Tag: DeFi exploit

  • Pragma flags 6 price feeds as critical risk following $3.5M Starknet lending exploit

    Pragma flags 6 price feeds as critical risk following $3.5M Starknet lending exploit

    Key Highlights

    • Oracle provider Pragma classified six of 22 Starknet mainnet market and rate feeds as critical risk in a Sept. 18 assessment, including NSTR, EKUBO, LORDS, BROTHER, DOG, and $DAI.
    • A manipulated NSTR oracle price enabled a ~$3.5 million borrowing exploit at the Nostra lending protocol on Sept. 17, prompting Nostra to pause all lending, borrowing, withdrawals, and liquidations.
    • Pragma’s analysis demonstrates that oracle prices do not guarantee liquidation liquidity, with sell-quote deterioration ranging from 15% to 22% for critical tokens when measured against $10,000 versus $10 quotes.

    Pragma Issues Critical Risk Assessment for Starknet Oracle Feeds

    Blockchain oracle provider Pragma published a liquidity risk assessment on Sept. 18 classifying six of 22 Starknet mainnet market and rate feeds as critical risk, warning lenders that the mere availability of a token price does not establish that collateral can be sold to cover a loan. The assessment placed BROTHER, $DAI, DOG, EKUBO, LORDS, and NSTR in its critical category, with nine additional feeds rated high risk. Pragma emphasized that the evaluation does not confirm every listed feed is actively used as collateral in lending markets.

    Nostra Exploit Highlights Oracle Manipulation Vulnerability

    The report followed a Sept. 17 borrowing exploit at Nostra, a lending protocol on Starknet. According to Nostra’s account, a manipulated NSTR oracle price allowed one account to borrow approximately $3.5 million of other assets against NSTR collateral. In its Sept. 17 statement, Nostra said it “paused lending, borrowing, withdrawals, and liquidations while it reconciled the impact and traced funds,” adding that “final losses and potential recoveries were still unknown.” The announcement leaves the subsequent status of withdrawals and recovery unconfirmed.

    Pragma’s incident analysis identified two contributing sources for the affected oracle response. The provider stated that an enforced three-source minimum would have rejected the manipulated input, and its integration guidance recommends freshness checks and thresholds suited to the asset’s risk profile. Pragma attributed the deviating input to a manipulated on-chain pool and said its reconstruction found no decimals or median-calculation error. The provider separately reported that the attacker’s address had been frozen and recovery work was ongoing.

    Why Oracle Valuations Don’t Equal Liquidation Liquidity

    The core finding underscores a structural gap in decentralized lending: an oracle supplies a valuation, but liquidation requires selling collateral, and a thin market may not absorb that sale near the quoted price. As Pragma explained, “An oracle supplies a valuation. Liquidation requires selling collateral, and a thin market may not absorb that sale near the quoted price. A loan can be backed by an apparent value that cannot be realized when repayment depends on selling the token.”

    At token quantities valued by the oracle at $10,000, sell-quote deterioration was measured at approximately 15% for NSTR, 17% for EKUBO, 22% for LORDS, and 20% for BROTHER, when compared against quotes for $10 sales. Pragma’s Sept. 18 snapshot showed indicative $10,000 sell quotes deteriorating 15% to 22% versus $10 quotes across these four tokens.

    Source Concentration and Aggregation Risks

    The $DAI critical rating stems from source concentration and tested Starknet token routes rather than global illiquidity. Pragma noted that current and legacy deployments had different exit curves, so the critical rating cannot be read as a finding that $DAI is globally illiquid. The provider also warned that multiple source labels do not necessarily solve the problem: “publishers and aggregators can share underlying market dependencies, so several labels may reflect overlapping liquidity.”

    Protocol Response and Recovery Efforts

    For depositors, the immediate consequence was restricted access to funds. Nostra’s pause of all protocol functions remains in effect while the team reconciles impact and traces funds. Pragma’s report confirmed the attacker’s address was frozen and that recovery work continues, though final loss figures and potential recoveries remain undetermined as of the Sept. 17 disclosures.

    Why This Matters

    Pragma’s assessment exposes a fundamental risk in decentralized finance: the conflation of price availability with exit liquidity. Lending protocols that accept oracle-valued tokens as collateral without independent liquidity analysis may face unbacked loans when markets cannot absorb forced sales at quoted prices. The Nostra exploit demonstrates how a single manipulated feed can cascade into multi-million dollar losses. For the broader Starknet ecosystem, the report forces a reevaluation of which assets qualify as collateral, appropriate exposure limits, and whether exit liquidity can support liquidation under stress. As Pragma concluded, “Publishing a price doesn’t settle any of those questions by itself.”

