Nostra - Rekt



Eight thousand three hundred and six. That is roughly how many times Nostra's own oracle inflated the price of its own token in its own lending market, within an eleven-minute window.

NSTR's circulating value was estimated at about $550,000 that morning by third-party trackers, not by Nostra's own pricing, yet one account used the distorted print to borrow roughly $3.5 million in ETH, STRK, USDC, USDT, WBTC, and DAI, a figure Nostra itself confirmed.

There was no flash loan here, no reentrancy bug, just an attacker-seeded, thin-liquidity pool, a GeckoTerminal-derived market quote that appears to have entered Pragma's price pipeline, and an oracle that blended the resulting quote with a clean one instead of rejecting the gap between them.

By one independent reconstruction, the NSTR posted behind that loan had a clean-market value of roughly $421, pocket change dressed up as collateral.

Nostra disclosed the incident with its money market already paused and said a post-mortem would follow.

The protocol had already disclosed a version of this fragility once before, pausing borrowing against two other tokens in March 2025, after its oracle overstated their value roughly threefold and admitting it had no fallback source, a different asset and a different mechanism, but the same broader oracle-risk problem.

Eighteen months later, that risk resurfaced in a far more consequential form.

Was that first warning ever actually fixed, or just filed away?

Credit: Sprunky, BeinCrypto, Nostra, Blocksec, CoinTelegraph, PeckShield, CertiK, BlockSec, AMLBot, GoPlus Security, Pragma, DBCrypto, DefiLlama, Vesu

On September 17th, Nostra disclosed its own incident.

The protocol's own Twitter account said a manipulated NSTR oracle price had enabled one account to borrow roughly $3.5 million against inflated collateral, and announced that its money market was already paused, lending, borrowing, withdrawals, and liquidations, all unavailable.

Nostra's statement appeared before public posts from PeckShield, CertiK, and other security trackers.

What it doesn't establish is when Nostra detected the manipulation, when it executed the pause, or whether outside researchers had already identified the relevant transactions privately.

The public forensic accounting began about eleven hours later.

PeckShield quote-tweeted Nostra's statement with the first number that mattered beyond the headline figure, roughly $1.92 million already bridged to Ethereum, broken down to 234.57 ETH and 1.3 million DAI.

CertiK followed within two hours, first confirming the price manipulation, then eighteen minutes later posting the fund split, about $1.55 million still sitting on the Starknet contract, another $1.93 million already on an Ethereum address.

BlockSec's Phalcon thread laid out the mechanics that the earlier alerts hadn't detailed, an attacker-created NSTR/SolvBTC pool, one-sided liquidity, a small trade that sharply moved the reported quote, each step tied to a transaction hash.

Independent researcher Sprunky then expanded the reconstruction, decoding the actual Pragma price prints, a clean AVNU quote, followed ten minutes and forty seconds later by a poisoned GeckoTerminal-derived quote, and running a detailed independent calculation that put the gap between the real NSTR/ETH rate and the one the borrow actually used at roughly 8,306x.

By the next morning, AMLBot said it had traced the exit route, Near Intents, CCTP, and LayerZero OFT stitched together to move funds off Starknet, with roughly $1.6 million still parked at the Starknet address at the time.

GoPlus Security's own reconstruction landed that same day, and it went further back than anyone else had reported, tracing the attacker's NSTR accumulation to March and August, months before the pool used in the manipulation was actually created.

Nostra disclosed the incident before the public forensic threads assembled the fuller picture.

The relevant NSTR accumulation predated the manipulation by months, that's what the record shows, not that anyone could have flagged an ordinary-looking wallet as a future exploit months in advance.

The attacker didn't need six months of undetected activity to pull this off.

They needed one thin, attacker-shaped pool to become a valid price source for borrowable collateral on the one day they chose to use it.

So why did Nostra's controls treat that pool's price as valid at all?

The Oracle That Split the Difference

The attacker didn't need to break Pragma's contract. They needed to feed it a lie convincing enough that averaging it with the truth still produced a number worth borrowing against.

BlockSec's Phalcon reconstruction lays out the setup in three moves.

First, a brand new NSTR/SolvBTC pool, seeded with about 1.5 SolvBTC placed one-sided, away from where the token actually traded.

Second, that reported liquidity appears to have influenced GeckoTerminal's pool-selection behavior, pulling the new, thin pool into play as a reference for NSTR's price.

Third, a small buy inside the now-rigged pool sent its quoted price from a fraction of a cent to just over $99.

