Key Highlights
- Nostra’s lending market on Starknet suffered an oracle manipulation exploit, allowing an attacker to borrow approximately $3.5 million using artificially inflated NSTR collateral.
- The attacker bridged roughly $1.92 million to Ethereum mainnet, comprising 234.57 ETH and 1.3 million DAI, before the protocol paused all lending, borrowing, withdrawals, and liquidations.
- The incident contributes to a surging trend in crypto security losses, with DeFiLlama data showing $1.1 billion stolen across more than 212 on-chain incidents in the first half of 2026 alone.
Oracle Manipulation Drains Nostra Lending Market on Starknet
Crypto security faced another significant breach today as Nostra’s lending market on the Starknet network was exploited through a deliberate manipulation of the price feed governing its native NSTR token. According to reports, the attacker subverted the protocol’s oracle system into reporting an inaccurate, inflated value for NSTR. Because Nostra relies on this oracle price to calculate collateral worth, the manipulated feed made the attacker’s NSTR holdings appear substantially more valuable than their actual market price, creating the conditions for a large-scale borrowing spree.
Attacker Borrows $3.5 Million Across Multiple Assets Before Bridging to Ethereum
Once the corrupted price data was accepted by Nostra’s oracle, the attacker leveraged the overvalued NSTR collateral to borrow roughly $3.5 million in a basket of assets, including Ethereum (ETH), Starknet (STRK), Circle’s USDC, Tether’s USDT, Wrapped Bitcoin (WBTC), and DAIv1. The loans appeared legitimate within the protocol’s logic because the collateral valuation and borrowing limits were derived from the compromised oracle feed. The attacker subsequently moved to extract value, bridging approximately $1.92 million to Ethereum mainnet, a sum comprising 234.57 ETH and 1.3 million DAI.
Protocol Pauses Operations Amid Investigation; Total Loss Still Unclear
In response to the breach, Nostra has enacted a comprehensive safety pause, halting all lending, borrowing, withdrawals, and liquidations while the team investigates the oracle manipulation vector. The protocol emphasized that the $3.5 million borrowed does not represent the final loss figure, as impact assessments and potential recovery efforts are ongoing. The exact technical method used to compromise the oracle has not yet been disclosed.
Wave of Exploits Highlights Systemic Vulnerabilities Across CeFi and DeFi
The Nostra incident does not exist in isolation. It coincides with a cluster of high-profile security failures over the past two weeks, signaling a broad threat landscape. Revolut, a major fintech player, fell victim to a sophisticated phishing attack initiated by a fraudulent government request that bypassed internal security checks. Term Finance suffered an exploit targeting weaknesses in its DAO governance structure, while Liquid Network experienced a software flaw that allowed attackers to generate approximately 4,000 BTC illicitly. These cases span centralized finance, decentralized governance, and sidechain infrastructure, demonstrating that attack vectors are diversifying across the entire crypto stack.
Why This Matters: Escalating Losses Define 2026 Security Landscape
Data from DeFiLlama underscores the severity of the current environment. Crypto security losses in the first half of 2026 have already reached $1.1 billion across more than 212 on-chain incidents. The month of April alone accounted for over $600 million in losses, driven primarily by the KelpDAO and Drift Protocol exploits. Ethereum recorded the highest chain-specific losses at $332 million, followed closely by Solana at $326 million. Zooming out to the trailing 12 months, total value hacked stands at approximately $2.101 billion, with DeFi protocols bearing the brunt at $1.353 billion and cross-chain bridges accounting for a further $758.96 million. The Nostra exploit on Starknet adds another data point to the mounting evidence that oracle integrity and cross-chain bridging remain critical systemic weak points.
Frequently Asked Questions
How did the attacker exploit Nostra’s lending market on Starknet?
The attacker manipulated the price feed oracle for the NSTR token, causing it to report an artificially inflated value. This allowed the attacker to deposit NSTR as collateral that appeared more valuable than it was, enabling them to borrow approximately $3.5 million in various assets (ETH, STRK, USDC, USDT, WBTC, DAIv1) against the overvalued collateral.
What actions has Nostra taken following the exploit?
Nostra has paused all lending, borrowing, withdrawals, and liquidations as a safety measure while investigating the oracle manipulation. The team is currently assessing the total impact and exploring potential recovery options. The exact technical method of the oracle compromise has not yet been disclosed.
What are the broader crypto security trends for 2026 based on DeFiLlama data?
In the first half of 2026, crypto exploits have resulted in $1.1 billion in losses across 212+ incidents. Ethereum ($332M) and Solana ($326M) lead in chain-specific losses. Over the past year, total losses reach $2.101 billion, with DeFi protocols accounting for $1.353 billion and cross-chain bridges for $758.96 million, highlighting persistent vulnerabilities in decentralized finance infrastructure and interoperability layers.

Leave a Reply