{"investigation":{"slug":"yieldblox-stellar-oracle-manipulation-exploit-feb-2026","entity_name":"YieldBlox Stellar Oracle Manipulation Exploit (Feb 2026)","trust_score":0,"severity_base":null,"score_modifier":-8,"confidence":0.88,"status":"published","content_type":"investigation","summary":"On February 22, 2026, the YieldBlox DAO-managed lending pool on Stellar's Blend V2 protocol was drained of approximately $10.97 million via a thin-liquidity oracle manipulation attack targeting the USTRY/USDC pair on the Stellar DEX. An attacker inflated the Reflector VWAP oracle price of USTRY from approximately $1.05 to $107 with a single low-volume trade costing roughly $5, then used overvalued USTRY collateral to borrow the pool's entire XLM and USDC reserves. Stellar Tier-1 validators froze approximately 48 million XLM (~$7.5 million) before the funds could be fully bridged out; the protocol developer Script3 committed to full depositor compensation and the attacker rejected a 10% white-hat bounty offer.","sections":[{"content":"On February 22, 2026, at approximately 00:24-00:25 UTC, the YieldBlox DAO Pool — a community-managed lending pool deployed on Blend V2 on the Stellar blockchain — was drained via a price oracle manipulation attack. Total losses are estimated at approximately $10.97 million, comprising 1,000,196.70 USDC and 61,249,278.31 XLM. The incident was confined to a single pool and a single collateral asset (USTRY, a yield-bearing stablebond issued by Etherfuse). Script3, the development team behind both YieldBlox and Blend, confirmed that no other Blend pools were affected and that no other pools shared the same vulnerability conditions. The root cause was assessed by multiple independent security firms as a pool-operator configuration error — specifically, reliance on a single-source Reflector VWAP oracle tied to an illiquid SDEX market without liquidity safeguards — rather than a flaw in the Blend V2 core smart contract architecture.","heading":"Incident Overview","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-yieldblox-hack-february-2026","name":"Explained: The YieldBlox Hack (February 2026) - Halborn","type":"research","credibility":2},{"url":"https://blocksec.com/blog/yieldblox-dao-incident-on-stellar-oracle-misconfiguration-enabled-a-10m-drain","name":"YieldBlox DAO Incident on Stellar: Oracle Misconfiguration Enabled a $10M+ Drain - BlockSec","type":"research","credibility":2},{"url":"https://rekt.news/yieldblox-rekt","name":"Yieldblox - Rekt News","type":"news_article","credibility":2},{"url":"https://x.com/script3official/status/2025403423840141450","name":"Script3 official statement on X","type":"official","credibility":2}],"severity":"critical"},{"content":"The attack exploited the Reflector oracle's reliance on volume-weighted average price (VWAP) data sourced directly from the USTRY/USDC market on Stellar's Decentralized Exchange (SDEX). The USTRY/USDC market had less than $1 in hourly trading volume and fewer than five USTRY tokens on the ask side of the order book at the time of the attack. The pool's only market maker had withdrawn all liquidity in the 15 minutes preceding the exploit, leaving zero competing trades in the Reflector pricing window.