All news
Articlex.com@script3officialtoday

Comet BLND-USDC LP Incident - Post Mortem

On August 25, an attacker exploited a Comet smart contract bug that failed to verify token inputs in swap functions, extracting 717,518 USDC from the BLND-USDC liquidity pool. Community white hats quickly recovered 190k USDC and 23M BLND before copycat attacks. Script3 is leading recovery and remediation efforts; Blend protocol lending continues but backstop deposits are at risk due to the non-upgradeable LP token.

SecuritySmart ContractsDeFi
Lumen Loop's take

On August 25, 2026, an attacker exploited a vulnerability in the Comet smart contract that ports Balancer V1 to Stellar. The bug failed to verify that swap inputs and outputs referenced different tokens; when the same token was used for both, the contract's internal accounting missed the swapped amount, creating an imbalance that attackers could amplify through flash loans. The attacker extracted 717,518 USDC in minutes before Script3 detected the activity. Community white hats then deployed the same technique to rescue 190k USDC and 23.2M BLND before copycat attackers could strike. Script3 is leading recovery and remediation of the captured funds. Blend lending continues normally, but the protocol's V2 backstop cannot be upgraded to remove its dependence on the vulnerable BLND-USDC LP token, forcing a wind-down toward V3. The Comet pool itself is unsafe and frozen.

Mentioned projects
2 projects linked
B
Blend CapitalFinancial Protocols
SCFAudited
DeFiLending & BorrowingLiquidity

Blend is a decentralized finance (DeFi) protocol built on Stellar's Soroban smart contract platform, enabling users, DAOs, and i…

View →
C
CometFinancial Protocols
SCFAudited
DEXDeFi

Comet is a weighted AMM protocol that offers soroban projects a flexible solution set when picking liquidity venues.

View →