Skip to main content
DeFi SecurityExploit Report· 3 min read· in Finance

Nostra Finance Pauses Starknet Lending Market Following $3.5 Million Oracle Exploit

A targeted manipulation of the NSTR token's price oracle allowed an attacker to borrow $3.5 million against artificially inflated collateral, prompting Nostra Finance to halt its money market operations.

By Bo Feng

DeFi Security Analysts 40%Starknet Ecosystem Developers 30%Institutional Liquidity Providers 30%
DeFi Security Analysts
Security researchers emphasize that oracle manipulation remains a fundamental structural weakness in emerging decentralized markets.
Starknet Ecosystem Developers
Network advocates view the exploit as a growing pain for a rapidly expanding Layer-2 ecosystem.
Institutional Liquidity Providers
Liquidity providers focus on the unacceptable risk of unmitigated oracle manipulation in low-liquidity environments.

Perspectives this story doesn't cover

  • Retail depositors whose funds are frozen

Why it matters

Oracle manipulation remains one of decentralized finance's most persistent structural vulnerabilities, forcing liquidity providers to reevaluate the security of price feeds on emerging Layer-2 networks like Starknet.

On Friday morning across the Starknet network, automated monitoring systems triggered a sudden halt on the Nostra Finance lending protocol after an attacker successfully drained $3.5 million in digital assets. The breach was executed not by breaking the protocol's core smart contracts or stealing private keys, but by artificially inflating the price of the native NSTR token feed by a staggering factor of 8,000. This allowed the exploiter to trick the system's accounting logic and extract millions before the broader market could react to the discrepancy.[1][2]

The mechanism relied on a classic decentralized finance vulnerability known as an oracle manipulation attack. Lending protocols rely on external price feeds, or oracles, to determine the real-time value of the collateral users deposit. By flooding the specific decentralized exchange liquidity pools that Nostra uses to determine asset prices, the attacker temporarily tricked the protocol into believing their NSTR collateral was worth vastly more than its actual market value, creating a brief window of infinite borrowing power.[2][4]

With the protocol's internal accounting systems registering the artificially inflated collateral value, the attacker immediately borrowed $3.5 million in stablecoins and other high-liquidity assets. Because the borrowing occurred in the exact same transaction block as the price manipulation, the automated system approved the massive loans before the oracle price could correct to its true baseline. The attacker then swapped the borrowed assets and moved them off the network, completing the extraction in seconds.[3][4]

The attacker artificially inflated the price of the NSTR token by a factor of 8,000 to borrow against the manipulated collateral.

Nostra Finance developers responded to the anomaly by pausing the protocol's money market contracts, freezing all further deposits, withdrawals, and liquidations to prevent additional capital flight. The rapid shutdown successfully contained the damage to the initial $3.5 million extraction, but it left legitimate users temporarily unable to access their deposited funds or manage their existing loan positions while the engineering team investigated the breach and patched the vulnerability.[3]

The incident marks the second major oracle exploit on the Starknet network in a two-week span, raising serious questions about the maturity of price-feed infrastructure on the Ethereum Layer-2 scaling solution. Starknet relies on zero-knowledge rollups to process transactions faster and cheaper than the Ethereum mainnet, but its decentralized finance ecosystem is still building the deep, resilient liquidity required to resist targeted price manipulation from well-capitalized attackers.[1][3]

Oracle vulnerabilities have become a defining risk factor for the broader cryptocurrency sector in the latter half of 2026. The Nostra Finance breach adds to a brutal September tally that has already seen more than $326 million extracted from various decentralized protocols through similar economic exploits, flash loan attacks, and smart contract vulnerabilities, highlighting the ongoing security challenges in permissionless finance.[5]

The exploit adds to a string of decentralized finance vulnerabilities that have cost the cryptocurrency sector over $326 million in September 2026.
Oracle vulnerabilities have become a defining risk factor for the broader cryptocurrency sector in the latter half of 2026.

Security analysts note that while traditional financial markets utilize circuit breakers and centralized clearinghouses to reverse fraudulent trades, decentralized protocols execute immutably. Once the $3.5 million was borrowed against the manipulated collateral, the assets were immediately bridged out of the Nostra ecosystem, leaving the protocol with bad debt in the form of the now-worthless NSTR collateral and creating a significant hole in the platform's balance sheet.[2][5]

The focus now shifts to Nostra's treasury reserves and the potential for user reimbursement. Protocol administrators have initiated an on-chain dialogue with the attacker, a standard industry practice that often involves offering a "white-hat" bounty—typically 10% to 20% of the stolen funds—in exchange for the return of the remaining capital. Initial reports from the cited security firms and news outlets did not include direct quotations from Nostra developers regarding a specific timeline for reopening the protocol or making users whole.[1][4]

What to know

  • An attacker drained $3.5 million from the Nostra Finance lending protocol on the Starknet network.
  • The exploit utilized an oracle manipulation attack, artificially inflating the NSTR token price by 8,000x.
  • Nostra developers paused the protocol's money market contracts to prevent further capital flight.
  • The incident is the second major oracle exploit on the Starknet network in a two-week period.

Where opinion splits

DeFi Security Analysts

Security researchers emphasize that oracle manipulation remains a fundamental structural weakness in emerging decentralized markets.

Analysts point out that low-liquidity tokens like NSTR are particularly vulnerable to price manipulation. Because the liquidity pools used to determine the token's price are relatively shallow, an attacker with sufficient capital can temporarily skew the ratio of assets in the pool, causing the oracle to report a artificially high price. This structural flaw forces lending protocols to either rely on centralized price feeds or risk economic exploits.

Starknet Ecosystem Developers

Network advocates view the exploit as a growing pain for a rapidly expanding Layer-2 ecosystem.

For developers building on Starknet, the focus remains on scaling the network's overall liquidity to make such attacks prohibitively expensive. While the Nostra exploit marks the second major incident in two weeks, ecosystem participants argue that these stress tests are necessary to harden the infrastructure. They advocate for the implementation of time-weighted average price (TWAP) oracles and stricter collateral caps to mitigate future risks.

Sources

Source coverage

5 outlets

3 viewpoints surfaced

DeFi Security Analysts 40%Starknet Ecosystem Developers 30%Institutional Liquidity Providers 30%
  1. [1]The CryptonomistDeFi Security Analysts

    Nostra Finance Exploit Highlights Starknet DeFi Vulnerability

    Read on The Cryptonomist
  2. [2]Cryptonews.netInstitutional Liquidity Providers

    Nostra Finance exploit drains $3.5M after 8,000x oracle price manipulation

    Read on Cryptonews.net
  3. [3]Altcoin BuzzStarknet Ecosystem Developers

    Nostra Starknet oracle exploit pauses money market, $3.5M borrowed

    Read on Altcoin Buzz
  4. [4]Phemex NewsInstitutional Liquidity Providers

    Nostra Protocol Exploited for $3.5M via NSTR Oracle Manipula

    Read on Phemex News
  5. [5]BeInCryptoDeFi Security Analysts

    Nostra Joins a September That Has Already Cost Crypto Over $326 Million

    Read on BeInCrypto

Comments

Stay informed

Every angle. Every day.

Get Finance stories with full source coverage and perspective breakdowns delivered to your inbox.