    Frequently Asked Questions

    Which tokens did Pragma classify as critical risk in its Sept. 18 assessment?
    Pragma placed BROTHER, $DAI, DOG, EKUBO, LORDS, and NSTR in its critical risk category, with nine other feeds rated high risk.
    What caused the Nostra exploit on Sept. 17?
    A manipulated NSTR oracle price allowed one account to borrow approximately $3.5 million of other assets against NSTR collateral.
    Does an oracle price guarantee that collateral can be liquidated at that value?
    No. Pragma’s analysis shows that oracle valuations do not reflect actual sell-side liquidity. Sell-quote deterioration for critical tokens ranged from 15% to 22% at $10,000 volumes versus $10 quotes, meaning forced liquidations would likely realize significantly less than the oracle price.
  • Nostra Hit by $3.5M Oracle Attack as Security Concerns Re-emerge

    Nostra Hit by $3.5M Oracle Attack as Security Concerns Re-emerge

    Key Highlights

    • Nostra’s lending market on Starknet suffered an oracle manipulation exploit, allowing an attacker to borrow approximately $3.5 million using artificially inflated NSTR collateral.
    • The attacker bridged roughly $1.92 million to Ethereum mainnet, comprising 234.57 ETH and 1.3 million DAI, before the protocol paused all lending, borrowing, withdrawals, and liquidations.
    • The incident contributes to a surging trend in crypto security losses, with DeFiLlama data showing $1.1 billion stolen across more than 212 on-chain incidents in the first half of 2026 alone.

    Oracle Manipulation Drains Nostra Lending Market on Starknet

    Crypto security faced another significant breach today as Nostra’s lending market on the Starknet network was exploited through a deliberate manipulation of the price feed governing its native NSTR token. According to reports, the attacker subverted the protocol’s oracle system into reporting an inaccurate, inflated value for NSTR. Because Nostra relies on this oracle price to calculate collateral worth, the manipulated feed made the attacker’s NSTR holdings appear substantially more valuable than their actual market price, creating the conditions for a large-scale borrowing spree.

    Attacker Borrows $3.5 Million Across Multiple Assets Before Bridging to Ethereum

    Once the corrupted price data was accepted by Nostra’s oracle, the attacker leveraged the overvalued NSTR collateral to borrow roughly $3.5 million in a basket of assets, including Ethereum (ETH), Starknet (STRK), Circle’s USDC, Tether’s USDT, Wrapped Bitcoin (WBTC), and DAIv1. The loans appeared legitimate within the protocol’s logic because the collateral valuation and borrowing limits were derived from the compromised oracle feed. The attacker subsequently moved to extract value, bridging approximately $1.92 million to Ethereum mainnet, a sum comprising 234.57 ETH and 1.3 million DAI.

    Protocol Pauses Operations Amid Investigation; Total Loss Still Unclear

    In response to the breach, Nostra has enacted a comprehensive safety pause, halting all lending, borrowing, withdrawals, and liquidations while the team investigates the oracle manipulation vector. The protocol emphasized that the $3.5 million borrowed does not represent the final loss figure, as impact assessments and potential recovery efforts are ongoing. The exact technical method used to compromise the oracle has not yet been disclosed.

    Wave of Exploits Highlights Systemic Vulnerabilities Across CeFi and DeFi

    The Nostra incident does not exist in isolation. It coincides with a cluster of high-profile security failures over the past two weeks, signaling a broad threat landscape. Revolut, a major fintech player, fell victim to a sophisticated phishing attack initiated by a fraudulent government request that bypassed internal security checks. Term Finance suffered an exploit targeting weaknesses in its DAO governance structure, while Liquid Network experienced a software flaw that allowed attackers to generate approximately 4,000 BTC illicitly. These cases span centralized finance, decentralized governance, and sidechain infrastructure, demonstrating that attack vectors are diversifying across the entire crypto stack.

