Stellar

Oracles on Stellar: Reflector, RedStone, Band and Who Uses Them

How Stellar oracles work — Reflector, RedStone, Chainlink, Band, Pyth — update rules, TWAPs, SEP-40, who integrates them, and the YieldBlox lesson.

Oracles on Stellar compared: Reflector, RedStone, Chainlink, Band and Pyth

Updated 6 October 2026: provider list checked against Stellar's oracle-providers documentation; Chainlink's Stellar feeds (live 29 September) and Pyth's mainnet verifier added; integrations re-checked in Blend's docs and XOXNO's mainnet configuration.

Every lending market on Stellar is only as safe as the price it reads. Stellar oracles now come from five providers: Reflector, the network's homegrown oracle; RedStone, live since March 2026; Band, live since 2024; and Chainlink and Pyth, both added in September 2026. They differ in who signs the price, how often it changes and which interface a contract uses to read it. Here is how each works, who actually uses it, and what February's YieldBlox exploit showed.

Stellar oracles at a glance

OracleModelUpdate ruleInterfaceNamed Stellar users
ReflectorPush, signed by a node cluster via multisigPulse: every 5 min. Beam: 1-min granularity, threshold pushes, 2-hour heartbeatSEP-40Blend, OrbitCDP, DeFindex, Laina, EquitX, Slender, XOXNO
RedStonePushOn deviation (about 0.5–1% for stablecoins) plus at least dailySEP-40 for 18 of 47 feedsBlend, Templar, XOXNO
ChainlinkPush, one proxy for all feeds0.5% deviation (0.1% for gold), 24-hour heartbeatOwn (data_id)None named yet; live since 29 Sep 2026
BandPush, relayed from BandChainNot published for StellarOwn (get_reference_data)None found
PythPull, signed off-chain and verified on-chainOn demandOwn (verifier contract)Templar (per DefiLlama)

Stellar oracles by the numbers (October 2026)

Reflector runs three public mainnet oracles: Stellar DEX prices, external exchange prices and fiat exchange rates. RedStone reports 47 feeds on Stellar, 18 of them SEP-40 compliant. Chainlink lists nine Stellar feeds. The largest consumer, Blend Pools V2, held $162.8M on 6 October 2026, per DefiLlama.

  • DeFi that depends on prices: Stellar DeFi TVL was $271.6M on 6 October per DefiLlama, of which Blend Pools V2 is $162.8M and Templar Protocol $13.3M. XOXNO Lending, the most elaborately configured, holds $0.13M on Stellar.
  • Chainlink: BTC, ETH, LINK, USDT, USDC, XLM, EURC and FLHY against USD, plus an XAUM gold reference rate, per Chainlink's Stellar feed list.
  • RedStone: 47 feeds, 18 SEP-40 compliant, including BENJI, iBENJI, USDY, USTRY, CETES, TESOURO, deJTRSY, deJAAA, XAUm and PYUSD, per its August 2026 blog.
  • Pyth: the Stellar verifier contracts were audited by Zellic (report dated 1 September 2026) and added to Stellar's provider docs on 8 September.

How to choose

  • You are building on Stellar and want a free, standard feed: Reflector Pulse, read through SEP-40, with your own TWAP and staleness checks.
  • You need RWA or fund prices: RedStone's "fundamental" (NAV-style) feeds cover BENJI, USDY, USTRY and CETES; a DEX price for these tokens can be meaningless.
  • You want a second, independent source: pair providers that do not share data sources, as XOXNO does with Reflector and RedStone. Chainlink and Pyth are now options too.
  • You are a depositor, not a builder: find out which oracle your pool uses for every collateral asset, and how deep that asset's market is.

SEP-40 — the common interface

SEP-40 is a draft Stellar standard, created in 2023, that defines how contracts read prices: base asset, list of assets, decimals, resolution, price at a timestamp, the last N prices and the latest price. A contract written against it can switch providers without changing its logic.

Assets are identified either as a Stellar contract address or as a symbol such as "BTC", and prices come back as an integer plus a timestamp. The standard does not say how a provider gathers data, only how consumers read it. That matters for Soroban, where cross-contract calls cost fees: the authors' stated aim was to avoid chains of adapter contracts. Blend requires only two SEP-40 functions, lastprice and decimals.