New Pool Created:
0x741af6efcc55165e89f7ef0b8ebad7e87efeaa8daa3b60dddd62d5dcacae69dPragma’s aggregation was designed to reduce the risk that any one manipulated feed could dominate.

Pragma first establishes a price for each source by taking the median of publisher-submitted values; the consuming protocol then selects the final method for combining those source-level prices.

Its integration guidance recommends at least three pricing sources, alongside freshness checks and thresholds appropriate to an asset’s risk.

Only two inputs appear to have contributed that morning, an AVNU-derived reference quote near $0.00596 and a manipulated GeckoTerminal-derived quote near $99.02.

With a third source missing, the two available values produced a midpoint of roughly $49.52.

In Sprunky's reconstruction, that midpoint was the final aggregate returned to the Nostra market, the figure used to value NSTR collateral.

Sprunky traced the borrowing transaction to an NSTR/ETH collateral rate of 0.02032399, versus an estimated real NSTR/ETH rate of 0.00000244689, a 8,306-fold inflation at the time of the borrow.

That ratio didn't depend on ETH's dollar price that morning.

Pragma's post-incident update goes beyond confirming the two-source gap. It says NSTR had already been classified as a high-risk feed because of limited liquidity and available pricing sources, and that Pragma had previously highlighted these risks to Nostra.

It also says Gate.io was removed as an NSTR source at Nostra's request because of illiquidity and manipulation concerns, leaving limited source coverage in the months before the incident.

Removing a weak source may have been reasonable.

The issue is what came next: NSTR was a high-risk, source-limited feed, yet its two available prices still produced a collateral valuation that Nostra used to authorize borrowing against other assets.

Pragma says a mandatory three-source minimum would have rejected the manipulated response. And Pragma's reconstruction says it found no decimal or median-calculation error.

The aggregation math, in other words, appears to have produced exactly the output the configuration permitted.

Run the collateral math and the absurdity gets worse, not better. By Sprunky’s reconstruction, roughly 70,686 NSTR posted against the loan had a real-market value of about $421, yet supported approximately $3.5 million in borrowing, more than $8,000 borrowed for every dollar of estimated real collateral value.

That figure is an independent reconstruction, not a Nostra-confirmed accounting, but it explains why the attack never needed much real collateral to begin with.

NSTR's estimated circulating market cap sat around $550,000 that morning, which puts the borrowed assets at more than six times NSTR's entire circulating market cap, a comparison that's illustrative rather than a solvency test since market cap was never meant to double as a borrowing limit.

The public record establishes the outcome, not the reason. An extreme divergence between two price inputs was accepted, a missing third input didn't prevent a borrowable value from being produced, and the resulting NSTR collateral value was sufficient to authorize millions in debt.

What it doesn't yet establish is why no effective safeguard intervened.

What the public record does not yet establish is what controls, if any, Nostra applied to NSTR’s price inputs and collateral valuation, or why they allowed this price to authorize borrowing. Nostra’s code review and promised post-mortem should answer that.

Every component may have behaved exactly as configured. That's precisely why the configuration is an open question.

If a protocol can average a $0.006 quote with a $99 quote and call the result a collateral price, the manipulated pool was not the whole failure. The deeper failure was an oracle architecture that never asked whether $49.52 made economic sense.

The oracle didn't test whether the number was economically credible.

Once it cleared, who was left checking where the $3.5 million it unlocked actually went?

Six Assets, Seven Borrow Transactions

The core transactions in BlockSec's Phalcon reconstruction are public on-chain, and the key hashes are available for independent review.

What follows is the full chain, in order: the pool that made the manipulation possible, the trade that spiked its price, the two oracle entries Pragma recorded from it, and then every transaction in the borrow itself, asset by asset.

Pool creation (an NSTR/SolvBTC pool seeded with roughly 1.5 SolvBTC as one-sided liquidity): 0x741af6efcc55165e89f7ef0b8ebad7e87efeaa8daa3b60dddd62d5dcacae69d

Price-moving trade (a small transaction inside that thin pool that pushed its reported NSTR quote toward $99): 0x772e73613ffbc845508377fc6ded1137f60ad730aecb2b7c18a2978a84a6ac1

AVNU oracle entry: A 05:37 UTC publish_data_entries transaction decoded as an NSTR quote of $0.00596118: 0x1d33ab3d3ff72c82d7b1b6b317d28eff38abd03c0f084985c30b14859328b7f

