Tag: Nostra

  • Pragma flags 6 price feeds as critical risk following $3.5M Starknet lending exploit

    Pragma flags 6 price feeds as critical risk following $3.5M Starknet lending exploit

    Key Highlights

    • Oracle provider Pragma classified six of 22 Starknet mainnet market and rate feeds as critical risk in a Sept. 18 assessment, including NSTR, EKUBO, LORDS, BROTHER, DOG, and $DAI.
    • A manipulated NSTR oracle price enabled a ~$3.5 million borrowing exploit at the Nostra lending protocol on Sept. 17, prompting Nostra to pause all lending, borrowing, withdrawals, and liquidations.
    • Pragma’s analysis demonstrates that oracle prices do not guarantee liquidation liquidity, with sell-quote deterioration ranging from 15% to 22% for critical tokens when measured against $10,000 versus $10 quotes.

    Pragma Issues Critical Risk Assessment for Starknet Oracle Feeds

    Blockchain oracle provider Pragma published a liquidity risk assessment on Sept. 18 classifying six of 22 Starknet mainnet market and rate feeds as critical risk, warning lenders that the mere availability of a token price does not establish that collateral can be sold to cover a loan. The assessment placed BROTHER, $DAI, DOG, EKUBO, LORDS, and NSTR in its critical category, with nine additional feeds rated high risk. Pragma emphasized that the evaluation does not confirm every listed feed is actively used as collateral in lending markets.

    Nostra Exploit Highlights Oracle Manipulation Vulnerability

    The report followed a Sept. 17 borrowing exploit at Nostra, a lending protocol on Starknet. According to Nostra’s account, a manipulated NSTR oracle price allowed one account to borrow approximately $3.5 million of other assets against NSTR collateral. In its Sept. 17 statement, Nostra said it “paused lending, borrowing, withdrawals, and liquidations while it reconciled the impact and traced funds,” adding that “final losses and potential recoveries were still unknown.” The announcement leaves the subsequent status of withdrawals and recovery unconfirmed.

    Pragma’s incident analysis identified two contributing sources for the affected oracle response. The provider stated that an enforced three-source minimum would have rejected the manipulated input, and its integration guidance recommends freshness checks and thresholds suited to the asset’s risk profile. Pragma attributed the deviating input to a manipulated on-chain pool and said its reconstruction found no decimals or median-calculation error. The provider separately reported that the attacker’s address had been frozen and recovery work was ongoing.

    Why Oracle Valuations Don’t Equal Liquidation Liquidity

    The core finding underscores a structural gap in decentralized lending: an oracle supplies a valuation, but liquidation requires selling collateral, and a thin market may not absorb that sale near the quoted price. As Pragma explained, “An oracle supplies a valuation. Liquidation requires selling collateral, and a thin market may not absorb that sale near the quoted price. A loan can be backed by an apparent value that cannot be realized when repayment depends on selling the token.”

    At token quantities valued by the oracle at $10,000, sell-quote deterioration was measured at approximately 15% for NSTR, 17% for EKUBO, 22% for LORDS, and 20% for BROTHER, when compared against quotes for $10 sales. Pragma’s Sept. 18 snapshot showed indicative $10,000 sell quotes deteriorating 15% to 22% versus $10 quotes across these four tokens.

    Source Concentration and Aggregation Risks

    The $DAI critical rating stems from source concentration and tested Starknet token routes rather than global illiquidity. Pragma noted that current and legacy deployments had different exit curves, so the critical rating cannot be read as a finding that $DAI is globally illiquid. The provider also warned that multiple source labels do not necessarily solve the problem: “publishers and aggregators can share underlying market dependencies, so several labels may reflect overlapping liquidity.”

    Protocol Response and Recovery Efforts

    For depositors, the immediate consequence was restricted access to funds. Nostra’s pause of all protocol functions remains in effect while the team reconciles impact and traces funds. Pragma’s report confirmed the attacker’s address was frozen and that recovery work continues, though final loss figures and potential recoveries remain undetermined as of the Sept. 17 disclosures.

    Why This Matters

    Pragma’s assessment exposes a fundamental risk in decentralized finance: the conflation of price availability with exit liquidity. Lending protocols that accept oracle-valued tokens as collateral without independent liquidity analysis may face unbacked loans when markets cannot absorb forced sales at quoted prices. The Nostra exploit demonstrates how a single manipulated feed can cascade into multi-million dollar losses. For the broader Starknet ecosystem, the report forces a reevaluation of which assets qualify as collateral, appropriate exposure limits, and whether exit liquidity can support liquidation under stress. As Pragma concluded, “Publishing a price doesn’t settle any of those questions by itself.”