\n\nThe attack unfolded in three coordinated phases. First, on February 21 at 23:38 UTC, a burner account placed a sell offer for 1.2185 USTRY at 107 USDC per USTRY — approximately 100-fold the real market price of approximately $1.05. Second, at 00:10:21 UTC on February 22, a second attacker-controlled account executed a purchase of 0.05 USTRY against this offer at approximately $106.7, a trade costing roughly $5. Because this was the only transaction in the Reflector VWAP window, the oracle updated its reported USTRY price to the fabricated value. Third, at 00:24-00:25 UTC, the attacker's primary account deposited 13,003 USTRY as collateral and borrowed 1,000,196.70 USDC (Stellar transaction hash ae721cacee382bdecac8d2c47286ecd42cb4711f658bb2aec7cba60dc64a31ff), then deposited approximately 140,000 additional USTRY and borrowed 61,249,278.31 XLM (transaction hash 3e81a3f7b6e17cc22d0a1f33e9dcf90e5664b125b9e61f108b8d2f082f2d4657), representing the entire pool's XLM reserves. Total collateral deposited was approximately 153,000 USTRY valued at roughly $160,000 at real prices, against which the attacker extracted approximately $10.97 million.\n\nBlockSec's post-mortem noted that the Reflector oracle 'quoted correct prices' for the available market data, and attributed the attack surface to the pool operator's choice to list a collateral asset with insufficient liquidity guardrails. Reflector itself stated it was 'impossible to quote adequate prices for a market fully handled by a single market-maker with almost zero trading activity.' QuillAudits concluded: 'Robust oracle design must account not just for price accuracy, but for market quality.'","heading":"Technical Attack Mechanics","sources":[{"url":"https://rekt.news/yieldblox-rekt","name":"Yieldblox - Rekt News (on-chain forensics)","type":"research","credibility":2},{"url":"https://www.quillaudits.com/blog/hack-analysis/yeildblox-10m-hack-explained","name":"YeildBlox $10M Hack (Oracle Manipulation - Explained) - QuillAudits","type":"research","credibility":2},{"url":"https://www.halborn.com/blog/post/explained-the-yieldblox-hack-february-2026","name":"Explained: The YieldBlox Hack (February 2026) - Halborn","type":"research","credibility":2},{"url":"https://blocksec.com/blog/yieldblox-dao-incident-on-stellar-oracle-misconfiguration-enabled-a-10m-drain","name":"YieldBlox DAO Incident on Stellar - BlockSec","type":"research","credibility":2}],"severity":"critical"},{"content":"The attacker operated multiple Stellar and EVM accounts. Key Stellar accounts identified by BlockSec and QuillAudits include the primary borrower account GBO7VUL2TOKPWFAWKATIW7K3QYA7WQ63VDY5CAE6AFUUX6BHZBOC2WXC and manipulation accounts GCNF5GNRIT6VWYZ7LXUZ33Q3SR2NUGO32F5X65VVKAEWWIQCKGYN75HB, GDHRCQNC64UVL27EXSC6OG6I2FCT4NWM72KNHLHKEB3LK4MEEYYWETN3, and GATDQL767ZM2... The Reflector Oracle contract address is CALI2BYU2JE6..., and the victim pool address is CCCCIQSDIL... as cited by BlockSec.\n\nOn the EVM side, Rekt News identified three exploiter addresses: Exploiter 1 at 0xE69f6d77DB6Ff493FDD15D8A0B390c36E18E5b21 (approximately $729K in ETH at time of reporting), Exploiter 2 at 0x2D1CE29b4aF15fb6E76Ba9995BbE1421E8546482 (approximately $769K in ETH and USDC), and Exploiter 3 at 0x0b2B16E1a9E2e9b15027AE46Fa5eC547f5ef3eC6 (approximately $583K in ETH, reported dormant). QuillAudits confirmed 0x2D1CE29b4aF15fb6E76Ba9995BbE1421E8546482 as the primary EVM recipient address. The attacker's primary Stellar wallet was seeded on February 14, 2026 — eight days before the exploit — indicating deliberate pre-attack staging.","heading":"Attacker Addresses","sources":[{"url":"https://rekt.news/yieldblox-rekt","name":"Yieldblox - Rekt News (on-chain forensics)","type":"on_chain","credibility":2},{"url":"https://www.quillaudits.com/blog/hack-analysis/yeildblox-10m-hack-explained","name":"YeildBlox $10M Hack (Oracle Manipulation - Explained) - QuillAudits","type":"on_chain","credibility":2},{"url":"https://blocksec.com/blog/yieldblox-dao-incident-on-stellar-oracle-misconfiguration-enabled-a-10m-drain","name":"YieldBlox DAO Incident on Stellar - BlockSec","type":"on_chain","credibility":2}],"severity":"critical"},{"content":"Following