    Why This Matters: Escalating Losses Define 2026 Security Landscape

    Data from DeFiLlama underscores the severity of the current environment. Crypto security losses in the first half of 2026 have already reached $1.1 billion across more than 212 on-chain incidents. The month of April alone accounted for over $600 million in losses, driven primarily by the KelpDAO and Drift Protocol exploits. Ethereum recorded the highest chain-specific losses at $332 million, followed closely by Solana at $326 million. Zooming out to the trailing 12 months, total value hacked stands at approximately $2.101 billion, with DeFi protocols bearing the brunt at $1.353 billion and cross-chain bridges accounting for a further $758.96 million. The Nostra exploit on Starknet adds another data point to the mounting evidence that oracle integrity and cross-chain bridging remain critical systemic weak points.

    Frequently Asked Questions

    How did the attacker exploit Nostra’s lending market on Starknet?

    The attacker manipulated the price feed oracle for the NSTR token, causing it to report an artificially inflated value. This allowed the attacker to deposit NSTR as collateral that appeared more valuable than it was, enabling them to borrow approximately $3.5 million in various assets (ETH, STRK, USDC, USDT, WBTC, DAIv1) against the overvalued collateral.

    What actions has Nostra taken following the exploit?

    Nostra has paused all lending, borrowing, withdrawals, and liquidations as a safety measure while investigating the oracle manipulation. The team is currently assessing the total impact and exploring potential recovery options. The exact technical method of the oracle compromise has not yet been disclosed.

    What are the broader crypto security trends for 2026 based on DeFiLlama data?

    In the first half of 2026, crypto exploits have resulted in $1.1 billion in losses across 212+ incidents. Ethereum ($332M) and Solana ($326M) lead in chain-specific losses. Over the past year, total losses reach $2.101 billion, with DeFi protocols accounting for $1.353 billion and cross-chain bridges for $758.96 million, highlighting persistent vulnerabilities in decentralized finance infrastructure and interoperability layers.

  • Crypto Project Paying Nearly 1 Million People Daily Income Has Reserves Looted

    Crypto Project Paying Nearly 1 Million People Daily Income Has Reserves Looted

    Superfluid Bug Allows Attacker to Drain Over $100,000 from GoodDollar Reserves

    A vulnerability in Superfluid’s Celo deployment enabled a malicious application to bypass liquidation safeguards and mint excess G$ tokens, resulting in the drainage of more than $100,000 from GoodDollar’s reserves. GoodDollar announced on September 9 that 86,588 cUSD was exchanged out of its Celo reserve and an additional $20,857 was taken from its XDC reserve. External G$ liquidity pools were also impacted, though neither project has disclosed the extent of those losses.

    GoodDollar’s UBI Model and Reserve Structure

    GoodDollar operates as a decentralized universal basic income (UBI) protocol that distributes G$ tokens daily to registered users. The protocol’s reserve is backed by stablecoins, with yield generated through DeFi investments used to support G$ issuance and UBI distributions. According to GoodDollar’s dashboard, the program has over 963,000 unique UBI claimants and has distributed more than 2.3 billion G$ tokens to date, making the reserve central to the token’s economic model and daily distribution system.

    Celo Network Holds 28% of G$ Circulating Supply

    Approximately 2.4 billion G$ tokens circulate on the Celo network, representing roughly 28% of the token’s 8.7 billion circulating supply. This makes Celo the second-largest network for G$ after Fuse, which holds 4.19 billion G$. Ethereum accounts for about 1.82 billion G$, while the XDC network holds 292.5 million G$.

    GoodDollar Crypto Tokens Circulating Supply by Networks (Source: GoodDollar’s Dashboard)

    Superfluid Identifies Celo-Specific Vulnerability

    Superfluid’s Security Council confirmed that the vulnerability was isolated to its Celo deployment. A malicious application circumvented a whitelisting requirement, allowing insolvent G$ balances to remain active instead of being liquidated. These excess balances were then exchanged against assets in the GoodDollar Reserve and other liquidity pools.

    Superfluid detected insolvent accounts on September 3 and traced the liquidation failure to the Super App bug the following day. The team deployed a hotfix, reinstated Super App whitelisting on Celo, and closed the affected accounts. The council stated that other Superfluid networks were not exposed to the same flaw.

    GoodDollar Activates Emergency Safeguards

    GoodDollar reported that its Celo and XDC reserves were not fully depleted, crediting monitoring alerts, emergency pauses, and existing protocol safeguards. Claiming, G$ transfers, and identity verification have resumed on Celo. However, reserve operations on both Celo and XDC remain paused, bridging is suspended, and liquidity in external pools remains limited. GoodDollar has advised users against swapping G$ until liquidity improves, warning that thin markets could produce significant slippage and prices that diverge from normal levels.

