A Starknet lending protocol just handed the DeFi industry another lesson in why a “valid” price and a “usable” price are not the same thing. On September 17, 2026, an attacker manipulated the market for Nostra Finance’s native NSTR token, pushed its quoted price up roughly 8,000-fold, and borrowed about $3.5 million in liquid assets against the inflated collateral. Nostra paused the affected money market within hours. A day later, oracle provider Pragma reviewed 22 price feeds feeding Starknet’s DeFi apps and flagged six of them as critical risk, warning that a working price feed says nothing about whether the underlying token can actually be sold for that price.
It is the second Starknet oracle scare in two weeks. On September 4, a separate protocol called Vesu had already lost track of roughly $3 million in collateral when bad upstream price data triggered dozens of automatic liquidations. Neither event is catastrophic by 2026’s grim DeFi standards, but together they expose a pattern worth taking seriously: as more lending markets list thinly traded native tokens as collateral, the cost of moving a price far enough to drain a protocol keeps dropping.
What Happened: Nostra’s $3.5 Million NSTR Exploit
Nostra Finance runs one of Starknet’s larger money markets, letting users deposit crypto as collateral and borrow other assets against it, the same basic model as Aave or Compound on Ethereum. One of the assets it accepts as collateral is NSTR, its own governance token. On September 17, 2026, an attacker manipulated the market for NSTR so severely that its on-chain price jumped from roughly $0.006 to about $49.50, an increase reported at close to 8,000 times the token’s real value, with one tracker putting the multiple closer to 8,306x.
With NSTR suddenly “worth” tens of dollars instead of fractions of a cent, the attacker’s holdings looked like enormous collateral. Nostra’s lending contracts, which trust the oracle price rather than independently checking whether that price reflects real market depth, let the attacker borrow other, genuinely liquid assets, reportedly including ETH and DAI, against the inflated NSTR balance. The reported result: about $3.5 million pulled out of the protocol, with no realistic way for Nostra to recover the value because the true NSTR market could never support the loan.
Nostra’s team paused the affected money market once the anomaly was identified, a standard first response for a DeFi protocol that has just watched its risk parameters get exploited. As of publication, available reporting does not confirm a verified attacker wallet address, nor does it confirm that any of the $3.5 million has been frozen or returned. That puts Nostra in a different position than protocols that catch an exploit in progress and can negotiate a return, or that have insurance funds large enough to make users whole.
Timeline of the Attack and Response
The sequence of events, as reported by Crypto Times and corroborated by other outlets, ran fast even by DeFi-incident standards.
- September 17, 2026: An attacker manipulates the NSTR price feed and borrows roughly $3.5 million against inflated collateral.
- Same day: Nostra identifies the abnormal activity and pauses the affected money market to stop further borrowing against NSTR.
- September 18, 2026: Pragma publishes a risk review of 22 mainnet price and rate feeds used across Starknet DeFi, classifying six as critical risk, including the NSTR feed.
- September 18–29, 2026: Crypto outlets, including CryptoNews, continue reporting on the incident and its implications for other Starknet lending markets.
The available reporting does not describe this as a smart-contract bug in the traditional sense, no reentrancy, no integer overflow, no forgotten access-control check. It is a market-structure failure: a token with too little trading depth was allowed to serve as collateral for loans worth more than its real market could ever absorb.
How the Oracle Manipulation Actually Worked
Oracle manipulation is one of DeFi’s oldest attack categories, but the mechanics are worth spelling out because they explain why “the price feed was working correctly” and “the protocol got drained” can both be true at once.
A price oracle’s job is to report what an asset is currently trading for. If NSTR trades in a shallow pool, with little liquidity on either side, a trader willing to spend a comparatively small amount of capital can push the quoted price far above where it would settle under real selling pressure. The oracle, doing exactly what it is built to do, reports that inflated price. A lending protocol that treats the oracle price as ground truth then calculates the attacker’s collateral value using the manipulated number, not the number that would apply if the attacker actually tried to sell.
That is the gap Pragma’s post-incident assessment zeroed in on: a token can have a technically valid, technically current oracle price while having nowhere near enough real liquidity to support the loan a protocol is willing to issue against it. Six of the 22 feeds Pragma reviewed failed that liquidity-adequacy test badly enough to be labeled critical risk, with NSTR named directly and DAI referenced in secondary reporting on the same review.
Available reporting does not establish that a flash loan was used in the Nostra attack, and there is no confirmed on-chain address tying the exploit to a specific known actor. That is a meaningfully different profile from headline-grabbing flash-loan attacks, and it suggests the attacker may have used pre-positioned capital rather than a single atomic transaction, though this detail has not been independently confirmed in public writeups.