the exploit, stolen assets were converted to USDC on Stellar then bridged cross-chain. The attacker routed funds from Stellar to Base via Allbridge, then from Base to Ethereum via Across and Relay protocols, with additional movements to BNB Chain. On February 23, 2026 between 09:17 and 09:26 UTC, approximately 380 ETH was consolidated and moved via bridge transactions. On February 27, one of the exploiter EVM wallets moved 100 ETH to Tornado Cash, signaling active laundering of cross-chain proceeds after the bounty deadline elapsed. Rekt News also reported alleged fund routing to Bitcoin via THORChain.\n\nOf the stolen XLM, approximately 3.77 million XLM was alleged to have been sent to Binance (a KYC exchange) and 3.97 million XLM to ChangeNow (a non-KYC service), as reported by Rekt News based on on-chain forensics. The Binance deposit trail creates an alleged KYC record, though no law enforcement action had been publicly announced as of available reporting. Approximately $6.7 million in XLM remained in attacker Stellar addresses subject to Tier-1 validator freeze.","heading":"Fund Movement and Laundering Activity","sources":[{"url":"https://rekt.news/yieldblox-rekt","name":"Yieldblox - Rekt News (on-chain fund tracing)","type":"on_chain","credibility":2},{"url":"https://protos.com/yieldblox-lending-pool-hit-by-10m-hack-on-stellar/","name":"YieldBlox lending pool hit by $10M hack on Stellar - Protos","type":"news_article","credibility":2},{"url":"https://github.com/saariuslystoned/blnd-huntr","name":"blnd-huntr: Forensic investigation dashboard - GitHub","type":"on_chain","credibility":3}],"severity":"critical"},{"content":"In a notable and unusually rapid coordination, Stellar's Tier-1 validators froze approximately 48 million XLM across the attacker's Stellar accounts before the tokens could be fully bridged off-chain. This represented approximately 78-80% of the stolen XLM and approximately $7.2-$7.5 million in value at the time of the freeze. The YieldBlox Security Council followed up with an on-chain bounty message to the attacker's Ethereum address offering 10% of the stolen funds (approximately $1 million) as a white-hat incentive, with a 72-hour deadline and an offer to cease legal pursuit in exchange for return of 90% of funds. The attacker did not respond to the offer and did not return any funds within the deadline.","heading":"Validator Response and Fund Recovery","sources":[{"url":"https://rekt.news/yieldblox-rekt","name":"Yieldblox - Rekt News","type":"news_article","credibility":2},{"url":"https://protos.com/yieldblox-lending-pool-hit-by-10m-hack-on-stellar/","name":"YieldBlox lending pool hit by $10M hack on Stellar - Protos","type":"news_article","credibility":2},{"url":"https://cryip.co/blend-protocol-exploit-10-8m-stolen-from-stellars-yieldblox-pool-via-oracle-manipulation/","name":"Blend Protocol Exploit: $10.8M Stolen from Stellar's YieldBlox Pool - Cryip","type":"news_article","credibility":3}],"severity":"high"},{"content":"Script3 publicly confirmed the exploit was isolated to a single community-managed pool and committed to fully compensating all depositors in the affected pool for losses in USDC, XLM, and EURC. Script3's statement, posted on X at approximately 00:25 UTC on February 22, stated: 'NO OTHER BLEND POOLS WERE AFFECTED. NO OTHER POOLS ARE VULNERABLE.' The specific funding mechanism and timeline for the compensation were not detailed in available public sources at time of writing.