A decentralized lending platform on Starknet just became the latest cautionary tale in DeFi security. The Nostra Finance exploit, uncovered and detailed by blockchain security firm GoPlus Security, shows how a single manipulated price feed let an attacker walk away with millions in borrowed crypto — and it did so through a scheme that had reportedly been staged for months before it ever executed.

Key takeaways

  • On Sept 17, Nostra Finance’s money market on Starknet was hit by an oracle price manipulation attack, according to GoPlus Security.
  • The attacker borrowed roughly $3.5 million in assets against inflated collateral.
  • The NSTR token’s oracle price was pumped from about $0.006 to $49.5 — an increase of roughly 8,000x.
  • A fake NSTR/SolvBTC liquidity pool was used to hijack GeckoTerminal’s pool-selection logic.
  • Nostra Finance has fully paused its money market, disabling supply, borrow, and liquidation functions.

Nostra Finance Faces Oracle Price Manipulation Attack on Starknet

The core of the incident is straightforward once you strip away the technical layers: an attacker found a way to convince Nostra Finance‘s price oracle that a nearly worthless token was suddenly valuable, then borrowed against it. GoPlus Security’s breakdown of the Starknet DeFi attack pins the exploit to September 17, when the platform’s money market was hit with what the firm calls an oracle price-manipulation attack.

Chronology of the Attack

According to the timeline GoPlus Security published, the attacker had already accumulated NSTR tokens and pre-positioned collateral months earlier, in March and August. The active phase of the attack began at 05:23 UTC on Sept 17, when the attacker created a fake NSTR/SolvBTC pool holding just 1.5 SolvBTC in one-sided liquidity. Between 05:27 and 05:47, the attacker wash traded that pool and pulled liquidity from the market-making range. Minutes later, between 05:47 and 05:48, the thin pool was swapped through repeatedly, spiking the NSTR price to $49.5. From 05:48 to 05:50, the attacker borrowed out $ETH, $STRK, $USDC, $USDT, WBTC, and $DAI — roughly $3.5 million worth of assets. Between 05:51 and 07:08, the funds were dumped across AVNU, Ekubo, and JediSwap, while 2.2 million $STRK left the chain through the $NEAR Intents bridge. By around Sept 18, the stolen funds had been consolidated.

Technical Mechanics of the Exploit

The mechanism behind the oracle price manipulation hinged on gaming a data aggregator rather than breaking Nostra’s smart contracts directly. By seeding a fake NSTR/SolvBTC pool with minimal one-sided liquidity, the attacker manipulated which pool GeckoTerminal selected as the reference source for NSTR’s price. Once that rigged pool became the reference, wash trading inside it was enough to push the token’s on-chain valuation to absurd levels — an 8,000x jump from roughly $0.006 to $49.5 — without needing deep capital or a large trading volume.

Impact and Platform Response

The immediate fallout from the exploit was a $3.5 million drain in borrowed assets, followed swiftly by a full shutdown of Nostra Finance’s lending functions. This is the part of the story that matters most for anyone with funds still on the platform, since it defines what users can and cannot do right now.

Assets Borrowed and Funds Movement

Once the NSTR price was artificially inflated, the attacker used the overvalued token as collateral to drain a spread of major assets: $ETH, $STRK, $USDC, $USDT, WBTC, and $DAI, totaling approximately $3.5 million. Those funds were then routed through decentralized exchanges AVNU, Ekubo, and JediSwap before a portion — 2.2 million $STRK — exited the Starknet ecosystem entirely via the $NEAR Intents bridge. GoPlus Security identified several wallets tied to the operation, including a dedicated borrow account that executed six borrows and roughly 80 sell transactions, a separate manipulation account that ran the pump-and-dump sequence, and two transit wallets that received 1.2 million and 1.0 million $STRK respectively before bridging out immediately. An Ethereum address tied to the attacker reportedly consolidated around $1.9 million, while another $1.5 million is said to remain sitting in the borrow account.

Platform Suspension and Current Status

Nostra Finance’s money market is now fully paused. Supply, borrow, and liquidation functions are all offline, effectively freezing the platform while the aftermath of the attack is assessed. This matters beyond Nostra itself: when a lending protocol locks down entirely, it signals that the team views the vulnerability as serious enough to halt normal operations rather than attempt a partial fix while the market stays open.

Attack Preparation and Exploited Vulnerabilities

What separates this incident from a quick opportunistic hack is the apparent lead time behind it. GoPlus Security’s analysis suggests the attacker built the setup for this exploit long before executing it, which raises the question of how long the underlying weakness had been sitting exposed.

Months-Long Accumulation and Staging

The wallet GoPlus Security flagged as the borrow account had interacted with NSTR contracts as early as March and August, months before the attack itself. That accumulation window let the attacker stack NSTR tokens at cheap prices, effectively pre-funding the exploit well ahead of the actual price spike. Combined with the roughly 1.5 SolvBTC used to seed the fake pool, the total cost of pulling off an 8,000x price manipulation and a $3.5 million drain appears to have been relatively small compared to the payout.

Low Liquidity Oracle Failure and Third-Party Dependency

GoPlus Security describes this as a classic low-liquidity oracle failure, built on two structural weaknesses. First, an illiquid token — NSTR — was accepted as loan collateral in the first place. Second, the price feed for that token relied on a third-party data source, and the attacker appears to have added just enough surface-level liquidity for GeckoTerminal to select the rigged pool as its reference. This is precisely the kind of dependency that keeps surfacing across DeFi: protocols that lean on external liquidity aggregators for pricing thin, low-volume tokens remain exposed to the same playbook, regardless of how secure their core lending code might otherwise be.

FAQ

What happened to the Nostra Finance money market on Starknet?

It was hit by an oracle price manipulation attack on Sept 17, allowing the attacker to borrow $3.5 million against inflated collateral.

How did the attacker manipulate the NSTR token price?

The attacker created a fake NSTR/SolvBTC liquidity pool, performed wash trading to spike the price from about $0.006 to $49.5, an 8,000x increase.

What tokens were borrowed during the attack?

The attacker borrowed $ETH, $STRK, $USDC, $USDT, WBTC, and $DAI tokens using the overvalued NSTR as collateral.

What is the current status of the Nostra Finance platform after the attack?

The money market is fully paused, disabling supply, borrow, and liquidation functions.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.