","credibility":3,"archive_timestamp":"2026-03-15T20:37:28+00:00"},{"url":"https://www.bankless.com/read/news/lending-market-blend-suffers-10m-exploit","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.quillaudits.com/blog/hack-analysis/yeildblox-10m-hack-explained","name":"","type":"other","archive_url":"http://web.archive.org/web/20260611065641/https://www.quillaudits.com/blog/hack-analysis/yeildblox-10m-hack-explained","credibility":3,"archive_timestamp":"2026-06-11T06:56:41+00:00"},{"url":"https://github.com/blend-capital/blend-contracts-v2","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.linkedin.com/in/markuspaulsonluna/","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://communityfund.stellar.org/project/blend-mfy","name":"","type":"other","archive_url":"http://web.archive.org/web/20260521074749/https://communityfund.stellar.org/project/blend-mfy","credibility":3,"archive_timestamp":"2026-05-21T07:47:49+00:00"},{"url":"https://testnet.blend.capital/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260413144617/https://testnet.blend.capital/","credibility":3,"archive_timestamp":"2026-04-13T14:46:17+00:00"},{"url":"https://medium.com/@cryip/10-8m-oracle-manipulation-exploit-on-stellars-blend-protocol-6bdcbb1568c0","name":"","type":"other","archive_url":"http://web.archive.org/web/20260304075418/https://medium.com/@cryip/10-8m-oracle-manipulation-exploit-on-stellars-blend-protocol-6bdcbb1568c0","credibility":3,"archive_timestamp":"2026-03-04T07:54:18+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:18.769834+00:00","updated_at":"2026-08-30T03:54:58.78226+00:00"}}