    Frequently Asked Questions

    Which tokens did Pragma classify as critical risk in its Sept. 18 assessment?
    Pragma placed BROTHER, $DAI, DOG, EKUBO, LORDS, and NSTR in its critical risk category, with nine other feeds rated high risk.
    What caused the Nostra exploit on Sept. 17?
    A manipulated NSTR oracle price allowed one account to borrow approximately $3.5 million of other assets against NSTR collateral.
    Does an oracle price guarantee that collateral can be liquidated at that value?
    No. Pragma’s analysis shows that oracle valuations do not reflect actual sell-side liquidity. Sell-quote deterioration for critical tokens ranged from 15% to 22% at $10,000 volumes versus $10 quotes, meaning forced liquidations would likely realize significantly less than the oracle price.
  • Nostra Hit by $3.5M Oracle Attack as Security Concerns Re-emerge

    Nostra Hit by $3.5M Oracle Attack as Security Concerns Re-emerge

    Key Highlights

    • Nostra’s lending market on Starknet suffered an oracle manipulation exploit, allowing an attacker to borrow approximately $3.5 million using artificially inflated NSTR collateral.
    • The attacker bridged roughly $1.92 million to Ethereum mainnet, comprising 234.57 ETH and 1.3 million DAI, before the protocol paused all lending, borrowing, withdrawals, and liquidations.
    • The incident contributes to a surging trend in crypto security losses, with DeFiLlama data showing $1.1 billion stolen across more than 212 on-chain incidents in the first half of 2026 alone.

    Oracle Manipulation Drains Nostra Lending Market on Starknet

    Crypto security faced another significant breach today as Nostra’s lending market on the Starknet network was exploited through a deliberate manipulation of the price feed governing its native NSTR token. According to reports, the attacker subverted the protocol’s oracle system into reporting an inaccurate, inflated value for NSTR. Because Nostra relies on this oracle price to calculate collateral worth, the manipulated feed made the attacker’s NSTR holdings appear substantially more valuable than their actual market price, creating the conditions for a large-scale borrowing spree.

    Attacker Borrows $3.5 Million Across Multiple Assets Before Bridging to Ethereum

    Once the corrupted price data was accepted by Nostra’s oracle, the attacker leveraged the overvalued NSTR collateral to borrow roughly $3.5 million in a basket of assets, including Ethereum (ETH), Starknet (STRK), Circle’s USDC, Tether’s USDT, Wrapped Bitcoin (WBTC), and DAIv1. The loans appeared legitimate within the protocol’s logic because the collateral valuation and borrowing limits were derived from the compromised oracle feed. The attacker subsequently moved to extract value, bridging approximately $1.92 million to Ethereum mainnet, a sum comprising 234.57 ETH and 1.3 million DAI.

    Protocol Pauses Operations Amid Investigation; Total Loss Still Unclear

    In response to the breach, Nostra has enacted a comprehensive safety pause, halting all lending, borrowing, withdrawals, and liquidations while the team investigates the oracle manipulation vector. The protocol emphasized that the $3.5 million borrowed does not represent the final loss figure, as impact assessments and potential recovery efforts are ongoing. The exact technical method used to compromise the oracle has not yet been disclosed.

    Wave of Exploits Highlights Systemic Vulnerabilities Across CeFi and DeFi

    The Nostra incident does not exist in isolation. It coincides with a cluster of high-profile security failures over the past two weeks, signaling a broad threat landscape. Revolut, a major fintech player, fell victim to a sophisticated phishing attack initiated by a fraudulent government request that bypassed internal security checks. Term Finance suffered an exploit targeting weaknesses in its DAO governance structure, while Liquid Network experienced a software flaw that allowed attackers to generate approximately 4,000 BTC illicitly. These cases span centralized finance, decentralized governance, and sidechain infrastructure, demonstrating that attack vectors are diversifying across the entire crypto stack.

    Why This Matters: Escalating Losses Define 2026 Security Landscape

    Data from DeFiLlama underscores the severity of the current environment. Crypto security losses in the first half of 2026 have already reached $1.1 billion across more than 212 on-chain incidents. The month of April alone accounted for over $600 million in losses, driven primarily by the KelpDAO and Drift Protocol exploits. Ethereum recorded the highest chain-specific losses at $332 million, followed closely by Solana at $326 million. Zooming out to the trailing 12 months, total value hacked stands at approximately $2.101 billion, with DeFi protocols bearing the brunt at $1.353 billion and cross-chain bridges accounting for a further $758.96 million. The Nostra exploit on Starknet adds another data point to the mounting evidence that oracle integrity and cross-chain bridging remain critical systemic weak points.

    Frequently Asked Questions

    How did the attacker exploit Nostra’s lending market on Starknet?

    The attacker manipulated the price feed oracle for the NSTR token, causing it to report an artificially inflated value. This allowed the attacker to deposit NSTR as collateral that appeared more valuable than it was, enabling them to borrow approximately $3.5 million in various assets (ETH, STRK, USDC, USDT, WBTC, DAIv1) against the overvalued collateral.

    What actions has Nostra taken following the exploit?

    Nostra has paused all lending, borrowing, withdrawals, and liquidations as a safety measure while investigating the oracle manipulation. The team is currently assessing the total impact and exploring potential recovery options. The exact technical method of the oracle compromise has not yet been disclosed.

    What are the broader crypto security trends for 2026 based on DeFiLlama data?

    In the first half of 2026, crypto exploits have resulted in $1.1 billion in losses across 212+ incidents. Ethereum ($332M) and Solana ($326M) lead in chain-specific losses. Over the past year, total losses reach $2.101 billion, with DeFi protocols accounting for $1.353 billion and cross-chain bridges for $758.96 million, highlighting persistent vulnerabilities in decentralized finance infrastructure and interoperability layers.