\n\nReflector, the oracle provider, maintained that its infrastructure was not compromised and had reported accurate prices given the available market data, attributing the incident to extreme illiquidity at the pool-operator configuration level. Etherfuse, the issuer of the USTRY stablebond used as the manipulated collateral, was referenced in post-mortems but no specific remediation or statement from Etherfuse was cited in available sources.","heading":"Protocol Response and Depositor Compensation","sources":[{"url":"https://x.com/script3official/status/2025403423840141450","name":"Script3 official statement on X","type":"official","credibility":2},{"url":"https://blocksec.com/blog/yieldblox-dao-incident-on-stellar-oracle-misconfiguration-enabled-a-10m-drain","name":"YieldBlox DAO Incident on Stellar - BlockSec","type":"research","credibility":2},{"url":"https://www.halborn.com/blog/post/explained-the-yieldblox-hack-february-2026","name":"Explained: The YieldBlox Hack (February 2026) - Halborn","type":"research","credibility":2}],"severity":"medium"},{"content":"Blend V2 underwent a $125,000 Code4rena competitive audit combined with a Certora Formal Verification component, running from February 24 to March 17, 2025, approximately one year before the exploit. This was reported to be the first Rust/Soroban formal verification contest in DeFi history, with the Certora component focused on the Backstop contract's solvency and lending core invariants.\n\nThe February 2026 exploit did not bypass any of the formally verified properties. The health-factor check that permitted the attacker's borrows functioned exactly as designed and verified — it correctly evaluated collateral value against liabilities using the oracle-reported price, which was technically accurate given the available market data. The vulnerability resided in the oracle price input being manipulable through a thin market, a risk surface outside the scope of the formal verification engagement. Security researchers noted this as an illustration that formal verification of smart contract logic does not preclude oracle manipulation attacks arising from external data quality failures.","heading":"Prior Security Audits","sources":[{"url":"https://code4rena.com/audits/2025-02-blend-v2-audit-certora-formal-verification","name":"Blend V2 Audit + Certora Formal Verification - Code4rena","type":"research","credibility":2},{"url":"https://rekt.news/yieldblox-rekt","name":"Yieldblox - Rekt News","type":"news_article","credibility":2}],"severity":"medium"},{"content":"Multiple independent security firms — including Halborn, BlockSec, and QuillAudits — converged on a consistent root cause: a thin-liquidity oracle manipulation attack enabled by compounding pool-operator configuration decisions rather than a flaw in Blend V2 core protocol code. The four contributing systemic weaknesses identified were: (1) listing USTRY as collateral despite its near-zero SDEX liquidity, (2) relying solely on the Reflector VWAP oracle without minimum liquidity or volume validity gates, (3) absence of circuit-breaker logic for anomalous price deviations, and (4) absence of multi-source price aggregation for the USTRY asset. Security researchers noted that removing any single one of these conditions would have defeated the exploit.\n\nThe attack pattern is a well-documented class of DeFi exploit. Functionally similar mechanics were employed in the Mango Markets exploit in October 2022 and numerous earlier incidents. The YieldBlox incident is notable as the first major exploit of this scale on Stellar's Soroban smart contract environment, and for its exceptionally high capital efficiency: approximately $160,000 in real-value collateral was used to extract approximately $10.97 million, a roughly 68-fold leverage ratio.","heading":"Root Cause Assessment and