Finst

Nostra Pauses Money Market After Oracle Exploit on Starknet

The lending app on Starknet has paused lending and withdrawals while the team investigates the damage by asset. Earlier this month, Vesu was also hit by an oracle-related incident.

Nostra Pauses Money Market After Oracle Exploit on Starknet

Key Takeaways

  • Nostra paused its money market after an oracle exploit on Starknet that let one account borrow about $3.5 million using NSTR collateral.
  • Lending, borrowing, withdrawals, and liquidations are temporarily disabled while the team investigates the damage by asset; recovery is still uncertain.
  • Total value locked fell from about $4 million to around $710,632, and Nostra also warned about fake influencers and phishing.

Starknet lending protocol Nostra paused its money market on Thursday after a manipulated price oracle allowed one account to borrow about $3.5 million (€3 million) against NSTR collateral. Lending, borrowing, withdrawals, and liquidations are currently unavailable while the team works through the damage by asset. It is still unclear whether anything can be recovered, and if so, how much.

What Went Wrong

According to the available data, the account used NSTR as collateral and borrowed Ethereum, Starknet, USDC, USDT, Wrapped Bitcoin, and DAIv1 from the protocol against it. That put the haul at about six times the market value of the collateral token itself. Security firm PeckShield later reported that the account bridged $1.92 million (€1.7 million) to Ethereum, including 234.57 ETH and 1.3 million DAI.

The impact on the protocol was immediately visible in the numbers. Total value locked dropped from about $4 million (€3.5 million) on September 16 to around $710,632 (€619,000) at the time of writing. Nostra said it is still figuring out the impact by asset and is tracking the funds.

More Starknet Problems This Month

Nostra is not the only Starknet protocol that was hit this month. Earlier in September, a bad price from Pragma’s publishing chain triggered liquidations at Vesu, another lending app on Starknet. That incident showed how vulnerable protocols can be when they rely heavily on a single external price source.

The attack on Nostra was different, though. In Pragma’s case, it was a publishing error, while this one involved deliberate manipulation of a collateral price. For users on Starknet, that highlights that not just code bugs, but also price feeds and oracles, remain a major risk in DeFi. Earlier oracle exploits at lending protocols also show how fast a bad price feed can turn into oversized loans and direct losses.

September Is Still Expensive for Crypto

The timing fits into a broader string of incidents across the crypto market. Before the Nostra case, DefiLlama had already recorded more than $326 million in crypto losses in September, mostly because of the $320 million (€279 million) incident involving Liquid Network. Nostra added another smaller, but still significant, loss to that total.

The team also warned users about fake influencers and said it never sends direct messages or asks people to connect a wallet during recovery work. For Dutch and European crypto investors, that matters because recovery periods after a hack are often used for extra phishing and scams.


Disclaimer: This content is for informational purposes only and does not constitute financial, investment, legal, or tax advice. The information provided may be incomplete, inaccurate, or outdated and should not be relied upon as such. Nothing on this website should be considered a recommendation to buy, sell, or hold any cryptocurrency. Investing in crypto-assets involves risk of loss.