Pragma’s Post-Mortem: 6 of 22 Feeds Flagged Critical
Pragma is one of the main oracle providers plugged into Starknet’s DeFi ecosystem, supplying the price and rate data that lending markets like Nostra and Vesu rely on to value collateral and calculate interest. Its September 18, 2026 assessment reviewed 22 mainnet feeds and classified six as carrying critical risk, a distinction based not on whether the feed was technically broken, but on whether the asset behind the feed had enough real market depth to make its quoted price actionable in a liquidation.
That framing matters for anyone building or using a Starknet money market. A feed can pass every uptime and freshness check a team might monitor and still be dangerous, if the underlying token trades in a market thin enough that a single well-funded actor can move the price. Pragma’s review effectively told Starknet DeFi teams that oracle risk is now a liquidity-analysis problem as much as an infrastructure problem, and that the industry’s usual monitoring, watching for stale prices, watching for feed downtime, does not catch this failure mode at all.
Not Starknet’s First Scare This Month: The Vesu Incident
Nostra’s exploit was the second Starknet oracle incident within two weeks, and the two cases make an instructive contrast. On September 4, 2026, Vesu, another Starknet lending protocol that also consumes Pragma price feeds, saw 47 positions liquidated within a two-minute window, between 04:08 and 04:10 UTC, representing roughly $3 million in collateral, according to The Cryptonomist.
Unlike Nostra, Vesu’s incident was not attributed to deliberate manipulation. The reported cause was an upstream Pragma data error that briefly published an incorrect price, which self-corrected within about two minutes, but not before the protocol’s automated liquidation logic acted on the bad number and closed dozens of positions that should not have been at risk. Vesu said its contracts had operated exactly as designed, since a lending protocol that liquidates based on whatever price its oracle reports is, by definition, working correctly even when the oracle itself is briefly wrong. Pragma, Vesu, StarkWare, the Starknet Foundation, and pool curators reportedly coordinated on a recovery response afterward, though the scope of that recovery specific to Vesu is not fully detailed in available reporting.
The distinction is important for anyone trying to draw the right lesson from these two weeks. Vesu was a data-quality failure with no attacker and no stolen funds in the traditional sense, just mistimed liquidations. Nostra was an intentional attack that exploited thin liquidity to fabricate collateral value. Both point back to the same underlying weakness: Starknet DeFi’s reliance on external price feeds for markets that, in several cases, do not have the trading depth to make those prices trustworthy under stress.
Nostra vs. Vesu: Two Different Failure Modes
| Detail | Nostra Finance | Vesu |
|---|---|---|
| Date | September 17, 2026 | September 4, 2026 |
| Root cause | Deliberate manipulation of a thin NSTR market | Incorrect upstream Pragma price data |
| Mechanism | Inflated collateral used to borrow liquid assets | Automated liquidations triggered by a bad price tick |
| Scale | ~$3.5 million borrowed / bad debt | 47 positions, ~$3 million in collateral liquidated |
| Duration of bad data | Not specified in available reporting | Roughly 2 minutes (04:08–04:10 UTC) |
| Protocol response | Money market paused | No contract fault found; feed self-corrected |
| Confirmed recovery | Not confirmed as of publication | Coordinated response involving Pragma, StarkWare, Starknet Foundation, and pool curators |
Why Starknet’s Thin Liquidity Makes Oracle Attacks Cheap
The common thread across both incidents is liquidity, or the lack of it. Starknet’s total value locked has remained modest compared to Ethereum mainnet or larger layer-2 networks like Arbitrum and Base, and several of the tokens that Starknet lending markets accept as collateral, native governance tokens included, trade in pools too shallow to absorb a determined buyer without the price swinging wildly.
That matters because the cost of an oracle manipulation attack scales with market depth, not with the size of the protocol being attacked. A lending market holding tens of millions of dollars in deposits can still be drained for a few million if one of its accepted collateral assets trades in a pool that only needs a few hundred thousand dollars of buying pressure to move 100x. Nostra’s NSTR token appears to fit that description: a roughly 8,000x price swing is not something that happens in a deep, liquid market under any normal trading conditions.
Pragma’s decision to flag six feeds, rather than one, suggests this is not a Nostra-specific problem. It is a structural feature of smaller, faster-growing L2 ecosystems where new tokens list and get accepted as collateral before their markets have matured enough to make their prices resistant to manipulation. Protocol teams that want to keep listing native tokens as collateral are left with an uncomfortable tradeoff: cap loan-to-value ratios so conservatively that the token is barely useful as collateral, or accept a standing risk that someone eventually tests the market’s real depth.
Market Impact: Starknet TVL and Investor Sentiment
Two oracle incidents in two weeks have not triggered a broad Starknet exodus, but they have added to a narrative that the network’s DeFi layer is still working through growing pains. Market trackers have placed Starknet’s total value locked in the range of roughly $190 million through September 2026, a fraction of what larger L2s like Arbitrum and Base carry, and a level at which a handful of multimillion-dollar incidents can meaningfully move sentiment even if the dollar amounts look small next to headline exchange hacks.