Reflector — Stellar's homegrown oracle

Reflector is run by a cluster of node operators from Stellar ecosystem organisations. Each node computes prices independently and signs an update; the oracle's admin account needs more than half of the nodes' signatures to write. Pulse feeds are free and update every five minutes; Beam feeds update faster for a small XRF fee.

Its three public mainnet contracts source from the Stellar DEX, from external centralised and decentralised exchanges, and from fiat exchange rates. Prices are normalised to the feed's resolution, and history is kept in temporary storage with a guaranteed retention of 24 hours, so a consumer can read recent records but not years of data. Reflector's docs tell consumers to check every timestamp against the ledger time to avoid stale prices.

One common misunderstanding is that Reflector "provides a TWAP". The current interface has no TWAP method. Its documentation says TWAP and cross-price calculations are done in the consumer contract, by averaging records from prices(). A separate Flare service lets apps subscribe to price-change triggers delivered by webhook. Reflector is governed by a DAO of node operators with equal votes; XRF fees for paid services are burned.

Stellar's documentation lists Reflector integrations with Blend, OrbitCDP, DeFindex, Laina, EquitX, Slender and SorobanDomains.

RedStone — RWA and NAV feeds

RedStone launched on Stellar in March 2026, weeks after the YieldBlox exploit, with a push model built from Soroban adapter and price-feed contracts. Updates are deviation-based, around 0.5–1% for stablecoins, with at least a daily refresh. It adopted SEP-40 in June 2026.

Its differentiator on Stellar is coverage of tokenised funds and bonds. RedStone's August 2026 post lists 47 Stellar feeds, 18 SEP-40 compliant, including Franklin Templeton's BENJI and iBENJI, Ondo's USDY, Etherfuse's USTRY, CETES and TESOURO, and Centrifuge's deJTRSY and deJAAA. It names Templar Protocol, Blend and Centrifuge's deRWA tokens as users. XOXNO's mainnet config reads RedStone as a "fundamental" source for 14 of its markets, alone for assets such as USDY and PYUSD.

NAV-style feeds solve one problem and create another. They cannot be moved by a thin DEX market, but they report what the issuer says a token is worth, not what you could sell it for. For an asset with weak secondary liquidity, that gap is a liquidation risk; see RWAs as DeFi collateral.

Chainlink Data Feeds went live on Stellar on 29 September 2026. Unlike on EVM chains, one proxy contract serves every feed and consumers pick a feed by a 32-byte data_id. Nine feeds are listed, updating on a 0.5% deviation (0.1% for gold) or every 24 hours.

The interface is Chainlink's own: latest_round(data_id, decimals), get_round, decimals and description. A contract built for SEP-40 cannot read it without an adapter. The integration follows Stellar's move to join Chainlink's Scale programme. Because the feeds are a week old, we found no Stellar protocol publicly using them yet.

Band — the earliest, least visible

Band Protocol deployed its StandardReference contract on Soroban mainnet in March 2024. Prices are aggregated on BandChain, a Cosmos-SDK chain, and written to Stellar by relayers that Band's admin appoints. Consumers read them with get_ref_data or get_reference_data.

The contract was audited by Runtime Verification, with no critical issues reported. Band's model is a trust in Band itself: the admin and relayer roles are maintained by Band Protocol, and the contract does not follow SEP-40. We could not find a named Stellar protocol that publicly relies on Band's feed, nor a published update cadence for Stellar, so its practical footprint on the network appears small.

Pyth and DIA — pull model and testnet

Pyth runs on Stellar mainnet as a pull oracle: an app fetches a signed price update off-chain and verifies it on-chain through Pyth's verifier contract. Verification is permissionless, but receiving the data needs a subscription. DIA is listed in Stellar's docs with a testnet deployment only.

Pull oracles shift the update burden to the user of the price, which keeps prices fresh at the moment of use but means each transaction carries the update. DefiLlama lists Pyth as Templar Protocol's primary oracle, while RedStone also names Templar as a user of its Stellar feeds; Templar operates on more than one chain, so the two are not necessarily in conflict.

The YieldBlox lesson

In February 2026 an attacker took about $10M from the YieldBlox pool on Blend by pushing the price of USTRY on a nearly empty Stellar DEX market from about $1.06 to about $107. The pool read that market through a Reflector feed, so the oracle faithfully reported a manipulated price.

