Nostra Finance $3.5M Exploit: How an 8,000x Oracle Pump Drained a Starknet Money Market
The Protocol Did Not Need a Broken Function On September 17, 2026 , Starknet lending market Nostra Finance paused supply, borrow, withdrawal, and liquidation after one account borrowed roughly $3.5 million against NSTR collateral. Security coverage from GoPlus Security , PeckShield , CertiK , and SlowMist classified the event as oracle price manipulation , not a core-contract reentrancy or an…
On September 17, 2026, the Starknet lending market Nostra Finance paused operations after an account borrowed approximately $3.5 million in NSTR tokens. Security firms GoPlus Security, PeckShield, CertiK, and SlowMist determined that the incident was caused by oracle price manipulation, not a smart contract flaw or unauthorized mint.
Nostra Finance did not need to ship a faulty borrow() function for this exploit. The attacker manipulated the NSTR oracle price from around $0.006 to $49.5 in just 27 minutes, making it 8,000x higher than its actual market value of $546,751. The borrowed basket was about six times the collateral token's entire market cap, a clear case of oracle price manipulation rather than a smart contract bug.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.