Nostra Finance NSTR Oracle Manipulation
An attacker wash-traded NSTR through a fake pool to pump its price roughly 8,000x, then borrowed about $3.5 million against the inflated collateral on Nostra's Starknet money market.
- Date
- Victim
- Nostra Finance
- Chain(s)
- Status
- Funds Stolen
On September 17, 2026, Nostra Finance, a lending protocol on Starknet, was exploited for approximately $3.5 million after an attacker manipulated the price of its native NSTR token to borrow far more than the collateral was actually worth.
What happened
NSTR was accepted as loan collateral on Nostra's money market, but its reference price depended on external price aggregators that thin liquidity could distort. The attacker created a fake NSTR/SolvBTC liquidity pool seeded with only about 1.5 SolvBTC of one-sided liquidity, then ran roughly twenty minutes of wash trades through that shallow pool. The manipulation drove NSTR's quoted price from about $0.006 to $49.5 — a jump of roughly 8,000x. Once aggregators selected the manipulated pool as their reference, the attacker deposited the now wildly overvalued NSTR as collateral and borrowed against it, draining real assets from the protocol. PeckShield tracked about $1.92 million of the proceeds — some 234.57 ETH and 1.3 million DAI — bridged to Ethereum, with the remaining roughly $1.55 million left on Starknet. For context, NSTR's entire market capitalisation was under $600,000, illustrating how little genuine liquidity backed the collateral.
Aftermath
Nostra paused supply, borrow, withdrawal and liquidation across the affected market once the manipulation was detected, containing further damage while it investigated. The borrowed funds were not recovered, and no attacker identity has been confirmed. The team pointed to the illiquid, self-listed governance token accepted as collateral and its dependence on a distortable external price feed as the core failure.
Why it matters
Nostra is a textbook oracle-manipulation attack on a lending market: an illiquid token, a manipulable price feed, and borrowing power that outran real value — the same recipe behind Mango Markets and Moola Market. It also adds to Starknet's growing incident list alongside zkLend and mySwap, a reminder that newer execution layers inherit the oldest DeFi design mistakes. The lesson recurs across the catalogue: a governance or reward token should never be priced by a pool an attacker can build and wash-trade at will.
Sources & on-chain evidence
- [01]halborn.comhttps://www.halborn.com/blog/post/explained-the-nostra-finance-hack-september-2026
- [02]shattered.iohttps://shattered.io/nostra-finance-3-5-million-pragma-oracle-exploit-2026/
- [03]cryptotimes.iohttps://www.cryptotimes.io/2026/09/18/nostra-halts-starknet-money-market-after-3-5m-nstr-oracle-exploit/
- [04]beincrypto.comhttps://beincrypto.com/nostra-starknet-oracle-exploit-market-paused/
- [05]coinpaprika.comhttps://coinpaprika.com/news/fake-liquidity-pool-inflates-nstr-8000x/