That contrast is worth sitting with. The same week Nostra was working through its post-mortem, Bitget disclosed a hack of its hot and warm wallets totaling somewhere between $351.6 million and $387.5 million, restoring withdrawals in stages between September 28 and an expected October 2 completion, according to Reuters and other outlets. Reuters also reported that attackers stole roughly $2.9 billion across nearly 150 crypto attacks during 2025, with the $1.5 billion Bybit theft in February 2025 standing as the largest single incident on record. Next to those figures, Nostra’s $3.5 million barely registers. But DeFi users tend to judge a protocol less by the dollar amount lost and more by whether its risk model held up, and on that measure, Nostra and Vesu both had a rough September.
2025–2026 Crypto Losses in Context
| Incident | Date | Type | Reported loss |
|---|---|---|---|
| Bybit | February 2025 | Exchange hot wallet hack | $1.5 billion |
| 2025 full year | 2025 | Aggregate across ~150 attacks | ~$2.9 billion |
| Vesu | September 4, 2026 | Oracle data error / liquidations | ~$3 million in collateral |
| Nostra Finance | September 17, 2026 | Oracle price manipulation | ~$3.5 million |
| Bitget | September 24, 2026 | Exchange hot/warm wallet hack | $351.6M–$387.5 million |
Historical Context: Oracle Manipulation Is DeFi’s Oldest Trick
Oracle manipulation is not a new category of attack, it is arguably DeFi’s original sin. Early lending protocols that pulled prices directly from a single decentralized exchange pool learned the hard way, going back to incidents on Ethereum in 2020 and 2021, that any price source without built-in resistance to short-term manipulation is a liability the moment enough value sits behind it. The industry’s response was to build time-weighted average price feeds, multi-source aggregation, and dedicated oracle networks like Chainlink and Pragma specifically to make single-block price manipulation harder.
What the Nostra and Vesu incidents show is that those defenses solved the easy version of the problem, manipulating a price within one transaction, without fully solving the harder version: an asset can have a legitimate, slow-moving, aggregated price that is still unreliable simply because too little of it trades. Time-weighting a price over a thin market does not create liquidity that was never there. That is a design problem, not a data-feed problem, and it is one every L2 with a growing token ecosystem will keep running into as new collateral types get listed faster than their markets can mature.
Competitive Comparison: How Other L2s Handle Oracle Risk
Starknet is far from alone in wrestling with oracle-dependent lending risk, but its approach differs in emphasis from other major layer-2 networks. Arbitrum and Optimism host mature lending markets, largely forks or direct deployments of Aave and Compound, that generally restrict native, thinly traded tokens from serving as high loan-to-value collateral, leaning instead on blue-chip assets like ETH, WBTC, and major stablecoins where deep liquidity already exists across multiple venues. Base, which has grown quickly on the back of Coinbase’s distribution, has taken a similar conservative-collateral approach on its largest markets, even as it has had its own smaller DeFi incidents on newer, less-established protocols built on top of it.
Starknet’s DeFi ecosystem, by contrast, is younger and smaller, which cuts both ways. It has less total value at risk in absolute terms, but its protocols have also been more willing to list native ecosystem tokens as collateral to bootstrap usage, exactly the kind of asset Pragma’s review flagged as carrying critical liquidity risk. zkSync’s DeFi layer faces a similar tension as a newer zero-knowledge rollup competing for the same category of protocols and users. The pattern across all of these networks is consistent: the more established a chain’s DeFi ecosystem, the more conservative its accepted collateral list tends to become, because conservatism is what survives repeated stress-testing by attackers.
Code Pattern: Adding a Liquidity Check to Oracle-Based Lending
Pragma’s core warning, that a valid price does not guarantee sellable liquidity, has a fairly direct engineering answer, even if it adds friction to protocol design. Instead of trusting a spot or time-weighted price alone, a lending contract can check that a minimum depth of on-chain liquidity exists at or near the quoted price before allowing that price to be used for a large loan. The illustrative pattern below is a simplified, generic version of the kind of guard that liquidity-aware lending protocols implement, not a specific vendor’s actual code.
// Illustrative pattern only -- not production code
function getSafeCollateralValue(address token, uint256 amount) internal view returns (uint256) {
uint256 oraclePrice = priceOracle.getPrice(token);
uint256 availableLiquidity = liquidityTracker.getDepthNearPrice(token, oraclePrice);
// Reject the price if the market can't actually absorb a liquidation
// of this size without slippage beyond an acceptable threshold.
require(availableLiquidity >= amount * MIN_LIQUIDITY_MULTIPLIER,
"Insufficient liquidity to trust this price for this loan size");
return oraclePrice * amount;
}
The tradeoff is real: this kind of check caps how much any given token can be used as collateral relative to its actual market depth, which limits how aggressively a protocol can bootstrap borrowing against a new token. That is precisely the tradeoff Pragma’s assessment is pushing Starknet protocols toward, accept less collateral utility from thin markets in exchange for not getting drained by them.
