Nostra Finance Loses $3.5M After Attacker Manipulates NSTR Oracle 8,000x on Starknet
Starknet lending protocol Nostra Finance suffered a $3.5 million exploit on September 17, 2026, when an attacker manipulated the price of NSTR tokens from roughly $0.006 to $49.5 within minutes. The attacker created a fake NSTR/SolvBTC liquidity pool and used wash trades to inflate the price, then posted the overvalued NSTR as collateral to borrow ETH, STRK, USDC, USDT, WBTC, and DAI. Security firms including GoPlus Security, PeckShield, CertiK, and SlowMist classified the incident as oracle price manipulation rather than a smart contract vulnerability. Nostra responded by halting all protocol functions, causing total value locked to plummet from approximately $4 million to $710,000, freezing funds for all users including those uninvolved in borrowing. Investigators noted the attacker had been accumulating NSTR positions since March 2026 and exploited weaknesses in how price aggregators select reference pools, pointing to a broader supply-chain risk for DeFi lending protocols.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in