Classification","sources":[{"url":"https://blocksec.com/blog/yieldblox-dao-incident-on-stellar-oracle-misconfiguration-enabled-a-10m-drain","name":"YieldBlox DAO Incident on Stellar - BlockSec","type":"research","credibility":2},{"url":"https://www.halborn.com/blog/post/explained-the-yieldblox-hack-february-2026","name":"Explained: The YieldBlox Hack (February 2026) - Halborn","type":"research","credibility":2},{"url":"https://www.quillaudits.com/blog/hack-analysis/yeildblox-10m-hack-explained","name":"YeildBlox $10M Hack (Oracle Manipulation - Explained) - QuillAudits","type":"research","credibility":2},{"url":"https://dev.to/ohmygod/the-yieldblox-10m-oracle-poisoning-how-one-trade-in-a-dead-market-drained-an-entire-lending-pool-2k5d","name":"The YieldBlox $10M Oracle Poisoning - DEV Community","type":"other","credibility":3}],"severity":"high"},{"content":"The YieldBlox exploit was among the largest DeFi incidents of early 2026. CCN included it in a running total of DeFi losses exceeding $400 million across protocols through mid-2026. BlockSec's weekly security roundup for February 23 through March 1, 2026 cited it as the most significant incident of that period. Security analysts identified parallels with oracle manipulation incidents on other chains in 2026, including Venus Protocol and Moonwell, underscoring a systemic industry pattern of protocols treating oracle output as ground truth without validating the quality of underlying market data. The incident reinforced longstanding findings that single-source, DEX-derived VWAP oracles with no liquidity depth validation represent a persistent and exploitable weakness in DeFi lending protocol design.","heading":"Broader DeFi Context","sources":[{"url":"https://www.ccn.com/education/crypto/defi-hacks-exploits-causes-crypto-stolen-2026/","name":"Biggest DeFi Hacks and Exploits of 2026 - CCN","type":"news_article","credibility":2},{"url":"https://blocksec.com/blog/weekly-web3-security-incident-roundup-feb-23-mar-1-2026","name":"Weekly Web3 Security Incident Roundup Feb 23 - Mar 1 2026 - BlockSec Blog","type":"research","credibility":2},{"url":"https://crypto-economy.com/stellar-based-lending-protocol-hit-by-oracle-manipulation-attack/","name":"Stellar-Based Lending Protocol Hit by Oracle Manipulation Attack - Crypto Economy","type":"news_article","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2025-02-24","event":"Blend V2 Code4rena competitive audit with Certora Formal Verification launched, with a $125,000 USDC prize pool. Reported as the first Rust/Soroban formal verification contest in DeFi.","source":"Code4rena audit listing","source_url":"https://code4rena.com/audits/2025-02-blend-v2-audit-certora-formal-verification"},{"date":"2026-02-14","event":"Attacker's primary Stellar reconnaissance wallet created, seeded with 56.32 XLM, eight days before the exploit.","source":"Rekt News on-chain forensics","source_url":"https://rekt.news/yieldblox-rekt"},{"date":"2026-02-21","event":"At 23:35 UTC, attacker creates SDEX manipulation burner account (GCNF5GNRIT6VWYZ7LXUZ33Q3SR2NUGO32F5X65VVKAEWWIQCKGYN75HB) with 15 XLM. At 23:38 UTC, attacker places inflated sell offer for USTRY at 107 USDC per USTRY, approximately 100-fold fair value.","source":"Rekt News on-chain forensics","source_url":"https://rekt.news/yieldblox-rekt"},{"date":"2026-02-22","event":"At 00:10:21 UTC, second attacker-controlled account executes price-setting trade of 0.05 USTRY at approximately $106.7, dominating the Reflector VWAP pricing window. At 00:24-00:25 UTC, attacker deposits USTRY collateral and borrows 1,000,196.70 USDC and 61,249,278.31 XLM, draining the entire pool of approximately $10.97 million.","source":"Rekt