What Nostra and Starknet Do Next
Nostra’s immediate task is straightforward to describe and hard to execute cleanly: decide whether to absorb the $3.5 million as bad debt, attempt some form of socialized loss across the protocol, or wait for a longer investigation that might identify and negotiate with the attacker, as several DeFi protocols have done after past exploits. Available reporting does not indicate which path Nostra has chosen as of late September 2026.
For the wider Starknet ecosystem, Pragma’s six flagged feeds function as a checklist. Protocols still accepting those assets as high loan-to-value collateral now have a public warning on record, which raises the stakes if another exploit hits one of the same feeds. Expect other Starknet lending markets to quietly tighten loan-to-value ratios on thinly traded tokens in the coming weeks, both as a genuine risk response and as a defensive move against the reputational cost of being the third incident in a single month.
5 Predictions for Oracle Security Through 2027
- Liquidity-depth checks become standard, not optional. More Starknet and L2 lending protocols will add on-chain liquidity checks alongside price feeds, following the pattern Pragma’s review implicitly recommends.
- Native tokens get squeezed out of high-LTV collateral lists. Expect protocols to lower loan-to-value ratios sharply, or delist entirely, for governance tokens that lack deep, multi-venue liquidity.
- Oracle providers publish more public risk reviews. Pragma’s decision to name six critical feeds in public sets a precedent other oracle networks serving smaller L2s will likely follow after their own incidents.
- Smaller L2 DeFi ecosystems see slower TVL growth relative to risk appetite. Networks like Starknet with sub-$200 million TVL will face more scrutiny before large capital allocators commit, given back-to-back oracle incidents in the same month.
- Cross-protocol coordination on incident response improves. The Vesu response, which reportedly involved Pragma, Vesu, StarkWare, the Starknet Foundation, and pool curators together, is likely to become a template other L2 ecosystems formalize into standing incident-response groups.
FAQ
What is Nostra Finance?
Nostra Finance is a lending and money-market protocol built on Starknet, Ethereum’s zero-knowledge rollup layer-2 network. It lets users deposit crypto assets as collateral and borrow other assets against them, similar in structure to Aave or Compound on Ethereum mainnet.
How much was stolen in the Nostra exploit?
Reports place the loss at approximately $3.5 million, borrowed against an artificially inflated valuation of Nostra’s native NSTR token after its price was manipulated roughly 8,000-fold.
Was this a smart contract bug?
No. Available reporting does not describe this as a coding vulnerability like reentrancy or an overflow. It is characterized as an oracle price manipulation exploit, where the attacker moved the market for a thinly traded token to make the oracle report an inflated price, then borrowed against that inflated collateral value.
What is Pragma’s role in this incident?
Pragma is an oracle provider supplying price and rate data to Starknet DeFi protocols, including Nostra and Vesu. Following the Nostra exploit, Pragma published a risk assessment of 22 mainnet feeds and classified six as critical risk, warning that an available price does not guarantee enough market liquidity to support liquidations at that price.
Is the Vesu incident related to the Nostra exploit?
They are separate incidents that both trace back to Pragma price data on Starknet. Vesu’s September 4, 2026 event involved an upstream data error that triggered 47 liquidations worth about $3 million, and Vesu said its contracts functioned as designed. Nostra’s September 17, 2026 event involved deliberate manipulation of a token’s market price, not a data error.
Has any of the stolen $3.5 million been recovered?
As of publication, available reporting does not confirm that any of the funds from the Nostra exploit have been frozen or returned. That is separate from the Vesu incident, which involved a coordinated response among Pragma, Vesu, StarkWare, the Starknet Foundation, and pool curators.
Should DeFi users avoid Starknet lending protocols now?
The two incidents point to a specific risk category, thinly traded collateral assets, rather than a blanket problem with Starknet or its major protocols. Users can reduce exposure by checking which collateral types a lending market accepts and how deep the trading liquidity is for each one, rather than avoiding the network entirely.
How does this compare to the Bitget exchange hack the same month?
They are unrelated and structurally different. Bitget’s incident, reported at $351.6 million to $387.5 million, involved unauthorized transfers from a centralized exchange’s hot and warm wallets. Nostra’s exploit involved manipulating an on-chain price feed within a decentralized lending protocol. Both illustrate different sides of crypto’s security surface: custodial infrastructure versus on-chain market design.