GeckoTerminal oracle entry: A 05:47 UTC publish_data_entries transaction decoded as a manipulated NSTR quote of $99.02439975: 0x6bc9b41bce2b6c08639c16790af064efafa15890c1ebf8cc72df99a577a1cf1

ETH borrow (939.30 ETH, ~$2,297,659.30 at the September 17th price of $2,446.14): 0x2460fde607d09f2434d1b4e6d4089c6e1f459f4ce70ba2853d3a37547cdf00e

STRK borrow (28,272,985.90 STRK, ~$819,250.48 at the September 17th price of $0.02897644): 0x79005742a8f7fe443a4a0d444f053ba06a49a15d558662404aa894479ddb820

USDC.e borrow (113,661 USDC.e, ~$113,648.39): 0x34bb10618939a14db2f613acad1d63bfbfb96908fdb6a6f2fb65a07af6a200a

USDT borrow (84,377 USDT, ~$84,365.93): 0x61eacbd4f4fc4230a6e3b204ff0cdc26939db0663f3bec1418f51b79c5b0647

WBTC borrow, first (2 WBTC, ~$152,742.00 at the September 17th price of $76,371): 0x373be1419cb2b5d0ef7fc684070857dbe88235e81c29fbe5d8e053640968fb4

DAI borrow (29,078 DAI, ~$29,264.11): 0x5a8a94a14cc2950f81f5409c992218fa25827b4e2b9ec9a1d4b33bd623bc54d

WBTC borrow, second (0.88 WBTC, ~$67,206.48 at the September 17th price of $76,371): 0x439ab7565b07299ad1f6cb57ee10e9f47dd80b1b98a4bac2ba696a0934ce95

Total borrowed: Approximately $3.56 million across six assets, priced at their September 17th values, consistent with the $3.5 million Nostra itself confirmed.

The borrowed assets were subsequently sold through approximately 80 transactions across AVNU, Ekubo and JediSwap, according to GoPlus Security’s on-chain reconstruction.

The reconstruction describes a two-stage exit route: Sales on Starknet, followed by transfers through intermediary accounts and movement via NEAR Intents.

GoPlus attributes the seven-transaction Nostra borrowing sequence to this Starknet account: 0x06d48ef7ab62c26e3ef1987c322096cd508e9034c82048783a6b438fc1344bc3

It separately attributes the thin-pool trading and price movement that preceded the oracle distortion to this Starknet account: 0x2d9fb4edec9d5c015c43514ca5a309aab1b2638c3a45ad750d09ee971d0da23

After the DEX sales, 1.2 million STRK moved to this first transit account: 0x0285b4bf99e227c4baed7f9a8c7c673771fe0b75e897f7350729e3e13021321d

Another 1.0 million STRK moved to this second transit account: 0x074f5318f8d60ad0832068dc0430d0a0e2f9dd0c2e710fb8c032945a3804b57e

According to GoPlus, both intermediary accounts then moved funds through NEAR Intents.

The reconstruction identifies this Ethereum wallet as a consolidation point: 0xa059aaab82773caf622de9d9a0f2dbf9aa7f3c37

The reported route is therefore: Nostra borrows → AVNU / Ekubo / JediSwap sales → two Starknet transit accounts → NEAR Intents→Ethereum consolidation

The on-chain route shows how the assets moved; the next question is what the attack’s aftermath meant for the protocol and the people whose funds remained inside it.

The funds can be traced leaving Nostra, but what did the exploit leave behind for the protocol, its markets and its depositors?

When the Price Feed Becomes the Attack Surface

Nostra’s disclosure of roughly $3.5 million in unauthorized borrowing did not stop users from leaving.

The exploit had consequences, Nostra’s total value locked had fallen from about $4.15 million on September 16 to roughly $743k on September 18th, according to DefiLlama, while NSTR’s estimated circulating market value stood at about $546,751.

In its initial statement, Nostra said it had paused lending, borrowing, withdrawals and liquidations; that the final loss and potential recoveries remained unknown; and that it would publish a detailed post-mortem.

It also warned that it would never send direct messages or ask users to connect a wallet as part of recovery efforts: A warning worth repeating, since exploit-response periods are especially fertile ground for impersonation and phishing attempts.

Nostra was not the only Starknet oracle incident that month. On September 4, less than two weeks earlier, an upstream price-feed fault caused the oracle used by Vesu to report several assets at roughly half their real value for 109 seconds.

