Nostra Finance, a lending, swap, and bridge protocol constructed on the Starknet Layer 2 community, has paused its cash market after a manipulated value feed for its native NSTR token allowed a single account to borrow roughly $3.5 million in digital belongings in opposition to inflated collateral.
The exploit came about on September 17, 2026, and compelled the protocol to disable lending, borrowing, withdrawals, and liquidations whereas its group reconciles pool balances and traces the stolen funds. Nostra has stated the ultimate loss and any recoveries should not but identified.
1000’s of customers misplaced entry to their deposits, dealing with uncertainty about retrieving hundreds of thousands of {dollars}.
The exploit underscores rising mistrust in DeFi safety, prompting requires stricter oversight.
Potential phishing scams rise as attackers exploit restoration guarantees, threatening susceptible crypto contributors.
What Nostra Disclosed
In an official statement posted on X at 13:28 UTC on September 17, Nostra stated a manipulated NSTR oracle value enabled one account to deal with its NSTR holdings as inflated collateral and borrow belongings value roughly $3.5 million from the cash market. The stolen basket, in accordance with the group, included ETH, STRK, USDC, USDT, WBTC, and DAIv1.
The protocol stated the cash market has been paused pending pool-by-pool reconciliation. Customers presently can not lend, borrow, withdraw, or set off liquidations on the platform. Nostra stated the ultimate loss and any recoveries should not but identified, that it’s working with related events on restoration, and {that a} detailed autopsy will comply with.
The group additionally warned customers that it’s going to by no means ship direct messages or ask them to attach wallets as a part of the restoration course of, a typical phishing vector throughout protocol incidents.
Unbiased recaps of that assertion, together with TechFlow, stated deposits, borrows, withdrawals, and liquidations have been suspended whereas the group checks every asset pool.
Fund Circulate Tracked by Safety Corporations
The primary public breakdown of stolen fund motion got here from PeckShield’s alert at 00:41 UTC on September 18. The blockchain safety agency confirmed Nostra’s $3.5 million determine and reported that roughly $1.92 million had already been moved to the Ethereum mainnet, cut up as 234.57 ETH and 1.3 million DAI.
Blockchain safety agency CertiK independently flagged the incident in an alert at 02:30 UTC and adopted up at 02:48 UTC with on-chain explorer hyperlinks. In response to CertiK’s location cut up, roughly $1.55 million remained in a Starknet contract traceable via the Voyager block explorer, whereas roughly $1.93 million had been bridged to an Ethereum address seen on Etherscan.
The 2 monitored figures reconcile inside rounding to Nostra’s disclosed $3.5 million whole. Nostra has not itself confirmed the Ethereum receiving handle or the precise ETH and DAI quantities.
DefiLlama individually recorded a September 17, 2026 incident in opposition to Nostra Cash Marketplace for $3.5 million, labeled as oracle manipulation utilizing spot-price manipulation on Starknet.
Understanding the Oracle Mismatch
An oracle, within the context of decentralized finance (DeFi), is an information feed that provides real-world costs to a sensible contract. Lending markets use oracle costs to worth collateral and resolve how a lot a consumer can borrow. When an oracle prints a value that’s increased than the true market price, the collateral is overvalued within the protocol’s accounting, and the borrower can withdraw extra belongings than the collateral is definitely value.
The assault profile matches a typical lending market oracle failure fairly than a sensible contract vulnerability in Nostra’s core code. The NSTR feed printed a better value, and the identical NSTR stability then counted as bigger collateral inside the cash market. One account borrowed liquid belongings in opposition to that inflated valuation and moved the proceeds.
On the time of writing, NSTR was buying and selling between roughly $0.0055 and $0.0059 with a circulating market capitalization between about $550,000 and $590,000 in accordance with DefiLlama knowledge.
The overall borrowed worth of $3.5 million subsequently exceeds the complete circulating market capitalization of the collateral token by greater than 5 instances, which is the core of the oracle-to-collateral mismatch. DefiLlama has logged the occasion as a September 17, 2026 exploit labeled underneath oracle and spot value manipulation on Starknet. DefiLlama’s protocol web page listed NSTR close to $0.0055 and a market cap close to $549,675 on the time of this report.
