Tweet by Script3
Primary Source ↗Incident Details
A lending pool operated by YieldBlox on the Stellar blockchain was emptied of around $10.2 million in an oracle manipulation attack on the Reflector oracle supplying prices for the USTRY/USDC market. Reflector has said that there was no flaw with their oracle, and that market illiquidity caused the problem. “Reflector quoted correct prices. … but it’s impossible to quote adequate prices for a market fully handled by a single market-maker with almost zero trading activity.“The attacker was able to manipulate the oracle price to show that USTRY was priced at $100 (rather than its actual trading price of around $1.05). Then, they borrowed against the overvalued asset, withdrawing XLM and USDC priced at $10.2 million. However, around 48 million of the stolen XLM (~$7.2 million) were frozen.
Total loss estimated at $10,200,000.
Technical Details
- Initial Attack Vector
- Oracle price manipulation
- Vendor / Product
- YieldBlox theft
Timeline
- 2026-02-21 Breach occurred
- 2026-02-21 Publicly disclosed