The oracle did what it was designed to do; the pool's configuration asked the wrong question. Cointelegraph reported that the USTRY market had less than one dollar of hourly trading volume. The full timeline is in Blend's 2026 incidents. What changed afterwards shows the lessons in practice:

  • Average, don't snapshot. Blend's docs stress that TWAPs are harder to manipulate than spot prices, and geometric-mean TWAPs harder still.
  • Use two independent sources. XOXNO's markets read a three-period Reflector TWAP and cross-check it against RedStone, rejecting prices that diverge beyond about ±10% for XLM and ±5% for stablecoins, and requiring the sources to be disjoint.
  • Bound the answer. XOXNO also sets hard minimum and maximum sanity prices per asset, so a hundredfold jump is simply refused.
  • Pick the oracle once, carefully. A Blend pool's oracle cannot be changed after creation.

How these fit together

Reflector remains the default for Stellar-native assets because it is free, SEP-40 compliant and reads the Stellar DEX directly, which is both its strength and, for thin markets, its weakness. RedStone fills the gap for tokenised funds whose fair value is a NAV, not a trade. Chainlink and Pyth bring the price sources most DeFi users know from other chains, at the cost of non-standard interfaces. The safest designs combine at least two, check staleness, and cap what any one price can do. For how this plays out in lending, see what is Blend and the RWA platforms on Stellar whose tokens need these feeds.

The takeaway

The question to ask of any Stellar lending pool is not "which oracle?" but "which market does that oracle read for this asset, and what stops a single trade from setting it?" If the answer is a five-minute spot price from a thin DEX pair, the brand of the oracle will not save the pool.

Sources: stellar-docs, docs/data/oracles/oracle-providers.mdx; reflector-network/reflector-contract README and Reflector site text (llms-full.txt); SEP-0040; RedStone blog, "From Issuance to Markets" (26 Aug 2026); Cointelegraph, RedStone launch (4 Mar 2026); Chainlink documentation repo, Stellar feeds list and "Using Data Feeds on Stellar"; Band Protocol blog (7 Mar 2024) and band-std-reference-contracts-soroban README; Blend docs, "Selecting an Oracle"; blend-capital/oracle-aggregator README; XOXNO rs-lending-xlm configs/mainnet/markets.json; DefiLlama API, 6 October 2026.

Frequently asked questions

What oracle does Blend use?

Each Blend pool picks its own oracle when it is created, and the choice cannot be changed later. Blend's documentation names Reflector and RedStone as well-known options and requires the oracle to support SEP-40's lastprice and decimals functions. Script3 also publishes an example oracle aggregator that can combine sources; it has not been audited.

How often does Reflector update?

Reflector's free Pulse oracles publish on a uniform five-minute resolution and keep at least 24 hours of history. Its paid Beam oracles update at one-minute granularity, push updates when prices move past a threshold, and send a guaranteed heartbeat to every active feed every two hours.

What is SEP-40?

SEP-40 is Stellar's draft standard interface for price oracles. It defines functions such as base, assets, decimals, resolution, price, prices and lastprice, so a consumer contract can switch between providers without rewriting its logic. Reflector's contracts and RedStone's SEP-40 feeds follow it; Chainlink and Band use their own interfaces.

Does Reflector provide a TWAP?

Not as a contract method. Reflector's current interface returns individual price records, and its documentation says TWAP and cross-price calculations are done in the consumer contract, for example by averaging the last few records returned by prices(). XOXNO's lending markets, for instance, read a three-period Reflector TWAP this way.

WhaleHub Research
WhaleHub Research
Protocol research & education · WhaleHub

WhaleHub is a yield-optimization protocol on Stellar. We stake AQUA, aggregate ICE voting power, and auto-compound Aquarius rewards for stakers. This series explains the Stellar DeFi stack — and the wider market around it — in plain English.

Yield on Stellar, with the risks written down

WhaleHub stakes AQUA, aggregates ICE voting power and auto-compounds Aquarius rewards, and publishes how each part can fail.

Launch the app

This article is for education only and is not financial advice. Figures are taken from the sources linked in the text as of the date shown and change constantly. Verify them before acting.