PeckShield and CertiK haven’t but revealed a full transaction graph, the precise oracle contract handle, the pre- and post-attack NSTR print, or whether or not a skinny decentralized alternate (DEX) pool was used to maneuver the feed. These particulars stay excellent pending Nostra’s autopsy.
A Second Oracle Incident for Nostra
This isn’t the primary publicly disclosed value feed failure at Nostra. On March 24, 2025, the protocol reported in a statement that oracle feeds for xSTRK and sSTRK, two liquid staking derivatives of STRK, had inflated by roughly 3 times between Starknet blocks 1256310 and 1256360. In a single instance cited by the group, xSTRK moved from $0.1793 to $0.5897.
On the time, Nostra lowered collateral caps for these belongings to zero, paused new borrowing in opposition to them, and suggested customers to withdraw their positions. The group additionally disclosed that no secondary fallback oracle was out there for these explicit belongings.
The March 2025 occasion was described as a feed error that risked wrongful liquidations. The September 2026 occasion, against this, concerned an alleged manipulation that enabled over-borrowing. The frequent issue throughout each incidents is the usage of Starknet ecosystem token value knowledge as lending collateral. Nostra’s March 24, 2025 X thread is the first supply for the sooner xSTRK and sSTRK feed error.
Open Questions on Oracle Sourcing
In Might 2026, Nostra publicly introduced the combination of Chainlink Value Feeds on Starknet for BTC, DAI, ETH, LINK, STRK, USDC, USDT, and wstETH. NSTR was not a part of that preliminary record. Whether or not the NSTR feed was later routed via Chainlink, the Starknet-native oracle Pragma, or a unique supplier has not been clarified within the September 17 assertion, and the identification of the oracle used on the time of the exploit stays one in every of a number of open questions.
The September 2026 exploit lands in a interval of heightened scrutiny of oracle safety throughout DeFi. Ostium Labs, one other protocol whose July exploit was traced to a manipulated value feed, is presently dealing with a $15 million loan dispute in a New York federal courtroom tied to a $23.75 million loss.
Earlier within the week, Blockaid additionally flagged a FlamingoFinance contract exploit that noticed $345,900 stolen. These Ostium and Flamingo objects are separate incidents and are included solely as trade context, not as confirmed hyperlinks to Nostra.
Protocol Context
Nostra operates a collection of merchandise on Starknet, together with Nostra Cash Market, Nostra Swimming pools, Nostra Cash Market Alpha, and nstSTRK, its personal liquid staking by-product of STRK. The group has additionally disclosed plans to construct on the Monad blockchain. In response to official communications, the present exploit is confined to the Starknet cash market and doesn’t have an effect on its different merchandise.
Nostra’s management has been in public focus for different causes prior to now. Former chief government David Garai stepped down shortly after the NSTR token airdrop in June 2024.
What Stays Unverified
A number of key particulars in regards to the September 17 incident haven’t been confirmed by major sources on the time of publication:
- The precise begin block and finish block of the manipulated NSTR value feed
- The oracle supplier for NSTR on the time of the assault
- The complete record of borrow transactions and per-asset quantities
- Whether or not the $3.5 million determine represents realized unhealthy debt or gross borrowed notional
- Any freeze, return, or negotiation involving the Ethereum receiving handle
- Any user-level haircut utilized to depositors on the platform
These things ought to be handled as unverified pending additional disclosure from Nostra or its safety companions. Updates from the group are being posted via its Discord channel.
It is a growing story. The Crypto Instances will replace this report as Nostra, PeckShield, or different major sources publish confirmed figures, fund-flow particulars, or a autopsy. Early numbers could change.
Additionally Learn: $7.8M rsETH Drained From Ethereum Safe Wallet, MEV Bot Yoink Front-Runs the Exploit
Disclaimer: The data researched and reported by The Crypto Instances is for informational functions solely and isn’t an alternative choice to skilled monetary recommendation. Investing in crypto belongings includes important danger resulting from market volatility. All the time Do Your Personal Analysis (DYOR) and seek the advice of with a certified Monetary Advisor earlier than making any funding selections.