News; Halborn; BlockSec; QuillAudits","source_url":"https://rekt.news/yieldblox-rekt"},{"date":"2026-02-22","event":"Stellar Tier-1 validators coordinate to freeze approximately 48 million XLM (approximately $7.2-7.5 million) in attacker Stellar accounts before bridging can complete.","source":"Protos; Rekt News","source_url":"https://protos.com/yieldblox-lending-pool-hit-by-10m-hack-on-stellar/"},{"date":"2026-02-22","event":"Script3 issues public statement on X confirming exploit is isolated to a single pool, that no other Blend pools are affected, and commits to full depositor compensation for USDC, XLM, and EURC losses.","source":"Script3 on X","source_url":"https://x.com/script3official/status/2025403423840141450"},{"date":"2026-02-22","event":"YieldBlox Security Council sends on-chain bounty message offering 10% white-hat incentive with 72-hour deadline in exchange for return of frozen funds and cessation of legal pursuit.","source":"Rekt News","source_url":"https://rekt.news/yieldblox-rekt"},{"date":"2026-02-23","event":"Attacker consolidates approximately 380 ETH and bridges funds cross-chain between 09:17 and 09:26 UTC. Attacker does not respond to bounty offer before 72-hour deadline.","source":"Rekt News on-chain forensics","source_url":"https://rekt.news/yieldblox-rekt"},{"date":"2026-02-27","event":"Attacker moves 100 ETH to Tornado Cash (tx 0xdc082828a2358ccb33b3837b49bfe678c31259aad59c39c76916a53f8c73853b), signaling intent to launder rather than return funds.","source":"Rekt News on-chain forensics","source_url":"https://rekt.news/yieldblox-rekt"}],"sources_used":[{"url":"https://www.halborn.com/blog/post/explained-the-yieldblox-hack-february-2026","name":"Explained: The YieldBlox Hack (February 2026) - Halborn","type":"research","archive_url":"http://web.archive.org/web/20260315173622/https://www.halborn.com/blog/post/explained-the-yieldblox-hack-february-2026","credibility":2,"archive_timestamp":"2026-03-15T17:36:22+00:00"},{"url":"https://blocksec.com/blog/yieldblox-dao-incident-on-stellar-oracle-misconfiguration-enabled-a-10m-drain","name":"YieldBlox DAO Incident on Stellar: Oracle Misconfiguration Enabled a $10M+ Drain - BlockSec","type":"research","archive_url":"http://web.archive.org/web/20260315202324/https://blocksec.com/blog/yieldblox-dao-incident-on-stellar-oracle-misconfiguration-enabled-a-10m-drain","credibility":2,"archive_timestamp":"2026-03-15T20:23:24+00:00"},{"url":"https://rekt.news/yieldblox-rekt","name":"Yieldblox - Rekt News","type":"news_article","archive_url":"http://web.archive.org/web/20260414180157/https://rekt.news/yieldblox-rekt","credibility":2,"archive_timestamp":"2026-04-14T18:01:57+00:00"},{"url":"https://protos.com/yieldblox-lending-pool-hit-by-10m-hack-on-stellar/","name":"YieldBlox lending pool hit by $10M hack on Stellar - Protos","type":"news_article","archive_url":"http://web.archive.org/web/20260307153122/https://protos.com/yieldblox-lending-pool-hit-by-10m-hack-on-stellar/","credibility":2,"archive_timestamp":"2026-03-07T15:31:22+00:00"},{"url":"https://www.quillaudits.com/blog/hack-analysis/yeildblox-10m-hack-explained","name":"YeildBlox $10M Hack (Oracle Manipulation - Explained) - QuillAudits","type":"research","archive_url":"http://web.archive.org/web/20260312161912/https://www.quillaudits.com/blog/hack-analysis/yeildblox-10m-hack-explained","credibility":2,"archive_timestamp":"2026-03-12T16:19:12+00:00"},{"url":"https://x.com/script3official/status/2025403423840141450","name":"Script3 official statement on X","type":"official","archive_url":null,"credibility":2,"archive_timestamp":null},{"url":"https://code4rena.com/audits/2025-02-blend-v2-audit-certora-formal-verification","name":"Blend V2 Audit + Certora Formal Verification - Code4rena","type":"research","archive_url":"http://web.archive.org/web/20260305105518/https://code4rena.com/audits/2025-02-blend-v2-audit-certora-formal-verification","credibility":2,"archive_timestamp":"2026-03-05T10:55:18+00:00"},{"url":"https://blocksec.com/blog/weekly-web3-security-incident-roundup-feb-23-mar-1-2026","name":"Weekly Web3 Security Incident Roundup Feb 23 - Mar 1 2026 - BlockSec Blog","type":"research","archive_url":"http://web.archive.org/web/20260315202530/https://blocksec.com/blog/weekly-web3-security-incident-roundup-feb-23-mar-1-2026","credibility":2,"archive_timestamp":"2026-03-15T20:25:30+00:00"},{"url":"https://www.ccn.com/education/crypto/defi-hacks-exploits-causes-crypto-stolen-2026/","name":"Biggest DeFi Hacks and Exploits of 2026 - CCN","type":"news_article","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cryip.co/blend-protocol-exploit-10-8m-stolen-from-stellars-yieldblox-pool-via-oracle-manipulation/","name":"Blend Protocol Exploit: $10.8M Stolen from Stellar's YieldBlox Pool - Cryip","type":"news_article","archive_url":"http://web.archive.org/web/20260414174911/https://cryip.co/blend-protocol-exploit-10-8m-stolen-from-stellars-yieldblox-pool-via-oracle-manipulation/","credibility":3,"archive_timestamp":"2026-04-14T17:49:11+00:00"},{"url":"https://medium.com/@cryip/10-8m-oracle-manipulation-exploit-on-stellars-blend-protocol-6bdcbb1568c0","name":"$10.8M Oracle Manipulation Exploit on Stellar's Blend Protocol - Medium/Cryip","type":"other","archive_url":"http://web.archive.org/web/20260304075418/https://medium.com/@cryip/10-8m-oracle-manipulation-exploit-on-stellars-blend-protocol-6bdcbb1568c0","credibility":3,"archive_timestamp":"2026-03-04T07:54:18+00:00"},{"url":"https://medium.com/coinmonks/yieldblox-10m-exploit-d00f9ff88d27","name":"YieldBlox $10M Exploit: How a Single Trade Broke an Oracle - Coinmonks/Medium","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://dev.to/ohmygod/the-yieldblox-10m-oracle-poisoning-how-one-trade-in-a-dead-market-drained-an-entire-lending-pool-2k5d","name":"The YieldBlox $10M Oracle Poisoning - DEV Community","type":"other","archive_url":"http://web.archive.org/web/20260329022437/https://dev.to/ohmygod/the-yieldblox-10m-oracle-poisoning-how-one-trade-in-a-dead-market-drained-an-entire-lending-pool-2k5d","credibility":3,"archive_timestamp":"2026-03-29T02:24:37+00:00"},{"url":"https://dev.to/quillaudits/how-a-single-trade-caused-yieldblox-10m-loss-34hk","name":"How a Single Trade Caused YieldBlox $10M Loss - DEV Community / QuillAudits","type":"research","archive_url":"https://web.archive.org/web/20260727085616/https://dev.to/quillaudits/how-a-single-trade-caused-yieldblox-10m-loss-34hk","credibility":2,"archive_timestamp":"2026-07-27T08:56:16+00:00"},{"url":"https://github.com/saariuslystoned/blnd-huntr","name":"blnd-huntr: Forensic investigation dashboard for the February 2026 Blend Protocol exploit - GitHub","type":"on_chain","archive_url":"https://web.archive.org/web/20260726143935/https://github.com/saariuslystoned/blnd-huntr","credibility":3,"archive_timestamp":"2026-07-26T14:39:35+00:00"},{"url":"https://crypto-economy.com/stellar-based-lending-protocol-hit-by-oracle-manipulation-attack/","name":"Stellar-Based Lending Protocol Hit by Oracle Manipulation Attack - Crypto Economy","type":"news_article","archive_url":"http://web.archive.org/web/20260315203728/https://crypto-economy.com/stellar-based-lending-protocol-hit-by-oracle-manipulation-attack/","credibility":3,"archive_timestamp":"2026-03-15T20:37:28+00:00"}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-code-investigator","created_at":"2026-06-07T23:29:42.920406+00:00","updated_at":"2026-07-27T09:07:09.136397+00:00"}}