Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Here is why Strategy's dividend-paying crypto stock is crashing to near-historic lows

June 16, 2026

HashKey Chain Partners Morpho to Blend Compliance and DeFi for Institutional CeDeFi and RWA Lending

June 16, 2026

Kraken Brings Regulated Perpetual Futures Onshore to US Users

June 16, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Stellar-Based Lending Protocol Hit by Oracle Manipulation Attack
Security

Stellar-Based Lending Protocol Hit by Oracle Manipulation Attack

February 24, 2026No Comments2 Mins Read

TL;DR:

  • An attacker manipulated the price of the USTRY stablecoin from $1.05 to over $100 to drain funds.
  • Stellar validators reacted quickly, freezing 80% of the stolen $XLM tokens.
  • The development team assures that the attack was an isolated event in a single community pool.

This past weekend, the DeFi ecosystem was hit when the Stellar Blend protocol suffered a $10.8M exploit due to a coordinated oracle manipulation attack. The event resulted in the loss of at least $10.8 million, specifically affecting the autonomous USTRY/$XLM market.

To clarify:

This incident was isolated to a single asset in a single community managed pool.

No other Blend pools are vulnerable to the same oracle manipulation vector. There are no vulnerabilities in the Blend smart contracts.

Blend allows pool creators to choose their own… https://t.co/4M9VpIMVTw

— Script3 (@script3official) February 23, 2026

Technical reports on the incident reveal that the attacker managed to artificially inflate the price of the USTRY stablecoin from $1.05 to over $100 in a single transaction. Taking advantage of the inflated price, the hacker used the manipulated oracle to borrow 61 million $XLM and 1 million USDC.

Because USTRY liquidity had been temporarily withdrawn, the system detected no trading activity for a 15-minute window. This operational gap allowed the false price marker to be validated, facilitating the massive withdrawal of assets toward the Ethereum network.

Security Response and Recovery of Stolen Assets

The incident was severe, but Stellar network validators reacted immediately and managed to mitigate the financial impact. Thanks to their action, 80% of the stolen $XLM was frozen, preventing the attacker from liquidating the majority of the loot.

See also  Embargo Ransomware Gang Amasses $34.2m in Attack Proceeds

Meanwhile, the YieldBlox Security Council sent an on-chain message to the attacker offering a 10% “white hat” bounty. The proposal seeks the return of the remaining funds in exchange for not initiating legal action and facilitating the return of the 48 million $XLM held in the frozen addresses.

In summary, Script3 developers clarified that the vulnerability was limited to a community-managed pool and does not affect other Blend markets. However, this event highlights the importance of oracle redundancy to prevent price manipulation attacks in the future.

Source link

attack hit Lending Manipulation Oracle protocol StellarBased

Related Posts

HashKey Chain Partners Morpho to Blend Compliance and DeFi for Institutional CeDeFi and RWA Lending

June 16, 2026

India’s NHRC Raises Alarm Over Digital Arrest Scams

June 16, 2026

Rokarolla Trojan Combines Banking Fraud With Device Surveillance

June 16, 2026

Pyra to Cease Operations Following Drift Hack, Launches Fund Withdrawal Portal

June 16, 2026
Top Posts

Agentik.md Launches Open-Source AI Safety Specifications Ahead of 2026 EU and Colorado AI Regulations

March 14, 2026

Lombard migrates $1B in Bitcoin-backed assets to Chainlink CCIP after $292M exploit shakes LayerZero confidence

May 17, 2026

Crypto devs face new threat from Claude-based malware

May 3, 2026

Type above and press Enter to search. Press Esc to cancel.