Stellar

What Is Reflector? Stellar's Native Price Oracle

How Reflector, Stellar's native oracle, works: three feeds, a 4-of-7 node multisig, 5-minute VWAP prices, SEP-40, consumer-side TWAP and the YieldBlox lesson.

What is Reflector: Stellar's native price oracle, its feeds, SEP-40 interface and node consensus

Updated 9 October 2026: feed settings, asset counts and the live contract interface read directly from Reflector's three mainnet contracts; node signer threshold read from Horizon; TWAP change traced to the v3 commit; YieldBlox timeline from Script3's post-mortem and Reflector's statement.

Reflector is Stellar's homegrown price oracle: seven nodes compute prices from markets, sign them, and write one agreed price every five minutes into Soroban contracts that any protocol can read. It is free to read, follows the SEP-40 standard, and is the oracle behind most of Blend's lending. It also reports exactly what a market says, which is a strength until the market is too thin to mean anything.

Key takeaways
  • Three mainnet feeds: Stellar DEX prices (52 assets), external exchange prices (16) and fiat exchange rates (24), as read on-chain on 9 October 2026.
  • Updates need four of seven node signatures. Prices are five-minute volume-weighted averages, stored with 14 decimals for 24 hours.
  • The contract no longer offers a TWAP. Consumers average recent records themselves.
  • In February 2026 Reflector correctly reported a manipulated USTRY price; the YieldBlox pool that relied on it lost about $10M.
The short version

Reflector answers "what did this asset trade at in the last five minutes?" honestly and cheaply. Whether that answer is safe to lend against depends on the market behind it, and on whether the consuming contract smooths, cross-checks and bounds it.

Reflector by the numbers (October 2026)

Reflector runs three mainnet oracle contracts, all reporting a 300-second resolution, 14 decimals and 24-hour history retention when queried on 9 October 2026. Each is written by an account with seven signers and a threshold of four. DefiLlama lists Reflector as the oracle for Blend Pools V2, which held $146.6M that day.

FeedContractQuoted inAssets (9 Oct 2026)
Stellar DEXCALI2B…LE6MUSDC52
External CEX & DEXCAFJZQ…4DLNUSD16, including BTC, ETH, XLM, SOL, USDC, USDT, EURC
Fiat FXCBKGPW…CJZCUSD24, including EUR, GBP, MXN, BRL, NGN, KES and gold
  • Age: the Stellar DEX and external feed contracts were created on 4 March 2024, per StellarExpert; the FX feed on 22 April 2025.
  • Audits: OtterSec (January 2024; six findings, one high) and a Code4rena contest on Reflector v3 (October–November 2025; one high and five medium issues). Both reports are in Reflector's contract repository.
  • Token: XRF, a fixed supply of 120,000,000 with a locked issuer, used to pay for paid services and for governance. Spent XRF is burned.
  • Value secured: DefiLlama's protocol data names Reflector as the oracle for Blend Pools V2 ($146.6M), plus two very small listings. That is a TVL proxy, not DefiLlama's official "total value secured", which we could not access.

How to use this, depending on who you are

  • You build a lending market or vault: read the Pulse feed through SEP-40, compute your own TWAP over several records, check every timestamp against the ledger time, and cross-check against a second provider. See oracles on Stellar for the alternatives.
  • You need RWA or fund prices: a DEX price for a thinly traded tokenised fund can be meaningless. Consider a NAV-style feed instead, as covered in RWAs as DeFi collateral.
  • You need a different interface or provider set: Chainlink went live on Stellar on 29 September 2026 with its own interface; see Chainlink on Stellar.
  • You deposit, not build: ask which Reflector feed prices each collateral asset in your pool, and how much that asset actually trades.

What Reflector is

Reflector describes itself as a combination of smart contracts and peer-to-peer consensus among data-provider nodes run by Stellar ecosystem organisations. It is built by the team behind the StellarExpert block explorer, which commissioned its first audit. Its contracts live on Soroban.

