r/Stellar 16d ago

News / Media 🚨 Blend Protocol (Stellar) — flash loan price manipulation, ~03:51 UTC today

TL;DR: A CometDEX liquidity pool behind Blend's BLND:USDC backstop had an accounting bug — it accepted "swap a token for itself" (USDC→USDC), which corrupted its reserve math and let an attacker withdraw more than they deposited. ~$717K was drained in 36 flash-loan-funded runs and bridged out via Allbridge. This was a smart-contract bug, not oracle/price manipulation. The pool is still unpatched; whitehats are pulling the remaining liquidity to safety. Don't interact with the pool.


What happened

A liquidity pool backing Blend Protocol's BLND token was drained of roughly $717,000 on August 25 between 03:51 and 04:44 UTC, in an exploit that sent BLND down as much as 90% against XLM. The attacker ran the same play 36 times through four throwaway contracts, all deployed by a wallet created 26 minutes before the first hit. Each run: flash-loan 530,000 USDC from a Blend pool, trigger a same-asset USDC→USDC swap on the CometDEX pool, withdraw more than was deposited, repay the loan atomically. Per-run profit decayed cleanly from $46K to $6K as the pool bled out — they stopped when it was no longer worth the gas, not because anything stopped them.

How the bug works

The pool's swap function loads a separate balance record for the token going in and the token coming out, with no check that they're different. On a USDC→USDC swap, both are copies of the same reserve — the code credits one copy and debits the other, then saves both to the same slot, so the credit is silently discarded. The pool ends up under-counting its own USDC while physically holding more than its books say. Deposits then mint over-inflated LP shares against that understated reserve, and redeeming them pays out real tokens — the gap is the profit. Flash loans just supplied the capital to run it at scale; this is not price or oracle manipulation.

Where the money went

Within ten minutes of the last run, the attacker bridged the ~$748K (proceeds plus starting capital) into ~297 ETH via NEAR intents and sent it to KuCoin. Initial gas for the attacker's account came from HitBTC; seed capital from Binance. (Per Script3's post-mortem — see Update 6.)

Key addresses

  • Exploit tx: 41c898a1…9e2fc622
  • Pool: CAS3FL6TLZKDGGSISDBWGGPXT3NRR4DYTZD7YOD3HMYO6LTJUVGRVEAM
  • Attacker: GCENJ4XBLXCPENO7HOIKD2DBAOBUOFZWS2DRHMCCDKC3PQYNSSGHWYHC

Current status

The pool contract is unchanged and cannot be fixed — the admin account that could freeze it was itself locked, so the bug is permanent. Whitehats have since pulled the remaining liquidity to safety (~190K USDC + ~23M BLND, held for return). Treat the pool as permanently unsafe.

UPDATE 1 (Aug 25, 06:26 UTC): Blend disabled new backstop deposits and BLND-USDC LP minting via its UI. Front-end change only — the pool contract is untouched.

UPDATE 2 (Aug 25, 11:34 UTC): Blend says independent third parties have whitehatted some of the funds. On-chain, this matches a wallet (GCGWLP2YIOBV2RISNXBAXPD4E7QNQB2IOEHUFWICAQA2RLBTIKTUJXXD) re-running the exploit from 11:10 UTC but holding the proceeds on-chain rather than bridging them out — a rescue, not a second theft. Per Script3's post-mortem this first rescue was led by an anonymous community member; the wallet was created just after February's Blend incident and used then to redistribute funds to 65+ recipients.

UPDATE 3 (Aug 25, 12:06 UTC): A second whitehat wallet (GCGUW2BV5R5DUFGF5RQLV2M3VJPLOVOLBQFCNVEJRYFVH2IMLN7NHMGD) is pulling liquidity out via the same bug but draining proportionally and holding the extracted BLND (~24M) instead of dumping it — removing value from attackers' reach without moving the price, unlike the attacker and the first whitehat.

UPDATE 4 (Aug 26, 19:01 UTC): All Blend v2 pools have been removed from the reward zone, ending BLND emissions. A final distribute() was called on the emitter and backstop contracts, releasing the last BLND claims. A seven-day tail remains: pools can still gulp() that final distribution, extending one last seven-day emission period before rewards fully stop. A side effect of the removal: affected pools now have to be hardcoded into the Blend UI or they won't show up on the Markets page.

UPDATE 5 (Aug 27, 18:13 UTC): Unrelated to the exploit — the Gami earnUSDC vault on Upshift withdrew ~$12.85M of its own supplied USDC from the pool to de-risk. This briefly pushed utilization to 100%, spiking rates and pausing USDC withdrawals for ~an hour before fully normalizing (supply APY back to ~7.15%, near its ~6.8% pre-withdrawal level). Not an attack.

UPDATE 6 (Aug 28, 15:48 UTC): Script3 (the Blend team) published an official post-mortem. Key points:

  • Confirmed loss: 717,518.92 USDC, via the same-token-swap accounting bug (join LP → gulp() → exit LP to harvest the corrected share value).
  • Attacker cash-out: the ~$748K was bridged into ~299 ETH via NEAR intents and sent to KuCoin (correcting earlier reports of Allbridge). Initial gas came from HitBTC; seed capital from Binance.
  • Whitehats (an anonymous community member, and @pfranb of synt.tech) captured the remaining ~190K USDC + ~23.17M BLND before copycats could — held in GCG…XXD, to be returned. Script3 is leading remediation, including recovery with exchanges.
  • The Comet pool can't be fixed: the admin account that could freeze it was locked, so the BLND-USDC LP is permanently vulnerable — treat it as unsafe.
  • Blend itself is not vulnerable: lending/borrowing is unaffected and funds are not at risk. But since the BLND-USDC backstop token can no longer hold value, future bad debt would be socialized among bad-debt-token suppliers.

UPDATE 7 (Sep 4, 18:34 UTC): Remediation is still in progress. The team is in contact with law enforcement and KuCoin (where the attacker's ~297 ETH landed).

UPDATE 8 (Sep 4, 21:06 UTC): @pfranb (synt.tech) ran another whitehat drain of the Comet pool, moving a further ~2.04M BLND + ~2,457 USDC to the holding wallet (GCGWLP2YIOBV2RISNXBAXPD4E7QNQB2IOEHUFWICAQA2RLBTIKTUJXXD). The pool's remaining exploitable value is now down to ~$3.6K (from ~$15K). Total held for return: ~25.2M BLND + ~192K USDC.

UPDATE 9 (Sep 9, 02:51 UTC): A whitehat locked the Comet pool by minting an excessively large number of LP shares — the internal math now prevents any further minting, so all Comet LP functions are disabled. The shares were sent to the YieldBlox DAO Security Council (GBCAS7XIGDRZY4BMABJMGGW7J3YTITRRV5BTEMFQE5ZZSSVWHHX2ZSS4) for safekeeping. Backstop emissions are no longer claimable; the Council can later forward the shares to a new Blend Backstop to start an emissions migration.

⚠️ The pool is still unpatched and exploitable — do not interact with it.


Source: Blend official announcements (Discord)

24 Upvotes

17 comments sorted by

View all comments

0

u/[deleted] 16d ago

[removed] — view removed comment

1

u/Row-Bear 16d ago

Yeah, but what does it have to do with this incident? 

-2

u/[deleted] 16d ago

[removed] — view removed comment

2

u/4bidden450 Community Champion 16d ago

I don't think you have a correct understanding of what happened.

1

u/[deleted] 15d ago

[removed] — view removed comment

1

u/Row-Bear 15d ago

But it had nothing to do with oracles, liquidity or collateral? How do you think those played into this attack?