· via dev.to (home feed)
Nostra Finance loses $3.5M as forged NSTR price pump drains Starknet lending market
Nostra Finance paused all activity on Starknet after an attacker spoofed NSTR's price roughly 8,000x and borrowed about $3.5M in blue-chip assets, with most of the haul already bridged to Ethereum.

Starknet money market halted after $3.5 million theft
Nostra Finance, a lending market on Starknet, froze supply, borrowing, withdrawals and liquidations on September 17, 2026 after a single account took out roughly $3.5 million in loans against NSTR collateral. According to a dev.to account of the incident, the security firms GoPlus Security, PeckShield, CertiK and SlowMist all classified the event as oracle price manipulation rather than a bug in the core contracts. That distinction matters: the market appears to have followed its normal logic — read a price, value the collateral, lend — using a price that had been manufactured.
A 27-minute attack with months of setup
GoPlus's published timeline, relayed on dev.to, begins well before the theft: the wallet used for the borrowing had interacted with NSTR contracts in March and August 2026, quietly accumulating the token. The live attack then ran as follows:
- 05:23 UTC — a fake NSTR/SolvBTC pool was created, seeded with about 1.5 SolvBTC of one-sided liquidity
- 05:27–05:47 — wash trades ran through the pool while liquidity was pulled from the market-making range
- 05:47–05:48 — repeated swaps drove the pool's implied NSTR price from about $0.006 to roughly $49.5, an increase of around 8,000x
- 05:48–05:50 — the inflated NSTR was posted as collateral, and ETH, STRK, USDC, USDT, WBTC and DAI were borrowed
- 05:51–07:08 — proceeds were sold across the Starknet venues AVNU, Ekubo and JediSwap, and about 2.2 million STRK left the chain via the NEAR Intents bridge
PeckShield reported that roughly $1.92 million had already reached Ethereum, including 234.57 ETH and 1.3 million DAI. GoPlus described the remainder as split between an Ethereum consolidation wallet holding about $1.9 million and around $1.5 million still in the borrow account at the time of reporting.
The imbalance between collateral and loan stands out: BeInCrypto put NSTR's entire market value at about $546,751, so the borrowed basket was close to six times the market cap of the token backing it.
The pause and its price
Nostra responded with the most severe option available and took the market fully offline. DefiLlama figures cited by BeInCrypto show total value locked collapsing from about $4 million on September 16 to roughly $710,000. Depositors who never borrowed anything were frozen along with everyone else — the quieter cost of an oracle incident, since the halt protects what remains but converts a pricing failure into a liquidity freeze for honest users.
The weak point was pool selection
GoPlus's more consequential claim is that the attacker did more than trade a shallow pool: they gamed the pool-selection logic used by GeckoTerminal so the counterfeit venue, despite holding almost no real depth, became the reference source for NSTR's price. Once the aggregator pointed at the rigged pool, the wash trades produced the needed print.
That reframes the incident as a supply-chain problem rather than an arithmetic one. The dev.to piece argues a handful of standard defences would have turned the 8,000x print into a failed experiment: a time-weighted price taken across several independent venues, a maximum deviation check over short intervals, a borrow cap below NSTR's free float, and isolation so NSTR positions could not draw on shared ETH, USDC and WBTC vaults. Conventional audits tend to miss this class of failure unless their scope covers economic invariants, because the contract can be functionally correct while the number it consumes is fabricated.
Second oracle failure on Starknet within two weeks
BeInCrypto also noted an earlier incident on the same chain: on September 4, a publishing fault at oracle provider Pragma triggered 47 liquidations on Vesu, with Pragma later reporting roughly 95% recovery. Nostra's case is different in kind — the price was deliberately constructed rather than accidentally wrong — but the pair shows two distinct oracle failure modes on one chain in the same month. The dev.to piece adds that late-August manipulation of Moonwell's own token on Base fits the same structural pattern under a different name.
Why it matters
A lending protocol's security perimeter includes everything upstream of the number it consumes. An aggregator's ranking rules became the effective price authority here, and contract-level audits do not cover that boundary unless economic invariants are in scope. Protocol tokens with small floats remain popular collateral because they inflate TVL and token utility, but once the assets borrowable against a token exceed its market cap, the token behaves less like collateral and more like a claim on the pool. The staging was also visible in advance — a wallet accumulating the collateral token for months, then a new one-sided pool and a ranking change on a public aggregator — signals a continuous watcher could catch before the borrow burst. And once funds bridge to Ethereum, a paused Starknet market can do nothing; recovery odds fall with every hop.
- #defi
- #starknet
- #security
- #oracle
- #crypto