That last point matters on Stellar. Soroban contracts cannot call the internet; any outside data must be written on-chain first. Reflector's nodes do that writing, and any contract can then read the stored price in an ordinary cross-contract call. Reflector's own integrations list names Blend, Orbit CDP, DeFindex, Laina, EquitX, SorobanDomains, Etherfuse, Normal, Stratum, xBidAI and Slender. For how oracles fit into Stellar's lending stack, see what is Blend.

How the nodes agree

Each feed contract has an admin account whose signers are the node keys. Every node independently computes the same price from the same data, signs the resulting update, and shares it with the others. If more than half the nodes produce an identical update, it is submitted. On 9 October 2026 each admin account had seven signers and a threshold of four.

Determinism is the design: because the nodes run identical calculations over identical inputs, honest nodes produce byte-identical transactions, and mismatches are discarded rather than averaged. A minority of faulty or malicious nodes cannot write a price; a majority could. We could not find a public list of who runs the seven nodes. Reflector's DAO, in which only node operators can be members, governs with equal votes and simple majority.

How prices are made — five-minute VWAP

For Stellar assets, nodes read trades through Stellar RPC; for external assets, they pull from exchange, bank and forex sources. Each period's price is a volume-weighted average of the trades in that window, stamped to the start of the five-minute slot and stored with 14 decimals. Records are kept for 24 hours in temporary storage.

VWAP over five minutes is a sensible default for liquid markets: one odd trade among many barely moves it. In a market with no other trades, though, a single trade is the VWAP. Reflector's documentation also warns that history in temporary storage can be evicted, and tells consumers to check record timestamps against ledger time, so a contract never acts on a stale price without noticing.

Reflector sells three products on top of the same machinery. Pulse is the free, five-minute feed most protocols use; someone still pays its upkeep. Beam offers one-minute granularity, updates on price changes and a two-hour heartbeat, for a per-call fee in XRF. Flare, formerly called subscriptions, pushes webhook alerts when a price crosses a threshold, paid from an XRF deposit.

SEP-40 — the interface

SEP-40 is a draft Stellar standard, created in February 2023 and co-authored by OrbitLens, who also writes Reflector's contract code, that defines how contracts read prices: base, assets, decimals, resolution, price at a timestamp, the last N prices, and the latest price. A contract written against it can switch to any compliant oracle without code changes.

Reflector's live mainnet contract implements those calls (lastprice, price, prices, decimals, resolution, assets, base) plus housekeeping functions. Blend requires only lastprice and decimals. SEP-40 deliberately says nothing about how a provider gathers data, only how it is read. The standard does advise consumers to "apply TWAP whenever possible", but TWAP is not part of the interface.

TWAP is now the consumer's job

Reflector's original contract had a twap function that averaged up to 20 recent records. Version 3, merged on 9 March 2026, moved it and the cross-price functions into an external library. The live contract has no TWAP method; its documentation says these calculations happen in the consumer contract.

In practice a consumer calls prices(asset, n), checks that it received n records with no gaps and that the newest is fresh, and averages them. The old built-in version returned nothing if any record was missing or stale, a behaviour worth copying. Moving the logic out puts the choices where they belong: a lending market can pick its own window, use a geometric mean, or combine Reflector with another provider. It also means a protocol that does nothing gets a raw five-minute price. XOXNO's Stellar markets, for example, read a three-period Reflector TWAP and cross-check it against RedStone, as described in oracles on Stellar.

The YieldBlox lesson

On 22 February 2026 an attacker pushed USTRY on the Stellar DEX from about $1.06 to $107 with one trade after the only market maker withdrew its offers. Reflector's DEX feed reported it, and the YieldBlox pool on Blend let the attacker borrow about 61.3M XLM and 1.01M USDC against the inflated collateral.

Script3's post-mortem gives the timing. The market maker pulled its orders at 00:10:09 UTC; a trade at 107 USDC per USTRY went through at 00:10:21. Reflector published that price at 00:15:22 and again at 00:20:27, and the second update satisfied YieldBlox's check that required two consecutive updates. Pulse feeds do not post extra updates on price deviation, so there was no in-between price to contradict it. Script3 put the net loss at about $10.5M; other sources give $10.2M to $11M.

