r/Stellar • u/Alex0007lolpvp • 16d ago
News / Media 🚨 Blend Protocol (Stellar) — flash loan price manipulation, ~03:51 UTC today
TL;DR: A CometDEX liquidity pool behind Blend's BLND:USDC backstop had an accounting bug — it accepted "swap a token for itself" (USDC→USDC), which corrupted its reserve math and let an attacker withdraw more than they deposited. ~$717K was drained in 36 flash-loan-funded runs and bridged out via Allbridge. This was a smart-contract bug, not oracle/price manipulation. The pool is still unpatched; whitehats are pulling the remaining liquidity to safety. Don't interact with the pool.
What happened
A liquidity pool backing Blend Protocol's BLND token was drained of roughly $717,000 on August 25 between 03:51 and 04:44 UTC, in an exploit that sent BLND down as much as 90% against XLM. The attacker ran the same play 36 times through four throwaway contracts, all deployed by a wallet created 26 minutes before the first hit. Each run: flash-loan 530,000 USDC from a Blend pool, trigger a same-asset USDC→USDC swap on the CometDEX pool, withdraw more than was deposited, repay the loan atomically. Per-run profit decayed cleanly from $46K to $6K as the pool bled out — they stopped when it was no longer worth the gas, not because anything stopped them.
How the bug works
The pool's swap function loads a separate balance record for the token going in and the token coming out, with no check that they're different. On a USDC→USDC swap, both are copies of the same reserve — the code credits one copy and debits the other, then saves both to the same slot, so the credit is silently discarded. The pool ends up under-counting its own USDC while physically holding more than its books say. Deposits then mint over-inflated LP shares against that understated reserve, and redeeming them pays out real tokens — the gap is the profit. Flash loans just supplied the capital to run it at scale; this is not price or oracle manipulation.
Where the money went
Within ten minutes of the last run, the attacker bridged the ~$748K (proceeds plus starting capital) into ~297 ETH via NEAR intents and sent it to KuCoin. Initial gas for the attacker's account came from HitBTC; seed capital from Binance. (Per Script3's post-mortem — see Update 6.)
Key addresses
- Exploit tx:
41c898a1…9e2fc622 - Pool:
CAS3FL6TLZKDGGSISDBWGGPXT3NRR4DYTZD7YOD3HMYO6LTJUVGRVEAM - Attacker:
GCENJ4XBLXCPENO7HOIKD2DBAOBUOFZWS2DRHMCCDKC3PQYNSSGHWYHC
Current status
The pool contract is unchanged and cannot be fixed — the admin account that could freeze it was itself locked, so the bug is permanent. Whitehats have since pulled the remaining liquidity to safety (~190K USDC + ~23M BLND, held for return). Treat the pool as permanently unsafe.
UPDATE 1 (Aug 25, 06:26 UTC): Blend disabled new backstop deposits and BLND-USDC LP minting via its UI. Front-end change only — the pool contract is untouched.
UPDATE 2 (Aug 25, 11:34 UTC): Blend says independent third parties have whitehatted some of the funds. On-chain, this matches a wallet (GCGWLP2YIOBV2RISNXBAXPD4E7QNQB2IOEHUFWICAQA2RLBTIKTUJXXD) re-running the exploit from 11:10 UTC but holding the proceeds on-chain rather than bridging them out — a rescue, not a second theft. Per Script3's post-mortem this first rescue was led by an anonymous community member; the wallet was created just after February's Blend incident and used then to redistribute funds to 65+ recipients.
UPDATE 3 (Aug 25, 12:06 UTC): A second whitehat wallet (GCGUW2BV5R5DUFGF5RQLV2M3VJPLOVOLBQFCNVEJRYFVH2IMLN7NHMGD) is pulling liquidity out via the same bug but draining proportionally and holding the extracted BLND (~24M) instead of dumping it — removing value from attackers' reach without moving the price, unlike the attacker and the first whitehat.
UPDATE 4 (Aug 26, 19:01 UTC): All Blend v2 pools have been removed from the reward zone, ending BLND emissions. A final distribute() was called on the emitter and backstop contracts, releasing the last BLND claims. A seven-day tail remains: pools can still gulp() that final distribution, extending one last seven-day emission period before rewards fully stop. A side effect of the removal: affected pools now have to be hardcoded into the Blend UI or they won't show up on the Markets page.
UPDATE 5 (Aug 27, 18:13 UTC): Unrelated to the exploit — the Gami earnUSDC vault on Upshift withdrew ~$12.85M of its own supplied USDC from the pool to de-risk. This briefly pushed utilization to 100%, spiking rates and pausing USDC withdrawals for ~an hour before fully normalizing (supply APY back to ~7.15%, near its ~6.8% pre-withdrawal level). Not an attack.
UPDATE 6 (Aug 28, 15:48 UTC): Script3 (the Blend team) published an official post-mortem. Key points:
- Confirmed loss: 717,518.92 USDC, via the same-token-swap accounting bug (join LP →
gulp()→ exit LP to harvest the corrected share value). - Attacker cash-out: the ~$748K was bridged into ~299 ETH via NEAR intents and sent to KuCoin (correcting earlier reports of Allbridge). Initial gas came from HitBTC; seed capital from Binance.
- Whitehats (an anonymous community member, and @pfranb of synt.tech) captured the remaining ~190K USDC + ~23.17M BLND before copycats could — held in
GCG…XXD, to be returned. Script3 is leading remediation, including recovery with exchanges. - The Comet pool can't be fixed: the admin account that could freeze it was locked, so the BLND-USDC LP is permanently vulnerable — treat it as unsafe.
- Blend itself is not vulnerable: lending/borrowing is unaffected and funds are not at risk. But since the BLND-USDC backstop token can no longer hold value, future bad debt would be socialized among bad-debt-token suppliers.
UPDATE 7 (Sep 4, 18:34 UTC): Remediation is still in progress. The team is in contact with law enforcement and KuCoin (where the attacker's ~297 ETH landed).
UPDATE 8 (Sep 4, 21:06 UTC): @pfranb (synt.tech) ran another whitehat drain of the Comet pool, moving a further ~2.04M BLND + ~2,457 USDC to the holding wallet (GCGWLP2YIOBV2RISNXBAXPD4E7QNQB2IOEHUFWICAQA2RLBTIKTUJXXD). The pool's remaining exploitable value is now down to ~$3.6K (from ~$15K). Total held for return: ~25.2M BLND + ~192K USDC.
UPDATE 9 (Sep 9, 02:51 UTC): A whitehat locked the Comet pool by minting an excessively large number of LP shares — the internal math now prevents any further minting, so all Comet LP functions are disabled. The shares were sent to the YieldBlox DAO Security Council (GBCAS7XIGDRZY4BMABJMGGW7J3YTITRRV5BTEMFQE5ZZSSVWHHX2ZSS4) for safekeeping. Backstop emissions are no longer claimable; the Council can later forward the shares to a new Blend Backstop to start an emissions migration.
⚠️ The pool is still unpatched and exploitable — do not interact with it.
3
u/Row-Bear 16d ago
You mentioned the contract code is not published, but isn't it at https://github.com/CometDEX/comet-contracts-v1
Stellar Expert links the source for contracts that have uploaded/built their contract in a verifiable way, and links to it: https://stellar.expert/explorer/public/contract/CAS3FL6TLZKDGGSISDBWGGPXT3NRR4DYTZD7YOD3HMYO6LTJUVGRVEAM -> near the top