The error triggered 47 liquidations across 42 borrower wallets in seven Vesu pools.

The Vesu event was not a market-manipulation attack. It was a faulty price-publication event.

Vesu later said it had recovered 95% of the affected value at then-current prices, or 93% at prices from the morning of the incident: Approximately $1.33 million recovered against $1.395 million in borrower claims.

The two incidents had different causes: A price-publication failure at Vesu and an attacker-manipulated market input at Nostra.

But they demonstrate the same structural reality. An oracle does not merely describe a market when protocol contracts rely on it to determine collateral value or liquidation eligibility. A bad value can trigger liquidations or authorize borrowing before a human operator has time to intervene.

September had already been costly for the sector. Including the Nostra incident, DefiLlama’s exploit database had recorded more than $342 million in crypto losses for the month, with the vast majority tied to the roughly $320 million Liquid Network incident.

Nostra says Trail of Bits, Cairo Security Clan and Salus audited its smart contracts, although neither its FAQ nor terms page links to the reports, dates, scope, findings or remediation.

The apparent failure involved the price-data path feeding those contracts, the external market and oracle/pool-selection process that produced NSTR’s collateral price, not necessarily a defect in the lending code itself.

Pragma’s published documentation and audit material concern its oracle architecture and on-chain contracts; they do not, on their face, establish how an external market-data provider selected the pool whose price entered Nostra’s collateral calculation.

GeckoTerminal’s public API documentation shows that applications can retrieve token and pool data, including multiple pools for one token, but does not disclose what pool-selection safeguards, liquidity thresholds or manipulation checks, if any, determined which NSTR market informed the price used in this incident.

The question, then, is not whether Nostra’s contracts were audited. It is whether the protocol’s risk design adequately accounted for the off-chain dependencies those contracts were built to trust.

When a protocol’s code is designed to obey an oracle, who is accountable for ensuring the oracle deserves to be believed?

A thin pool did not authorize a multimillion-dollar loan on its own. A chain of trusted systems converted an attacker-shaped market price into borrowable collateral.

The critical question is not whether Nostra’s lending contracts malfunctioned, but why the protocol’s risk design allowed a thin, manipulable market signal to determine collateral capacity at that scale.

The incident was not without precedent. In March 2025, Nostra said price-feed errors had inflated the reported values of xSTRK and sSTRK to roughly three times their actual prices, and acknowledged it had no secondary oracle available for those assets.

In August 2025, Nostra’s own post-mortem said the Pragma-supplied xSTRK feed became non-functional, leaving four accounts undercollateralized and producing about $14,212 in bad debt, which Nostra Labs said it covered.

Pragma’s account of the recent NSTR incident makes the risk more concrete. Pragma said NSTR was already classified as a high-risk feed because of limited liquidity and available pricing sources, that it had previously raised those concerns with Nostra, and that Gate.io was removed as a source at Nostra’s request over illiquidity and manipulation concerns.

Pragma recommends at least three pricing sources, but said the response used in the incident had two contributors and that an enforced three-source minimum would have rejected it.

These earlier events did not share the same exact mechanism as the most recent NSTR exploit: March involved an overvalued price feed, August involved a non-functional or stale xSTRK feed, and September involved manipulation of an illiquid on-chain NSTR market.

But together they document a recurring category of risk, external price inputs affecting collateral valuation, rather than a wholly unforeseeable failure.

Nostra’s eventual post-mortem should therefore account for more than the manipulated pool.

It should explain how it assessed thin-liquidity collateral, what controls governed missing or divergent price sources, why NSTR remained eligible to support borrowing under those conditions, and how it will reconcile outstanding liabilities, recoverable assets and user losses.

The pool was the instrument, but will Nostra’s accounting identify the security model that treated its price as trustworthy enough to lend against?


share this article

REKT serves as a public platform for anonymous authors, we take no responsibility for the views or content hosted on REKT.

donate (ETH / ERC20): 0x3C5c2F4bCeC51a36494682f91Dbc6cA7c63B514C

disclaimer:

REKT is not responsible or liable in any manner for any Content posted on our Website or in connection with our Services, whether posted or caused by ANON Author of our Website, or by REKT. Although we provide rules for Anon Author conduct and postings, we do not control and are not responsible for what Anon Author post, transmit or share on our Website or Services, and are not responsible for any offensive, inappropriate, obscene, unlawful or otherwise objectionable content you may encounter on our Website or Services. REKT is not responsible for the conduct, whether online or offline, of any user of our Website or Services.