    Unexplained XDC Reserve Loss Raises Questions

    Meanwhile, the $20,857 loss from the XDC reserve remains unexplained. Superfluid stated the underlying vulnerability existed only on Celo, yet GoodDollar reported an outflow from its XDC reserve. Neither project has disclosed how the excess G$ reached or affected the XDC network.

    Incident Reports and Recovery Plans Underway

    GoodDollar said it plans to address the excess G$, restore liquidity, and reopen the remaining paused functions. Both GoodDollar and Superfluid are preparing separate incident reports that should provide a fuller accounting of external-pool losses and explain how the Celo exploit produced an outflow on XDC.

  • Injective Mainnet Halt: Community Analysis Points to Possible Exploit With $2.8 Million at Risk

    Injective Mainnet Halt: Community Analysis Points to Possible Exploit With $2.8 Million at Risk

    The Injective ($INJ) blockchain has experienced a sudden halt in new block production, prompting community analysts to investigate a possible exploit. On-chain data shared by the crypto-focused Telegram channel Moneystack suggests that approximately $2.79 million in cryptocurrency may have been stolen during the incident.

    An on-chain message posted on Etherscan, allegedly directed at the attacker, appears to open negotiations over the return of the funds. The Injective team had not issued an official statement at the time of reporting.

    What Happened to the Injective Mainnet?

    The Injective mainnet stopped producing new blocks, an unusual event for a blockchain that normally operates continuously. Community members first noticed the interruption, and monitoring services later confirmed the halt.

    The exact cause remains unconfirmed. However, Moneystack’s analysis points to a possible exploit involving a protocol or bridge associated with Injective that may have drained user funds.

    The Etherscan message appears to have been posted by the affected party and requests the return of the stolen assets in exchange for a reward. Such negotiations are a common response to cryptocurrency hacks as projects attempt to recover funds and limit losses.

    What the Injective Halt Means for Users

    The incident raises fresh concerns about the security of cross-chain bridges and smart contracts, which remain frequent targets for attackers. While the mainnet is halted, Injective users may be unable to complete transactions and face uncertainty over when normal network operations will resume.

    The potential loss of approximately $2.8 million is relatively small compared with some of the largest crypto exploits, but it could still affect user confidence and the market performance of the INJ token. The Injective team’s response and transparency in the coming hours will be important to managing the situation.

    Why the Injective Incident Matters to DeFi

    Blockchain exploits are not new, but each incident highlights the continuing risks associated with decentralized finance (DeFi). For investors and users, the Injective network halt reinforces the importance of due diligence and strong security measures when interacting with protocols and bridges.

    The event also demonstrates the value of community monitoring and rapid information sharing, which can help identify suspicious activity and reduce the potential impact of an attack. The outcome could influence how other blockchain projects approach security reviews, monitoring, and incident response.

    Injective Mainnet Halt: What Happens Next?

    The Injective mainnet halt may have been caused by an exploit linked to approximately $2.8 million in stolen cryptocurrency. An apparent negotiation attempt has been posted on-chain, while the community continues to await an official statement from the Injective team.

    As the investigation develops, attention will focus on recovering the funds, determining the precise cause of the halt, and strengthening security measures to help prevent similar incidents in the future.

    Frequently Asked Questions

    What caused the Injective mainnet halt?

    The exact cause has not been confirmed. Community analysis suggests that a possible exploit may have led to the theft of approximately $2.8 million in cryptocurrency.

    Is my money safe on Injective?

    Injective users should monitor official channels for updates. The team had not released a statement at the time of reporting, and the full extent of the incident remains unknown. Users should exercise caution while the situation develops.

    What is the on-chain message on Etherscan about?

    The message appears to seek negotiations with the attacker, likely offering a reward for the return of the stolen funds. This is a common approach in cryptocurrency incidents aimed at reducing losses.

    Related Reading

    • Bithumb Temporarily Halts $INJ Deposits and Withdrawals Amid Injective Network Issue
    • Injective Mainnet Halts Block Production for 15 Minutes, Upbit Suspends $INJ Transactions
    • Cronos Halts Network After Tectonic Exploit: $75M Borrowed via Price Manipulation
    • Polygon Discloses Previously Undisclosed Security Flaws Fixed via Recent Hard Forks
    • FOGO Reports 400 Million Token Theft in Exploit; Chain Remains Operational

    Source: cryptonews.net