Nostra Finance, a lending, swap, and bridge protocol built on the Starknet Layer 2 network, has paused its money market after a manipulated price feed for its native NSTR token allowed a single account to borrow approximately $3.5 million in digital assets against inflated collateral.
The exploit took place on September 17, 2026, and forced the protocol to disable lending, borrowing, withdrawals, and liquidations while its team reconciles pool balances and traces the stolen funds. Nostra has said the final loss and any recoveries are not yet known.
What Nostra Disclosed
In an official statement posted on X at 13:28 UTC on September 17, Nostra said a manipulated NSTR oracle price enabled one account to treat its NSTR holdings as inflated collateral and borrow assets worth approximately $3.5 million from the money market. The stolen basket, according to the team, included ETH, STRK, USDC, USDT, WBTC, and DAIv1.
The protocol said the money market has been paused pending pool-by-pool reconciliation. Users currently cannot lend, borrow, withdraw, or trigger liquidations on the platform. Nostra said the final loss and any recoveries are not yet known, that it is working with relevant parties on recovery, and that a detailed post-mortem will follow.
The team also warned users that it will never send direct messages or ask them to connect wallets as part of the recovery process, a common phishing vector during protocol incidents.
Independent recaps of that statement, including TechFlow, said deposits, borrows, withdrawals, and liquidations were suspended while the team checks each asset pool.
Fund Flow Tracked by Security Firms
The first public breakdown of stolen fund movement came from PeckShield’s alert at 00:41 UTC on September 18. The blockchain security firm confirmed Nostra’s $3.5 million figure and reported that approximately $1.92 million had already been moved to the Ethereum mainnet, split as 234.57 ETH and 1.3 million DAI.
Blockchain security firm CertiK independently flagged the incident in an alert at 02:30 UTC and followed up at 02:48 UTC with on-chain explorer links. According to CertiK’s location split, approximately $1.55 million remained in a Starknet contract traceable through the Voyager block explorer, while approximately $1.93 million had been bridged to an Ethereum address visible on Etherscan.
The two monitored figures reconcile within rounding to Nostra’s disclosed $3.5 million total. Nostra has not itself confirmed the Ethereum receiving address or the exact ETH and DAI amounts.
DefiLlama separately recorded a September 17, 2026 incident against Nostra Money Market for $3.5 million, classified as oracle manipulation using spot-price manipulation on Starknet.
Understanding the Oracle Mismatch
An oracle, in the context of decentralized finance (DeFi), is a data feed that supplies real-world prices to a smart contract. Lending markets use oracle prices to value collateral and decide how much a user can borrow. When an oracle prints a price that is higher than the true market rate, the collateral is overvalued in the protocol’s accounting, and the borrower can withdraw more assets than the collateral is actually worth.
The attack profile matches a standard lending market oracle failure rather than a smart contract vulnerability in Nostra’s core code. The NSTR feed printed a higher price, and the same NSTR balance then counted as larger collateral inside the money market. One account borrowed liquid assets against that inflated valuation and moved the proceeds.
At the time of writing, NSTR was trading between roughly $0.0055 and $0.0059 with a circulating market capitalization between about $550,000 and $590,000 according to DefiLlama data.
The total borrowed value of $3.5 million therefore exceeds the entire circulating market capitalization of the collateral token by more than five times, which is the core of the oracle-to-collateral mismatch. DefiLlama has logged the event as a September 17, 2026 exploit classified under oracle and spot price manipulation on Starknet. DefiLlama’s protocol page listed NSTR near $0.0055 and a market cap near $549,675 at the time of this report.
PeckShield and CertiK have not yet published a full transaction graph, the exact oracle contract address, the pre- and post-attack NSTR print, or whether a thin decentralized exchange (DEX) pool was used to move the feed. Those details remain outstanding pending Nostra’s post-mortem.
A Second Oracle Incident for Nostra
This is not the first publicly disclosed price feed failure at Nostra. On March 24, 2025, the protocol reported in a statement that oracle feeds for xSTRK and sSTRK, two liquid staking derivatives of STRK, had inflated by approximately three times between Starknet blocks 1256310 and 1256360. In one example cited by the team, xSTRK moved from $0.1793 to $0.5897.
At the time, Nostra reduced collateral caps for those assets to zero, paused new borrowing against them, and advised users to withdraw their positions. The team also disclosed that no secondary fallback oracle was available for those particular assets.
The March 2025 event was described as a feed error that risked wrongful liquidations. The September 2026 event, by contrast, involved an alleged manipulation that enabled over-borrowing. The common factor across both incidents is the use of Starknet ecosystem token price data as lending collateral. Nostra’s March 24, 2025 X thread is the primary source for the earlier xSTRK and sSTRK feed error.
Open Questions on Oracle Sourcing
In May 2026, Nostra publicly announced the integration of Chainlink Price Feeds on Starknet for BTC, DAI, ETH, LINK, STRK, USDC, USDT, and wstETH. NSTR was not part of that initial list. Whether the NSTR feed was later routed through Chainlink, the Starknet-native oracle Pragma, or a different provider has not been clarified in the September 17 statement, and the identity of the oracle used at the time of the exploit remains one of several open questions.
The September 2026 exploit lands in a period of heightened scrutiny of oracle security across DeFi. Ostium Labs, another protocol whose July exploit was traced to a manipulated price feed, is currently facing a $15 million loan dispute in a New York federal court tied to a $23.75 million loss.
Earlier in the week, Blockaid also flagged a FlamingoFinance contract exploit that saw $345,900 stolen. Those Ostium and Flamingo items are separate incidents and are included only as industry context, not as confirmed links to Nostra.
Protocol Context
Nostra operates a suite of products on Starknet, including Nostra Money Market, Nostra Pools, Nostra Money Market Alpha, and nstSTRK, its own liquid staking derivative of STRK. The team has also disclosed plans to build on the Monad blockchain. According to official communications, the current exploit is confined to the Starknet money market and does not affect its other products.
Nostra’s leadership has been in public focus for other reasons in the past. Former chief executive David Garai stepped down shortly after the NSTR token airdrop in June 2024.
What Remains Unverified
Several key details about the September 17 incident have not been confirmed by primary sources at the time of publication:
- The exact start block and end block of the manipulated NSTR price feed
- The oracle provider for NSTR at the time of the attack
- The full list of borrow transactions and per-asset amounts
- Whether the $3.5 million figure represents realized bad debt or gross borrowed notional
- Any freeze, return, or negotiation involving the Ethereum receiving address
- Any user-level haircut applied to depositors on the platform
These items should be treated as unverified pending further disclosure from Nostra or its security partners. Updates from the team are being posted through its Discord channel.
This is a developing story. The Crypto Times will update this report as Nostra, PeckShield, or other primary sources publish confirmed figures, fund-flow details, or a post-mortem. Early numbers may change.
Also Read: $7.8M rsETH Drained From Ethereum Safe Wallet, MEV Bot Yoink Front-Runs the Exploit