Reflector's own statement said hourly trading volume on that market had been under $1, and that it is "impossible to quote adequate prices for a market fully handled by a single market-maker". It said Reflector was not exploited, and that is technically right: the oracle did what it was built to do. Script3 reported that Tier 1 validators quarantined 48M of the stolen XLM and that suppliers were made whole. We found no announced change to Reflector's feeds in response. The fixes sit with consumers: do not list collateral whose only price comes from a market one trader controls; average over longer windows; cross-check; cap moves. The full incident is in Blend's 2026 incidents, and the general lesson in DeFi risks.

How these fit together

Reflector is infrastructure in the narrow sense: it moves market data on-chain, cheaply and with a clear trust model of four signatures out of seven. It does not judge whether a market deserves to be trusted. SEP-40 makes it easy to adopt and easy to replace, and the v3 decision to push TWAP into consumers makes the division of responsibility explicit. With RedStone, Band, Pyth and now Chainlink also on Stellar, a careful protocol has no reason to rely on one oracle alone.

The takeaway

Reflector is a good oracle for assets that trade. Its prices are honest five-minute averages, signed by a node majority and readable through a standard interface. The risk is in what you point it at: a DEX feed for an asset with no market is a price anyone can set. If you build on it, add the TWAP, staleness and sanity checks yourself; if you deposit, ask whether your protocol has.

Sources: reflector-network/reflector-contract (README, audits folder, v3 commit 468c5f4, 9 Mar 2026); reflector-network/reflector-stellar-connector; reflector.network llms.txt, llms-full.txt and stellar.toml; Reflector's integrations list (reflector-website repo); read-only queries of Reflector's three mainnet contracts and Horizon admin accounts, 9 Oct 2026; StellarExpert contract pages; SEP-0040; developers.stellar.org oracle providers; docs.blend.capital, "Selecting an oracle"; Script3, "YieldBlox USTRY Oracle Manipulation — Post Mortem" (4 Mar 2026); Reflector's statement on X (22 Feb 2026); BlockSec and Halborn incident analyses; Code4rena 2025-10-reflector; DefiLlama protocols API, 9 Oct 2026.

Frequently asked questions

What is Reflector on Stellar?

Reflector is a price oracle built for Stellar's Soroban smart contracts. A group of independent nodes computes prices, signs them, and writes them on-chain through a shared account that needs four of seven node signatures. Contracts such as Blend's lending pools read those prices through the SEP-40 standard interface.

How often does Reflector update prices?

Its free Pulse feeds record a price every five minutes, the resolution reported by all three mainnet contracts on 9 October 2026. A paid product, Beam, offers one-minute granularity with updates on price changes and a two-hour heartbeat.

Does Reflector provide a TWAP?

Not any more. The original contract had a twap function, but version 3, merged in March 2026, moved it out to an external library. Reflector's documentation now says TWAP and cross-price calculations are done in the consumer contract, typically by averaging recent records from prices().

Was Reflector hacked in the YieldBlox exploit?

No. Reflector reported the price that actually traded on the Stellar DEX. The problem was that the USTRY market had less than $1 of hourly volume and a single market maker, so one trade could set the price. Read more in Blend's 2026 incidents.

WhaleHub Research
WhaleHub Research
Protocol research & education · WhaleHub

WhaleHub is a yield-optimization protocol on Stellar. We stake AQUA, aggregate ICE voting power, and auto-compound Aquarius rewards for stakers. This series explains the Stellar DeFi stack — and the wider market around it — in plain English.

Yield on Stellar, with the risks written down

WhaleHub stakes AQUA, aggregates ICE voting power and auto-compounds Aquarius rewards, and publishes how each part can fail.

Launch the app

This article is for education only and is not financial advice. Figures are taken from the sources linked in the text as of the date shown and change constantly. Verify them before acting.