The real failure of Nostra was not the oracle—it was the liquidity no one monitored
An attacker prepared their attack on Nostra for months and only needed three minutes of low liquidity to inflate NSTR 8,000 times.
Nostra lost ~USD 3.5 million on September 17, 2026 on Starknet
The price of NSTR jumped from ~USD 0.006 to USD 49.5 in minutes
On September 17, Nostra confirmed that a single account manipulated the price of its NSTR token and used it as collateral to borrow around USD 3.5 million in ETH, STRK, USDC, USDT, WBTC, and DAI. The lending protocol on Starknet immediately paused loans, withdrawals, and liquidations while investigating what happened.
The amount lost is the least revealing part of the case. What this attack exposes is a flaw that isn’t in Nostra’s code, but in a market condition that any lending protocol can inherit without realizing it: the solvency of a system depends on assets that no one audits with the same rigor as the code.
To understand the mechanism, you need to explain two pieces. The first is the oracle: a system that tells a DeFi protocol how much a deposited token is worth, at any given moment. An oracle doesn’t invent the price; it takes it from some real market where that token is bought and sold.
The second piece is the liquidity of that market. When a token trades in a pool with very little backing money, moving its price doesn’t require much capital—it's like auctioning an object between two people in an empty room: all it takes is for one of them to offer more for the “market price” to spike, even if no one else is actually willing to pay that. That was exactly the ground the attacker exploited.
#news
$BTC $ZEC $SPCXB
An attacker prepared their attack on Nostra for months and only needed three minutes of low liquidity to inflate NSTR 8,000 times.
Nostra lost ~USD 3.5 million on September 17, 2026 on Starknet
The price of NSTR jumped from ~USD 0.006 to USD 49.5 in minutes
On September 17, Nostra confirmed that a single account manipulated the price of its NSTR token and used it as collateral to borrow around USD 3.5 million in ETH, STRK, USDC, USDT, WBTC, and DAI. The lending protocol on Starknet immediately paused loans, withdrawals, and liquidations while investigating what happened.
The amount lost is the least revealing part of the case. What this attack exposes is a flaw that isn’t in Nostra’s code, but in a market condition that any lending protocol can inherit without realizing it: the solvency of a system depends on assets that no one audits with the same rigor as the code.
To understand the mechanism, you need to explain two pieces. The first is the oracle: a system that tells a DeFi protocol how much a deposited token is worth, at any given moment. An oracle doesn’t invent the price; it takes it from some real market where that token is bought and sold.
The second piece is the liquidity of that market. When a token trades in a pool with very little backing money, moving its price doesn’t require much capital—it's like auctioning an object between two people in an empty room: all it takes is for one of them to offer more for the “market price” to spike, even if no one else is actually willing to pay that. That was exactly the ground the attacker exploited.
#news
$BTC $ZEC $SPCXB
